Tech Blog

everyWAN Blog

Technology, cybersecurity and IT trends that matter

Deep Analysis
Cybersecurity
IT Trends
Filter by:
Tipos de imprenta de madera: PostScript nació para hablar con impresoras y sigue vivo dentro de las bibliotecas que procesan imágenes
7 min read

It was called .png and inside it was PostScript: the WordPress 7.0.4 flaw

On 12 August WordPress shipped 7.0.4 with a single fix: CVE-2026-65640, remote code execution by uploading a file that announces itself as an image and is PostScript inside. The patch reaches back to the 4.7 branch, from December 2016. For it to affect you two conditions have to hold at once, and the first one is not yours to decide. Why validating the extension does not validate what you think, what "requires Author role" really means, and how to check it in ten minutes.

Sala de control con una pared de pantallas mostrando paneles y mapas mientras varias personas los observan: el panel que todo el mundo mira y nadie mantiene
8 min read

Metabase: the data dashboard that was also the keyring

On 3 August, attackers walked into Metabase instances through the "forgot my password" endpoint, unauthenticated, with a CVSS of 10.0. Framework and Tally have already told their users. What an attacker takes from a compromised BI dashboard is not the charts: it is the credentials for every connected database, stored unencrypted unless somebody turned encryption on by hand. Which versions are in range, why this hole never shows up in your CVE feed, and why patching is the easy half of the job.

Fachada de un edificio residencial con balcones: en el hosting compartido, tu superficie de ataque incluye a los vecinos que no elegiste
8 min read

cPanel CVE-2026-58048: in shared hosting, your neighbour sets the risk

Any ordinary customer on a cPanel server could execute SQL as database root simply by renaming a database. The headline is the 9.4, but the figure almost nobody reads sits at the end of the vector: SC:H/SI:H/SA:H, CVSS 4.0's way of stating in writing that the damage leaves the vulnerable system. On a shared server, "the subsequent system" has a name: everybody else. What the flaw does, why its 5.6 sibling says it more plainly, what to check this week, and the honest question of whether you should flee shared hosting (not always).

CVE-2026-34486 en Apache Tomcat: el EncryptInterceptor procesaba los mensajes del clúster aunque fallara el descifrado, un control de seguridad que falla abriendo
8 min read

If decryption fails, the message goes through anyway

The fix for the Apache Tomcat vulnerability CISA flagged as exploited on 4 August fits in a single line of code moved somewhere else. For two weeks, if decryption of a cluster message failed, Tomcat logged the error and processed the message anyway. And only 11.0.20, 10.1.53 and 9.0.116 were affected: precisely the versions carrying the patch for the previous flaw. What it means for a control to "fail open", why the log was the only signal, and what we check.

CVE-2026-66066, un fallo de CVSS 9,5 en Active Storage de Ruby on Rails, permite leer ficheros del servidor subiendo una imagen cuando la aplicación procesa variantes con libvips
8 min read

A 9.5 in Rails: the flaw is not in your application, it is in the library nobody chose

On 29 July 2026 Rails published CVE-2026-66066: a 9.5 in Active Storage letting an unauthenticated attacker read files from the server — including the process environment with secret_key_base and the database credentials — by uploading an image. The flaw is not in the code you commissioned, nor exactly in Rails: it is in which formats libvips considers safe to read, a C library nobody at your company chose. And libvips has published since 2022 which of its operations it has not verified, with a switch to block them. The label was there; what was missing was flipping it.

Subscribe to our newsletter

To receive IT stories, everyWAN news and exclusive subscriber offers, sign up to our mailing list

Minorisa de Sistemas Informaticos y Gestión S.L. © 2026
everyWAN
everyWAN