Category: Vulnerability News

  • 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

    15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx…

  • Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

    Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue, tracked as CVE-2026-53565,…

  • New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

    New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw,…

  • OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

    OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits how OpenSSL pre-allocates memory during the TLS…

  • Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

    Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. These flaws, tracked as CVE-2026-9770 and CVE-2026-13230, could allow an attacker on the same local network to obtain sensitive information from vulnerable devices. The most serious issue,…

  • CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks

    CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle Payments, a component of Oracle E-Business Suite.…

  • Critical SonicWall Firewall 0-Day Vulnerabilities Actively Exploited in Attacks

    Critical SonicWall Firewall 0-Day Vulnerabilities Actively Exploited in Attacks SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA1000 Series appliances. The company is warning that attackers are actively exploiting these flaws in real-world attacks. The most critical issue, tracked as CVE-2026-15409, carries a maximum CVSS severity score of 10.0 and can…

  • New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry

    New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store configuration…

  • New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

    New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such as .env files. The ASSET Research Group demonstrated that a pull request containing an explicit, plain-text…

  • Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds

    Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. The vulnerability, tracked as CVE-2026-40639 (DSA-2026-197), stems from a broken XOR encryption scheme rather than…

  • Django SQL Injection Vulnerability Actively Exploited in the Wild

    Django SQL Injection Vulnerability Actively Exploited in the Wild A high-severity SQL injection vulnerability in the Django web framework is now being actively exploited in real-world attacks, raising concerns for organizations running geospatial applications on PostGIS-backed deployments. The flaw, tracked as CVE-2026-1207, affects Django’s GIS module and has been confirmed by multiple threat intelligence sources…

  • Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability

    Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain elevated privileges on vulnerable systems. The vulnerability is classified as…

  • New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents

    New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents A newly disclosed vulnerability pattern dubbed “GhostApproval” has exposed a critical security flaw in six of the most widely used AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, allowing malicious repositories to bypass Human-in-the-Loop safety…

  • Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic

    Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending specially crafted network traffic. Tracked as CVE-2026-0288, the flaw carries a CVSS-B score of 9.2 (HIGH,…

  • 15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions

    15-year-old GhostLock Kernel Flaw Enables Privilege Escalation in Major Linux Distributions A critical Linux kernel vulnerability, tracked as CVE-2026-43499 and dubbed “GhostLock,” has been disclosed by security researchers at VEGA, exposing a privilege escalation flaw that has silently affected major Linux distributions for over a decade. GhostLock originates from a logic error in the kernel’s…

  • 16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory

    16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed “Januscape,” exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained unnoticed for nearly…

  • Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access

    Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access BeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, potentially allowing attackers to bypass access controls and gain unauthorized access to sensitive systems. The issues are tracked under Advisory ID BT26-03 and carry…

  • Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website

    Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website A newly disclosed vulnerability in Opera GX allowed attackers to silently exfiltrate sensitive user data with no interaction required, simply by luring victims to a malicious website. The issue, documented in recent research titled “One trigram at a time: XSLeak via Universal CSS…

  • Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks

    Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks Security researchers at runZero have disclosed seven new CVEs affecting FatFs, the ubiquitous lightweight FAT/exFAT filesystem driver used across embedded and IoT ecosystems. The vulnerabilities range from CVSS Medium to High, with no Critical-rated findings, but their reach is significant: FatFs underpins platforms including…

  • New “Bad Epoll” 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices

    New “Bad Epoll” 0-Day Vulnerability Allows Root Access on Linux Servers and Android Devices A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged local user to escalate to root on Linux servers, desktops, and Android devices by exploiting a race condition and a use-after-free (UAF) in the kernel’s epoll subsystem. Bad…

  • Multiple WatchGuard Firebox OS Vulnerabilities Enable Arbitrary Code Execution Attacks

    Multiple WatchGuard Firebox OS Vulnerabilities Enable Arbitrary Code Execution Attacks Multiple high‑severity vulnerabilities in WatchGuard Firebox devices running Fireware OS could let authenticated attackers execute arbitrary code and take full control of affected appliances. WatchGuard has disclosed three high‑impact vulnerabilities in Fireware OS affecting Firebox firewall appliances, all scored 8.6 under CVSS v4.0 and already…

  • Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit

    Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit Security researchers from HawkTrace have disclosed technical details of a high-severity server-side request forgery (SSRF) vulnerability in Microsoft Exchange, tracked as CVE-2026-45504. The flaw, which carries a CVSS score of 8.8, allows authenticated, low-privileged users to read arbitrary files from vulnerable Exchange servers, raising…

  • Hacker Used Claude AI to Score Free Tickets to Nearly Every US Music Show

    Hacker Used Claude AI to Score Free Tickets to Nearly Every US Music Show A critical unauthenticated SQL injection vulnerability in Front Gate Tickets (FGT), a Live Nation/Ticketmaster subsidiary that powers ticketing for major US festivals including EDC, Bonnaroo, and Outside Lands, allowed full administrative takeover of the platform with help from Anthropic’s Claude AI…

  • CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks

    CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in Attacks CISA has added a newly disclosed Microsoft SharePoint Server vulnerability, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is actively being exploited in real-world attacks. The vulnerability is a deserialization of untrusted data issue (CWE-502) that allows…

  • Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition

    Multiple ClamAV Vulnerabilities Allow Remote Attacker to Cause a DoS Condition Multiple high-severity vulnerabilities in Cisco’s ClamAV engine allow remote attackers to crash the antivirus scanning process, causing a denial-of-service (DoS) on affected Cisco Secure Endpoint Connector deployments. The flaws affect Windows, Linux, and macOS, with the highest impact on Windows, where they are rated…

  • WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes

    WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or further exploitation. WinRAR 7.23…

  • Chrome Update Fixes 382 Vulnerabilities, Including 15 Critical Ones – Update Now!

    Chrome Update Fixes 382 Vulnerabilities, Including 15 Critical Ones – Update Now! Chrome 151’s latest stable-channel update delivers patches for 382 security vulnerabilities, including 15 critical bugs that can be weaponized for remote code execution and full browser compromise if left unpatched. Google is rolling this update out for Windows, macOS, Linux, and Chrome for…

  • Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication

    Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication The Apache Software Foundation has disclosed two vulnerabilities affecting Apache Tomcat that could allow attackers to bypass authentication and security constraints protecting web applications. The flaws, tracked as CVE-2026-55957 and CVE-2026-55956, impact multiple major versions of the widely deployed servlet container, prompting urgent upgrade recommendations across…

  • New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets

    New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets A new Linux kernel local privilege escalation vulnerability, dubbed “DirtyClone” (CVE-2026-43503), that allows unprivileged local users to gain full root access by manipulating cloned network packets through the XFRM/IPsec subsystem, all without leaving a trace in kernel logs or audit records. DirtyClone…

  • Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments

    Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments A high-severity vulnerability in the Amazon Q Developer Extension for Visual Studio Code (VS Code), Amazon’s AI-powered coding assistant. Tracked as CVE-2026-12957 and CVE-2026-12958 and disclosed by Wiz Research, the flaws allowed attackers to achieve arbitrary code execution and cloud credential theft simply…

  • CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks

    CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to apply patches immediately amid active exploitation in the wild. The flaw, tracked as CVE-2026-20230, enables…

  • Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks

    Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks Google has released a critical security update for its Chrome browser, pushing the Stable channel to version 149.0.7827.196/197 for Windows and Mac, and 149.0.7827.196 for Linux. The update addresses 18 security vulnerabilities, including four rated Critical and fourteen rated High severity,…

  • FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials

    FortiBleed Attack Hit 430,000+ FortiGate Firewalls, Stealing 110M+ Credentials A large-scale, ongoing credential-harvesting campaign dubbed “FortiBleed” has silently compromised more than 430,000 FortiGate firewalls globally, siphoning over 110 million credentials directly from live network traffic since at least February 2026. The campaign came to light after security researcher Volodymyr “Bob” Diachenko discovered an exposed directory…

  • Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability

    Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability A researcher has earned a total of 148,337 USD from Google for uncovering a set of flaws in Google Cloud’s Application Integration service that escalated into remote code execution (RCE) in Google Cloud production. The core bug is now tracked as CVE‑2026‑2031. The researcher Arvin Shivram…

  • Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets

    Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets A critical security vulnerability has been identified in the widely used libssh2 library, allowing remote attackers to execute arbitrary code through specially crafted SSH packets. The flaw, tracked as CVE-2026-55200, carries a CVSS score of 9.2 and is classified under CWE-680 (Integer…

  • Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files

    Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files A critical vulnerability has been disclosed in FFmpeg’s MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in some scenarios, achieve remote code execution (RCE). The flaw, tracked as CVE-2026-8461 and dubbed “PixelSmash,” is a heap out-of-bounds write in FFmpeg’s libavcodec component, with…

  • CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation

    CISA Adds LiteSpeed cPanel Plugin Vulnerability to KEV List Following Active Exploitation CISA has added a critical LiteSpeed cPanel Plugin vulnerability, tracked as CVE-2026-54420, to its Known Exploited Vulnerabilities (KEV) catalog following evidence of active exploitation in the wild. The flaw affects shared hosting environments and poses a significant risk to servers running CloudLinux with…

  • Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers

    Chrome Extensions’ Critical Flaws Let Attackers Easily Compromise Millions of Browsers Critical security flaws discovered in widely used Chrome extensions SiderAI and MaxAI are putting millions of users at risk, enabling attackers to fully compromise browser sessions and potentially access sensitive data across websites and local systems. Security researchers at Rebora Security uncovered vulnerabilities dubbed…

  • Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks

    Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1,…

  • CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks

    CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks CISA has issued a high-priority alert warning organizations about a critical vulnerability in Splunk Enterprise that is actively being exploited in the wild. The flaw, tracked as CVE-2026-20253, has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling immediate risk to enterprise…

  • Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses

    Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses Node.js has released a new round of security updates addressing 12 vulnerabilities across its supported release lines, including two high-severity flaws that could lead to authentication bypass and denial-of-service (DoS) attacks. The updates impact Node.js versions 22.x, 24.x, and 26.x, with patched releases now available as…

  • Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch

    Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed “RoguePlanet,” and confirmed it is actively developing a security patch to address the flaw. Tracked as CVE-2026-50656, the vulnerability was formally published on June 16, 2026, by the Microsoft Security Response…

  • Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection

    Critical LiteLLM Flaw Allows Authentication Bypass via Host Header Injection A critical security vulnerability has been disclosed in LiteLLM, an increasingly popular proxy used for managing large language model (LLM) APIs. The flaw, tracked as CVE-2026-49468, allows attackers to bypass authentication mechanisms under specific conditions by exploiting improper handling of the Host header. The issue…

  • Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now!

    Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code – Update Now! Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Users are strongly advised to update immediately as several flaws impact core browser components. The latest Chrome…

  • Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code

    Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Microsoft released critical fixes for three closely related remote code execution (RCE) vulnerabilities in Microsoft Outlook and Word that stem from low‑level memory‑safety flaws in the Word rendering engine and its integration with Outlook Classic. These bugs, tracked as CVE‑2026‑45456, CVE‑2026‑45458, and CVE‑2026‑47635, are…

  • Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User

    Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Palo Alto Networks fixed a new command injection vulnerability in PAN‑OS (CVE-2026-0273) that allows authenticated administrators to execute arbitrary commands as root via the CLI or web management interface. Two related medium‑severity issues in the same advisory window cover CLI privilege escalation…

  • Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code

    Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Google has released a new Chrome security update addressing 28 vulnerabilities, including several critical flaws that could allow attackers to execute malicious code on affected systems. The latest Stable channel update upgrades Chrome to version 149.0.7827.114/.115 on Windows and macOS, and to 149.0.7827.114…

  • Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data

    Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Microsoft has disclosed a significant security vulnerability in Microsoft Teams for Android that could allow an authenticated attacker to expose sensitive information over a network. The flaw, tracked as CVE-2026-42835, was officially released on June 9, 2026, and has been rated Important in severity.…

  • Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email

    Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks Using Weaponized Email Microsoft has confirmed active exploitation of a new zero‑day spoofing flaw in on‑premises Exchange Server, tracked as CVE‑2026‑42897. The flaw allows attackers to execute arbitrary JavaScript in Outlook Web Access (OWA) simply by sending a weaponized email that a victim opens in a browser.…

  • Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks

    Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks A high-severity vulnerability, CVE-2026-6973, in Ivanti Endpoint Manager Mobile (EPMM) could allow authenticated attackers to achieve remote code execution by injecting malicious Apache configuration directives. The flaw, assigned a CVSS score of 7.2, is classified as a configuration control vulnerability (CWE-15) and affects multiple versions…

  • New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers

    New Windows Defender 0-Day Exploit “RoguePlanet” Grants SYSTEM Access to Attackers A researcher known as Nightmare Eclipse (also tracked as Chaotic Eclipse or Dead Eclipse) has publicly released a new proof-of-concept (PoC) exploit named RoguePlanet, targeting a previously undisclosed race condition vulnerability in Microsoft Windows Defender. When successfully executed, the exploit spawns a command shell…

  • Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary Commands

    Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary Commands Threat actors are actively exploiting a critical chained vulnerability in LiteLLM, a popular open-source AI gateway proxy, allowing unauthenticated remote code execution (RCE) on vulnerable deployments. Researchers at Horizon3.ai confirmed that combining two CVEs creates a CVSS 10.0 Critical attack path requiring zero…

  • SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched

    SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched SAP’s June 2026 Security Patch Day, observed on Tuesday, June 9, delivered 15 new security notes addressing a broad range of vulnerabilities across core SAP products, including four critical-severity flaws that demand immediate enterprise attention. SAP strongly urges all customers to visit the SAP…

  • Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws

    Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws The Apache Software Foundation released Apache HTTP Server version 2.4.68 on June 8, 2026, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, cross-site scripting, heap-based buffer overflows, denial-of-service, privilege escalation, and out-of-bounds read issues affecting…

  • Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

    Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in…

  • Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server

    Critical Redis RCE Vulnerability Enable Attackers to Gain Complete Control to Host Server In May 2026, Redis developers fixed a dangerous post-authentication remote code execution vulnerability, dubbed DarkReplica (CVE-2026-23631), that allowed attackers to gain full control of a Redis host. Redis provides powerful server-side Lua engines, allowing administrators to run custom logic directly in the…

  • CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks

    CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The issue, categorized as improper authentication, affects Linux…

  • CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

    CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in the wild. Tracked as CVE-2026-28318, the vulnerability affects SolarWinds Serv-U file transfer software and…

  • Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks

    Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks A newly disclosed critical vulnerability in the HuggingFace Transformers library, tracked as CVE-2026-4372, allows attackers to achieve remote code execution (RCE) through malicious model configuration files. The flaw exposes a significant supply chain risk in one of the most widely used machine learning frameworks, impacting…

  • Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User

    Cisco SD-WAN Vulnerability Exploited in the Wild to Execute Arbitrary Commands as Root User Cisco has disclosed a high-severity vulnerability in its Catalyst SD-WAN Manager that is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges. The issue, tracked as CVE-2026-20245, carries a CVSS score of 7.8 and stems…

  • Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code

    Microsoft Edge Vulnerability Allows Remote Attackers to Execute Arbitrary Code Microsoft has released a security update addressing a critical vulnerability in Microsoft Edge that could allow remote attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2026-45495 and reported by Orange Tsai of DEVCORE, the flaw carries a CVSS v3 score of 7.5 and…

  • Acer Working to Patch Wave 7 Router 0-day Vulnerability

    Acer Working to Patch Wave 7 Router 0-day Vulnerability Acer is preparing a firmware update to address a critical zero-day vulnerability affecting its Wave 7 routers, following disclosure by independent security researcher Gergo Pap. The issue affects devices running firmware versions earlier than and poses a significant risk due to unauthenticated remote exploitation. According to…

  • 1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

    1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a victim into clicking a single malicious link. The bug was publicly disclosed on June 2, 2026, by security…

  • Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control

    Android 0-Day Vulnerability Exploited in Attacks to Gain Complete Device Control A critical Android zero-day vulnerability is being actively exploited in targeted attacks, allowing threat actors to gain near-complete control over affected devices without any user interaction. The flaw, tracked as CVE-2025-48595, was highlighted in the June 2026 Android Security Bulletin, where Google confirmed limited…

  • Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication

    Critical StrongDM Vulnerability Allows Attackers to Steal and Reuse Authentication A critical authentication flaw in StrongDM’s desktop application has been identified that allows attackers to hijack user sessions by reusing locally stored authentication material, potentially exposing sensitive enterprise infrastructure. The issue, tracked as CVE-2026-4387, was discovered by SpecterOps during a security assessment and has been…

  • Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild

    Palo Alto Networks PAN-OS Authentication Vulnerability Bypass Exploited in the Wild Palo Alto Networks authentication bypass vulnerability, CVE-2026-0257, affecting PAN-OS and Prisma Access, is now being actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on May 29, 2026. Palo Alto Networks published its security advisory on May…

  • Critical Samba Vulnerability Enables Remote Code Execution Attacks

    Critical Samba Vulnerability Enables Remote Code Execution Attacks A critical vulnerability in the Samba printing subsystem, tracked as CVE-2026-4480, has been disclosed, allowing unauthenticated attackers to achieve remote code execution (RCE) on affected systems. The flaw carries a maximum CVSS v3.1 score of 10.0, highlighting its severe impact and ease of exploitation. Samba, widely used…

  • Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones

    Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones Google has pushed a major Chrome Stable update that fixes 151 security flaws, including 22 critical vulnerabilities affecting core graphics, networking, media, and UI components across Windows, macOS, and Linux. The Stable channel has been updated to version 148.0.7778.216/217 for Windows, 148.0.7778.215/216 for macOS, and…

  • VS Code Remote-SSH RCE Lets Attackers Pivot From Developer Machines to Cloud Servers

    VS Code Remote-SSH RCE Lets Attackers Pivot From Developer Machines to Cloud Servers A newly disclosed vulnerability in Visual Studio Code’s Remote-SSH extension exposes a critical post-compromise attack path that allows threat actors to pivot from infected developer machines into cloud and production environments. Given the extension’s widespread adoption across modern development workflows, the issue…

  • Veeam Backup & Replication Tool Vulnerability Enables Privilege Escalation Attacks

    Veeam Backup & Replication Tool Vulnerability Enables Privilege Escalation Attacks Veeam has addressed a high-severity vulnerability in its Backup & Replication platform that could enable attackers to escalate privileges and gain deeper access to enterprise systems. The issue impacts Veeam Backup & Replication version 13.0.1.2067 and all earlier version 13 builds, prompting urgent patching recommendations…

