CVE-2026-55495
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUTRELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite fi...
Read full story at vulners.comMore Tech news

Apple’s new Upgrade program makes getting a Mac easier, but it may not save you money
Image via Apple Apple has expanded its upgrade program beyond the iPhone, giving customers a new way to get Macs, iPads, Apple Watches, and iPhones without paying the full price upfront. The catch

US' first sixth-gen fighter jet could fly with less powerful engine
Regardless of the engine used initially, the F-47 is expected to be significantly more capable than previous generations of fighters in terms of survivability, networking, sensor fusion, and long-range operations.
RevAPK: Reverse engineer Android apps
submitted by /u/cronocr [link] [comments]
CVE-2026-56672 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/file served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, ...