Security, AI, and other curiosities
Apache HTTP/2 double-free RCE (CVE-2026-23918) with public PoC targets millions of servers; MetInfo CMS unauthenticated PHP injection (CVE-2026-29014) actively exploited with surge in APAC targeting.