CISA and Readwise Reader Android report multiple stored XSS vulnerabilities
Readwise Reader Android 8.7.2 has stored XSS bugs tied to CVE-2026-18311, CVE-2026-18312, and CVE-2026-18320.
541 articles published in the last 90 days, most about Cybersecurity and Data Center.
Records are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Threat Desk • September 25, 2026
Readwise Reader Android 8.7.2 has stored XSS bugs tied to CVE-2026-18311, CVE-2026-18312, and CVE-2026-18320.
Decision Insights Threat Desk • September 24, 2026
Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency…
Decision Insights Threat Desk • September 8, 2026
ONLYOFFICE ownCloud plugin 9.12 has an SSRF flaw (CVE-2026-84282) enabling admin-driven outbound requests and internal port probing.
Decision Insights Threat Desk • August 23, 2026
TCG TPM 2.0 reference code flaws include CVE-2026-6726 key credential leakage and CVE-2026-6727 RSA OAEP timing side-channel.
Decision Insights Threat Desk • August 23, 2026
HP Deskjet 2800 firmware TBP1CN2612AR has an authorization bypass in webserver APIs tracked as CVE-2026-13753.
Decision Insights Threat Desk • August 23, 2026
RDK-B WebUI rdkb-2025q4-kirkstone has flaws including JWT signature verification errors and memory corruption that can bypass authentication and cause DoS.
Decision Insights Threat Desk • August 23, 2026
VPS.org one-click templates use static credentials: Supabase exposes PostgreSQL on 0.0.0.0:5432 and Zulip enables session forgery.
Decision Insights Threat Desk • August 23, 2026
Analog Way Picturall Quad Compact Mark II version 3.5.8 has CVE-2026-14985 enabling root via a maintenance script. Fixed in 3.5.9.
Decision Insights Record • April 15, 2026
Endor Labs launched an agentic code security benchmark extending Carnegie Mellon’s SusVibes, plus a public leaderboard (Agent Security League).
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.