ClickHouse has a permission bypass vulnerability where unprivileged users can read restricted data by disabling query validation in UPDATE mutations, which execute with full database privileges. The issue affects ClickHouse 26 and was rejected by the vendor's disclosure program.
Microsoft has closed multiple Windows 11 account bypass methods in recent updates, but a simple workaround persists: clicking a small "Learn more" link during setup unexpectedly allows users to create a local account instead of using a Microsoft account. The method requires no command prompt or technical expertise, and works on the latest Windows 11 Home installation media.
CVE-2026-19490 is a critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway affecting SAML handling. An unauthenticated request exploits the vulnerability to execute post-login code, with impact ranging from crash to root access depending on configuration. Patches are available in versions 13.1-63.21 and 14.1-73.32 or later.