Security researchers identified three critical vulnerabilities in Extreme Networks’ HiveOS (CVE-2025-27229, CVE-2025-27228, CVE-2025-27227) allowing attackers to escalate privileges, decrypt passwords, and execute commands. Extreme Networks issued a patch (10.7r5) to address these flaws. The vulnerabilities, which pose significant risks, have been added to CISA’s Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch by March 2025.

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted


