Tag: cve
-
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits allow attackers to take control of print management servers, steal credentials, and deploy Meterpreter payloads within enterprise networks. Analysts Jens Pose and Ross Phillips from Arctic Wolf reported that these intrusions progressed from remote command execution to…
-
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Critical ASUS Control Center Flaw The advisory was published on September 4, 2026, and was last updated on the same day. While the…
-
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Critical ASUS Control Center Flaw The advisory was published on September 4, 2026, and was last updated on the same day. While the…
-
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed threat…
-
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.”A First seen on…
-
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.”A First seen on…
-
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. The post CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-owncloud-nuclear-data-breach-apac-philippines/
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 an authentication bypass and remote code execution chain to conduct command execution and reconnaissance, as well as First…
-
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on…
-
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on…
-
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Google patched CVE-2026-85046, the sixth Chrome zero-day exploited in the wild in 2026. Here’s how to update your browser and stay protected. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-chrome-cve-2026-85046-zero-day/
-
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A high-severity flaw in All-in-One WP Migration leaves 3.25 million WordPress sites exposed, with vulnerable versions potentially leading to site compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-all-in-one-wp-migration-cve-2026-19949/
-
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15,…
-
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 2014, the flaw can be exploited by attackers with low-level replication access to execute code,…
-
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. >>Google is aware that an … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/google-chrome-zero-day-cve-2026-85046/
-
Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary…
-
Google fixes the sixth actively exploited Chrome zero-day of 2026
Tags: browser, chrome, cve, exploit, flaw, google, remote-code-execution, update, vulnerability, zero-dayGoogle patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a…
-
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.The vulnerabilities in question are – CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type,…
-
September 2026 Patch Tuesday forecast: All we need is more time
The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/september-2026-patch-tuesday-forecast/
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome’s JavaScript and WebAssembly engine.”Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a…
-
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for…
-
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for…
-
Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released
Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively being exploited. This flaw can allow remote attackers to execute code within Chrome’s sandbox by convincing a victim to open a specially crafted HTML page. The security update…
-
Inside OWAReaper: How CVE-2026-42897 Enables Persistent Exchange Mailbox Compromise
Tags: cveFirst seen on resecurity.com Jump to article: www.resecurity.com/blog/article/inside-owareaper-how-cve-2026-42897-enables-persistent-exchange-mailbox-compromise
-
Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should-do-and-how-zscaler-can-help/
-
Cisco Fixed Critical RCE in Nexus 9000 Series Switches
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center…
-
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.The Nexus vulnerability,…
-
CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cve-2026-84115-cleo-harmony-jwt-refresh-token/

