Security updates
The newest releases whose notes mention a security fix, as tagged by our normalization of each vendor’s changelog. Follow along in your reader with the RSS feed.
Latest security updates
PocketBase
PocketBase · Databases & DataBumped golang.org/x/ dependencies and minimum Go version to 1.26.6 for bug and security fixes
1Password CLI
AgileBits · Security & PrivacyDebug output now includes per-request timing; Debug output now reports more information when a vault cannot be read; Reporting item usage for cached items no longer delays reading…
BigBlueButton
BigBlueButton · CommunicationHarden static asset path resolution in bbb-etherpad
Docker Engine
Docker · Infrastructure & DevOpsFix CVE-2026-41568: symlink escape in mount destination creation; Decompress archives before entering container filesystem, fixing CVE-2026-41567; Fix CVE-2026-42306: bind mount…
1Password CLI
AgileBits · Security & PrivacyDebug output now includes per-request timing; 1Password Environments commands are now significantly faster on Apple silicon Macs; Debug output now reports more information when a…
Digimon Masters Online
Move Games Co., Ltd. · GamesSecurity improvement; Server and channel stabilization; Game database organization and backup; July event reward provision
ONNX Runtime
Microsoft · AIWebGL and JSEP execution providers in onnxruntime-web are deprecated in favor of the native WebGPU EP; POSIX telemetry is now available on Linux, macOS, Android, and iOS when ONNX…
gemini-cli
gemini-cli · AIImplement tool registry discovery; Implement Cloud Run webhook ingestion service for caretaker; Implement egress cloud run service skeleton for caretaker; Add triage worker core…
Claude Code
Anthropic · Developer ToolsFixed interactive sessions that could stop redrawing entirely while the process kept running after a rare internal layout error; Fixed git / Git Bash not being found on Windows…
Zulip Server
Zulip · CommunicationGuest users could receive new messages sent to public channels they were not subscribed to by registering an event queue with appropriate parameters, and existing event queues…
serverless
serverless · Frameworks & LibrariesHost MCP servers on AWS Lambda with a new mcp section in serverless.yml that deploys official MCP TypeScript SDK servers behind API Gateway with response streaming, OAuth…
Meilisearch
Meili · Databases & DataForeign filter now supports sharding by retrieving documents through the network when evaluating foreign filters and hydrating documents; Increase the limit of documents that a…
XanMod Kernel
XanMod · Operating Systemsusb: typec: ucsi: Correct teardown ordering in ucsiinit() error path; drm/amd/display: Exit idle optimizations before programming; drm/amd/display: check GRPHFLIP status before…
Docker Desktop
Docker · Infrastructure & DevOpsUpdate Docker Engine to v29.7.2; Update Docker Buildx to v0.36.0; Update Docker Scout CLI to v1.24.0; Update Docker Agent to v1.119.0; Improve Docker VMM Beta performance with…
Calibre-Web
Calibre-Web · MediaMOBI files now support metadata extraction on upload; Reverse proxy login with shared secret header implemented; Cover path is now selected based on the correct setting instead of…
Schedule I
TVGS · GamesFixed a security vulnerability in which users could join a multiplayer game without being friends with the host; Fixed packaging station button text wrapping; Fixed main menu info…
Super Productivity
Johannes Millan · ProductivityAdded search to global settings and a keyboard shortcut cheat sheet; Added crash-safe local drafts for project notes; Added interval recurrence phrases such as @every 2 weeks and…
Private Internet Access
Private Internet Access · Security & PrivacyFixed race condition overriding selected location; Addressed security concern; Clear keystore after use; Added permissions blocks; Removed duplicate lookup; Fixed snooze remaining…
cherry-studio
cherry-studio · AILocalize workspace tree errors in agent files; Use preset append mode for agent prompts in claude-code; Address high and critical security advisories; Serve DeepSeek V4 models…
Linux Kernel
Linux Kernel Organization · Operating SystemsMake Safe-RET robust against interrupt injection
Linux Kernel
Linux Kernel Organization · Operating SystemsMake Safe-RET robust against interrupt injection
Recently mentioned CVEs
CVE ids found verbatim in release notes — extracted from the text itself, not tagged by a model, so short notes count too. Each links to every release that mentions it.
- CVE-2026-197302 releases · 1 product
- CVE-2026-336302 releases · 1 product
- CVE-2026-398225 releases · 4 products
- CVE-2026-403555 releases · 1 product
- CVE-2026-403565 releases · 1 product
- CVE-2024-406351 release · 1 product
- CVE-2026-415671 release · 1 product
- CVE-2026-415681 release · 1 product
- CVE-2026-423061 release · 1 product
- CVE-2026-411781 release · 1 product
- CVE-2026-425054 releases · 3 products
- CVE-2026-466005 releases · 2 products
- CVE-2026-4726210 releases · 4 products
- CVE-2026-501631 release · 1 product
- CVE-2026-5348810 releases · 4 products
- CVE-2026-568526 releases · 3 products
- CVE-2026-715561 release · 1 product
- CVE-2026-715571 release · 1 product
- CVE-2026-331867 releases · 6 products
- CVE-2026-32012 releases · 1 product