CVE-2025-24888 - Code Execution Vulnerability in SecureDrop Client via Malicious Server
Summary:
A critical vulnerability, CVE-2025-24888, was discovered in the SecureDrop Client—a desktop application used in newsrooms for secure source communication. This flaw, fixed in
CVE-2025-26511 - Privilege Escalation in Instaclustr Cassandra-Lucene-Index Plugin—Your Data At Risk
> Summary:
CVE-2025-26511 exposes a dangerous weakness found in the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin, affecting plugin versions 4.-rc1-1.. through 4.