CVE
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
MITRE ATT&CK TTPs 1
Source Articles
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controllers due to a credible external security threat. The affected component is the self-hosted Storage Zone Controller, which is internet-facing and thus exposed to potential exploitation. While Progress states there is no evidence of unauthorized access to accounts or data, it has not disclosed the nature of the threat or the responsible actor. The lack of a patch and the directive to fully power down systems suggest a critical, unpatched vulnerability or potential compromise of credentials or internal systems.
hacker-news Jul 10, 2026
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A critical unpatched vulnerability dubbed XRING in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers using legitimate QPACK traffic. The flaw stems from an integer underflow during dynamic table resizing in QPACK, leading to out-of-bounds memory copy and server crash. The vulnerability affects all XQUIC versions up to v1.9.4 and impacts servers using HTTP/3 with default QPACK settings, including those behind Alibaba's Tengine web server. No patch or CVE has been assigned as of July 10, 2026.
hacker-news Jul 10, 2026
Summer of Clearinghouses
The article discusses the emergence of 'clearinghouses' for managing pre-disclosure vulnerabilities in open source software, driven by AI-powered security research. These platforms aim to centralize vulnerability data, but the real value lies in automated actuation—turning findings into patched, signed software artifacts quickly. The author emphasizes that scale, speed of remediation, and upstream patching are critical for effectiveness, while warning that many announced clearinghouses are superficial. The long-term goal is to move beyond patching toward 'secure by design' systems that prevent vulnerabilities altogether.
hacker-news Jul 9, 2026