  • Critical Notepad++ Vulnerabilities Allow Attackers to Execute Arbitrary Code

    Critical Notepad++ Vulnerabilities Allow Attackers to Execute Arbitrary Code Notepad++, one of the most widely used open-source text editors for Windows, has released an urgent security update addressing three vulnerabilities, including two arbitrary code execution flaws that could allow attackers to silently run malicious programs on a victim’s machine. The Notepad++ development team released version…

  • New 0-Click WhatsApp Account Takeover Attack Targeting iOS 16 Users

    New 0-Click WhatsApp Account Takeover Attack Targeting iOS 16 Users A new 0-Click WhatsApp Account Takeover Attack Targeting iOS 16 Users is raising serious concerns after multiple iPhone users reported their accounts being hijacked without any interaction, warnings, or visible linked devices. According to a recent forensic investigation by the Italian security firm Forenser, attackers…

  • PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw

    PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw PuTTY 0.84 has been released with fixes for multiple minor security flaws, including issues that could trigger SSH key exchange crashes and a Telnet prompt spoofing weakness. While these vulnerabilities are considered low severity, they highlight how even small flaws in…

  • New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems

    New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s NTFS archive handler. Tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, the flaw resides…

  • CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classified under CWE-89, affects Drupal’s database abstraction API and could allow attackers to execute malicious…

  • Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

    Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now! A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip, the vulnerability affects both NGINX Plus and NGINX Open Source, and can be triggered by…

  • Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data

    Splunk Patches Multiple Vulnerabilities that Enable DOS Attack and Exposes Sensitive Data Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238,…

  • CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks

    CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations of active exploitation risks. The flaw, tracked as CVE-2026-34926, affects on-premise deployments of Trend Micro Apex One…

  • Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users

    Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users Google has publicly released proof-of-concept (PoC) exploit code for a critical, still-unpatched vulnerability in the Chromium codebase, potentially exposing millions of users across Chrome, Microsoft Edge, and other Chromium-based browsers to stealthy botnet-style abuse. The vulnerability, originally reported in late 2022 by independent…

  • Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys

    Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, exposes a serious local privilege escalation flaw that has remained undetected for nearly nine years. Security researchers at the Qualys Threat Research Unit (TRU) revealed that the issue allows attackers to exfiltrate sensitive data, including SSH…

  • New Microsoft Defender 0‑Days Actively Exploited in the Wild

    New Microsoft Defender 0‑Days Actively Exploited in the Wild Two newly disclosed Microsoft Defender vulnerabilities are being actively exploited in the wild, enabling local attackers to elevate privileges to SYSTEM and potentially disrupt endpoint protection across Windows environments. The bugs, tracked as CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service), were published on May…

  • Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access

    Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access Cisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain unauthorized access to sensitive resources via internal APIs. The flaw, tracked as CVE-2026-20223, carries a maximum CVSS score of 10.0 and is categorized under CWE-306 (Missing Authentication…

  • Critical Drupal Core Security Vulnerability Exposes Websites to Cyberattack

    Critical Drupal Core Security Vulnerability Exposes Websites to Cyberattack A highly critical security vulnerability in Drupal core is set to impact websites worldwide, with the official security release scheduled for May 20, 2026. The vulnerability has been assigned a “Highly Critical” severity rating (20/25), indicating potential risks to confidentiality and integrity across affected systems. While…

  • New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code

    New NGINX Vulnerability Allow Remote Attackers to Trigger Malicious Code A new vulnerability in NGINX JavaScript (njs), tracked as CVE‑2026‑8711, allows unauthenticated remote attackers to trigger a heap‑based buffer overflow that can lead to denial‑of‑service and, in some conditions, remote code execution in the NGINX worker process. The flaw is tied to how the js_fetch_proxy…

  • PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability

    PoC Exploit Released for 20-Year Old PostgreSQL RCE Vulnerability A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2005, a critical remote code execution (RCE) vulnerability affecting PostgreSQL’s pgcrypto extension. The flaw, rooted in legacy code dating back nearly two decades, highlights the long-standing risks associated with memory handling issues in widely deployed database systems.…

  • Hackers Actively Exploiting Critical NGINX RCE Vulnerability in the Wild

    Hackers Actively Exploiting Critical NGINX RCE Vulnerability in the Wild Hackers are wasting no time exploiting a newly disclosed critical vulnerability in NGINX, with security researchers already observing real-world attacks just days after its public release. Security researcher Patrick Garrity from VulnCheck revealed that threat actors are actively targeting CVE-2026-42945, a heap buffer overflow flaw…

  • CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks

    CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying on on-premises email infrastructure. The flaw CVE-2026-42897 is a cross-site scripting (XSS) vulnerability affecting Microsoft Exchange Server, specifically within…

  • New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released

    New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released A critical Windows privilege escalation zero-day vulnerability dubbed “MiniPlasma” has emerged with a public proof-of-concept exploit that allows attackers to achieve SYSTEM-level privileges on fully patched Windows systems. Security researcher Nightmare-Eclipse released the weaponized exploit on GitHub on May 13, 2026, claiming that…

  • Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks

    Critical WordPress Plugin Vulnerability Exposes Websites to Authentication Bypass Attacks A critical vulnerability in a widely used WordPress plugin has exposed over 200,000 websites to full account takeover, raising urgent concerns across the security community. Discovered on May 8, 2026, by Wordfence’s AI-powered PRISM threat intelligence platform, the flaw affects the Burst Statistics plugin, a…

  • First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

    First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days Apple’s M5 silicon has reportedly been exploited for the first time in a public macOS kernel memory corruption attack, successfully bypassing the company’s notable hardware-level memory protection. Researchers from Calif, Bruce Dang, Dion Blazakis, and Josh Maine, developed a working…

  • Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address

    Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address A newly disclosed flaw in Android 16 is raising serious privacy concerns after researchers revealed that malicious apps can bypass VPN protections and expose a user’s real IP address even when strict security settings are enabled. The vulnerability, dubbed the “Tiny UDP Cannon,”…

  • VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root

    VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked as CVE-2026-41702, the flaw was privately reported to Broadcom and patched on May 14, 2026, under security advisory VMSA-2026-0003.…

  • 79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now!

    79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now! Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsing the web on an outdated version leaves your entire system wide open…

  • Windows DNS Client Vulnerability Enables Remote Code Execution Attacks

    Windows DNS Client Vulnerability Enables Remote Code Execution Attacks A newly disclosed vulnerability in the Microsoft Windows DNS Client could let attackers silently execute malicious code across enterprise networks, exposing a massive attack surface. Officially designated as CVE-2026-41096, this critical security flaw carries a severe CVSS score of 9.8 out of 10. By simply returning…

  • Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks

    Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks A critical heap buffer overflow vulnerability has been discovered in the source code of NGINX, present since 2008. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution (RCE) against one of the most widely used web…

  • Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks

    Microsoft Teams Vulnerability Allows Hackers to Perform Spoofing Attacks A newly disclosed security vulnerability in Microsoft Teams could allow attackers to spoof local devices, raising concerns for enterprises and individual users who rely on the platform for daily communications. Microsoft disclosed CVE-2026-32185 on May 12, 2026, as part of its coordinated May 2026 Patch Tuesday…

  • Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks

    Critical PHP SOAP Extension Vulnerabilities Enables Remote Code Execution Attacks A serious cluster of vulnerabilities has been uncovered in PHP’s core string processing and ext-soap components, putting numerous web servers at immediate risk of total takeover. While the SOAP extension has a notorious history of memory corruption flaws, this latest discovery crosses the red line…

  • New cPanel and WHM Flaws Enable Code Execution, DoS Attacks

    New cPanel and WHM Flaws Enable Code Execution, DoS Attacks cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection,…

  • Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

    Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators. Microsoft’s Security Response Center published advisories for CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 as…

  • Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

    Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline built around Anthropic’s Claude Mythos…