Find notable cyber news and cases, enriched with sources, timelines, and signals.

Dify security patch release for CVE-2026-41947

Security Patch Release
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API traffic. The release addressed CVE-2026-41947, CVE-2026-41949, and CVE-2026-41950, while CVE-2026-41948 remained pending. The patch reduced risk for Dify's multi-tenant cloud service and left one flaw for the next update cycle.

Related Happenings

RabbitMQ maintainers security patch release for CVE-2026-57219

Security Patch Release
H score29 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...

Amazon security patch release for CVE-2026-50549

Security Patch Release
H score29 First: 09.07.2026 14:00 Last: 09.07.2026 14:00 Sources 1

About this happening: Amazon, Google and Cursor shipped fixes for GhostApproval, a flaw in AI coding assistants that let deceptive repository paths bypass approval prompts. The patch response c...

Citrix security patch release for CVE-2026-13474

Security Patch Release
H score35 First: 01.07.2026 06:54 Last: 01.07.2026 06:54 Sources 1

About this happening: Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could enable arbitrary file reads or denial of servi...

NHS England Digital libssh2 update advisory for CVE-2026-55200

Advisory/Mitigation
H score38 First: 29.06.2026 10:06 Last: 29.06.2026 10:06 Sources 1

About this happening: NHS England Digital has issued an update advisory for libssh2 after a public proof-of-concept surfaced for CVE-2026-55200. The flaw can let a malicious or compro...

AWS Amazon Q Developer patch for CVE-2026-12957 and CVE-2026-12958

Security Patch Release
H score18 First: 26.06.2026 18:23 Last: 26.06.2026 18:23 Sources 1

About this happening: AWS released fixes for Amazon Q Developer after a high-severity flaw in the VS Code extension could expose developers’ cloud credentials. The patch set covers CV...

Timeline

  1. 22.06.2026 19:13 2 articles · 23d ago

    Dify ships version 1.14.2 to address most DifyTap flaws

    Mitigation Patch Update

    Dify shipped version 1.14.2 to address most of the DifyTap vulnerabilities, including the authorization-bypass flaws in trace configuration, file preview, and same-tenant file access. CVE-2026-41948 remained pending for a later release, leaving the Plugin Daemon API path traversal flaw unpatched.

    Show sources