Featured Posts
All Posts
.png)
Security
Aug 14, 2026
PostgreSQL 14 EOL Nov 2026: 44 CVEs This Year, One Patch Left
The security risk of sticking with an aging database version, and why the CVE spike makes upgrading urgent.
Greg Allen
.png)
Compliance
Aug 14, 2026
NIS2 and End-of-Life Dependencies: What Compliance Teams Need to Know
NIS2 treats an unsupported dependency as a known, quantifiable risk. If it is not in your risk plan, that is a gap.
Rob Nalen

Security
Aug 11, 2026
CVE-2026-59888: Jackson Record @JsonIgnore Bypass via Naming Strategy
How a property-collection ordering bug lets renamed JSON keys write to Record components marked @JsonIgnore
Greg Allen

EOL Software
Aug 10, 2026
The Top 5 Reasons Why Organizations Choose HeroDevs for Never-Ending Support
Secure and Compliant Legacy Software: Why 800+ Enterprises Trust HeroDevs Never-Ending Support
Javier Perez

Security
Aug 7, 2026
Why a Post-End-of-Life CVE Is Different From a Normal Vulnerability
A normal CVE comes with a patch. A post-end-of-life CVE usually does not, and it stays open indefinitely.
Mark Szymanski
.png)
Security
Aug 6, 2026
CVE-2026-69149, CVE-2026-68945 and CVE-2026-69151: Angular SSR XSS, Transfer Cache Poisoning, and i18n XSS
How unescaped SSR serialization, ambiguous transfer-cache keys, and translatable event-handler attributes let attackers inject script and poison server-rendered responses across three related Angular vulnerabilities
Greg Allen

EOL Software
Aug 6, 2026
Is It Safe to Keep Running End-of-Life Software in Production?
Unsupported software keeps running, but every new vulnerability becomes permanent. How to weigh the risk honestly.
Taylor Corbett
.png)
Risk Mitigation
Aug 5, 2026
CVE-2026-55856 Through 55860 and CVE-2026-61700: MariaDB Connector CVEs in Spring Boot
Six MariaDB Connector/J and R2DBC vulnerabilities affect multiple versions of Spring Boot's dependency tree
Greg Allen

EOL Software
Aug 5, 2026
Is AngularJS Still Supported in 2026?
The framework has been end-of-life since December 2021. Here is what that means for security, compliance, and your options.
Javier Perez

Security
Aug 4, 2026
CVE-2026-39852: Quarkus Authorization Bypass via Matrix Parameters
How a matrix-parameter path-normalization mismatch lets an unauthenticated request slip past Quarkus authorization policies
Greg Allen

Security
Aug 4, 2026
July 2026 .NET Patch Tuesday: 14 CVEs Also Affect .NET 6
How fourteen of Microsoft's seventeen July Patch Tuesday .NET fixes reach back into the end-of-life .NET 6 line, and why the advisory metadata will mislead your scanner
Greg Allen

EOL Software
Aug 4, 2026
Is Node.js 18 End of Life, and Is It Safe to Keep Running?
Node.js 18 stopped receiving security patches on April 30, 2025 and what that means for production and how to move forward.
Javier Perez

Security
Aug 3, 2026
MessagePack-CSharp Patches 12 CVEs Affecting .NET 6 and SignalR
How attacker-controlled sizes, recursion depths, and dictionary comparers produced a twelve-CVE denial-of-service batch across every MessagePack-CSharp release line
Greg Allen

Security
Aug 3, 2026
Node.js July 2026 Security Release: 11 CVEs, Node 18 and 20 EOL
Eleven CVEs were patched upstream in Node 22, 24, and 26, including three High-severity flaws in HTTP/2 and the Permission Model. Node 18 and 20 received nothing, and the two EOL lines still pulled more than 136 million downloads in July.
Greg Allen

EOL Software
Aug 3, 2026
Quarkus Versions, EOL Dates, and Latest Releases (July 2026)
Understand Quarkus support lifecycles, identify end-of-life versions, and plan your migration to supported LTS releases.
Greg Allen
.png)
.png)
.png)