June 26, 2026
- curl shipped fixes for a large batch of CVEs including its oldest-ever reported bug (~24–25 years old), with HackerOne reports detailing several credential-leak and connection-reuse flaws — stale proxy passwords (CVE-2026-9079),
.netrcpassword mispairing (CVE-2026-8926), an SSH host-key mismatch silently accepted (CVE-2026-9547), STARTTLS session reuse enabling MITM (CVE-2026-8286), and ASan-validated UAF/Referer leaks (CVE-2026-9546). Aisle, SecurityWeek · Vulnerabilities & Exploits
in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine