OpenSSL released patches for 18 vulnerabilities, including a high-severity heap use-after-free bug (CVE-2026-45447) in PKCS#7 verification that can enable remote code execution. A California researcher discovered the flaw using Claude AI and Anthropic Research. Alex Gaynor of Anthropic reported half a dozen of the patched vulnerabilities.
Tap to vote and see what everyone thinks.
Gogs patches critical zero-day enabling remote code execution
Summary by ByteBrief