BoletimSec•October 6, 2026•🇵🇹Translated from Portuguese

Web Application Vulnerabilities Surge as AI-Driven Development Outpaces Security Testing

The number of vulnerabilities in web applications continues to grow each quarter, with a significant portion of this increase linked to the adoption of artificial intelligence in development workflows.

Integrating AI into the software development process represents a genuine advancement that raises productivity and shortens delivery timelines. The critical issue lies elsewhere: in the rush to launch new products, organizations have accelerated release cycles without scaling security testing and validation at the same rate.

The outcome is a rising volume of code moving into production environments without ever being evaluated through the lens of a potential attack. Cybercriminals recognized this pattern earlier than most organizations. Applications deployed without security reviews tend to repeat the same classes of flaws, allowing attackers to compromise systems built over weeks in a matter of minutes.

Companies are being breached and sensitive data exposed through gaps that proper validation would have detected prior to any incident. This is the point at which pentest activities must be embedded directly into the development cycle. When code changes every week, security testing must occur at matching frequency, whether on a weekly or monthly recurring basis.

Each production update creates a fresh opportunity for attackers, and only continuous testing closes the gap between rapid development and secure development. Treating pentest as an integral process element keeps security aligned with development velocity. This ongoing approach enables teams to detect and fix weaknesses before they reach adversaries seeking to exploit them.

Developing quickly with AI is not the core problem. Publishing code without validating what was generated is what converts velocity into exposure. While development accelerates and the attack surface expands, organizations that test their systems continuously are the ones able to release with the same confidence they apply to innovation.

Related articles

Hispasec•Vulnerabilities & Exploits

LibreOffice and Apache OpenOffice Flaws Enable Remote Code Execution via Malicious Spreadsheets Without Macro Warnings

Two vulnerabilities, CVE-2026-63277 in LibreOffice Calc and CVE-2026-59265 in Apache OpenOffice, allow attackers to execute arbitrary code simply by tricking users into opening specially crafted spreadsheet files. The flaws exploit Java integration and class path handling, bypassing traditional macro security prompts entirely. LibreOffice has already released fixes in versions 26.2.5 and 26.8.0 that restrict class path entries to local file URLs only. Apache OpenOffice 4.1.16 and earlier remain vulnerable, with the stable patch expected in 4.1.17; interim mitigation requires disabling Java integration. The issues highlight risks in office suites that process untrusted documents containing external data connections or JDBC references. Organizations are advised to enforce least-privilege execution and avoid opening files from unknown sources until patches are applied.

BoletimSec•Vulnerabilities & Exploits

Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access

Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.

Habr•Vulnerabilities & Exploits

New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction

Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.

Security NEXT•Vulnerabilities & Exploits

Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score

Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.