A vulnerability reporter says Xray-core’s certificate pinning could be bypassed and alleges the initial fix was incomplete and not disclosed.
Browsing Category
Vulnerability Intelligence & Disclosure
34 posts
Several Vulnerabilities Have Been Discovered In The Linux Kernel
Debian’s DSA-6528-1 lists a large set of Linux kernel CVEs. The advisory identifies an update, but supplied details do not specify severity or affected releases.
Why Vulnerability Management Needs Business Owners
Learn how business owners help prioritize vulnerability fixes, balance service disruption, and turn security findings into accountable risk decisions.
What Remediation Verification Means After a Fix
Remediation verification is checking that a reported security weakness is actually fixed — not just patched, ticketed, or scanned. Here’s how to do it right.
How to Track Vulnerabilities Across Multiple Products
A practical guide to tracking vulnerabilities across products: SBOMs, CVE matching, prioritization, and remediation records that hold up.
Why Public Proofs of Concept Can Create Real Risk
Learn when public vulnerability demos help defenders, when they lower the bar for attackers, and how teams can respond safely.
How Vendors Decide Whether to Credit a Researcher
Why security researchers sometimes get public credit for a bug — and sometimes don’t. The factors vendors weigh, and how to protect your attribution.
What a Disclosure Timeline Should Balance
Learn how to balance speed and accuracy in security disclosure timelines — who to notify, when, and how to avoid the mistakes that leave people exposed.
Why Duplicate Vulnerability Reports Are So Common
Discover why duplicate vulnerability reports happen so often in bug bounties and disclosure — plus how researchers and programs can reduce wasted effort.
CVE-2026-88772: Citrix NetScaler Improper Restriction Of Operations Within The Bounds Of A Memory Buffer Vulnerability Actively Exploited (CISA KEV)
CISA lists CVE-2026-88772 in its Known Exploited Vulnerabilities catalog. The supplied notice gives few details on affected versions or remediation.