Vulnerability Management Squid proxy vulnerability dubbed Squidbleed discovered June 22, 2026 Share By SC Staff (Adobe Stock) As reported by Security Week, a memory leak vulnerability named Squidbleed has been disclosed in the widely used open-source web proxy software Squid. This vulnerability, officially tracked as CVE-2026-47729, has reportedly existed in the software since 1997. Squidbleed allows an attacker to read beyond the boundary of a memory buffer within Squid's FTP parser. This could expose sensitive data from previous user requests, including authentication credentials, session tokens, and API keys. The vulnerability poses the greatest risk in shared proxy environments like corporate networks, schools, and public Wi-Fi hotspots, where multiple users share a single Squid instance. Exploitation requires the attacker to control an FTP server accessible from the proxy. The exposure is limited to cleartext HTTP traffic and deployments where Squid terminates TLS; standard HTTPS connections are not affected. Security researchers at Calif.io discovered the vulnerability with the aid of Anthropic's Claude Mythos AI model. A patch was merged into Squid version 8 in April 2026 and released in version 7.6 in June 2026. Disabling FTP support entirely can mitigate the risk if it is not needed. Source: Security Week SC Staff Related Vulnerability Management WordPress plugin Gravity SMTP exploited for sensitive information disclosure SC Staff June 22, 2026 The vulnerability resides in an exposed REST API endpoint within the Gravity SMTP plugin. Vulnerability Management Max severity Joomla Content Editor extension flaw targeted in automated attacks Laura French June 17, 2026 The flaw was added to CISA’s Known Exploited Vulnerabilities catalog with a three-day deadline. Vulnerability Management SimpleHelp vulnerability allows unauthenticated attackers to create privileged accounts SC Staff June 16, 2026 The flaw, affecting SimpleHelp versions 5.5.15 and older, and 6.0 pre-release versions, stems from improper validation of identity assertions from an OIDC identity provider. Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds