Tag: cve
-
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io discovered an exposed file directory on August 13, 2026, hosted at 31.58.209[.]241:8000, an Amsterdam-based server registered to CGI Global Limited. The directory was served through…
-
CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability
Tags: cisa, citrix, cve, cyber, cybersecurity, exploit, infrastructure, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. This vulnerability was added on August 26, 2026, and federal civilian agencies are required to apply vendor-recommended mitigations by August 29, 2026. Citrix…
-
TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices
TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an attacker on the same local network to intercept, replay, or forge control messages, potentially manipulating affected products. This issue, tracked as CVE-2026-76784, arises from inadequate cryptographic protections in the protocol used for local communications among Kasa devices. TP-Link has assigned…
-
CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability
Tags: cisa, cve, cyber, cybersecurity, exploit, infrastructure, kev, microsoft, rce, remote-code-execution, service, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability allows an attacker to execute code in the security context of the SQL Server Database Engine service account. Microsoft SQL Server…
-
GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI Pipelines
GitLab has released security updates for both its Community Edition and Enterprise Edition, addressing seven vulnerabilities, including a high-severity flaw in its Duo Claude AI agent. This vulnerability could allow authenticated developers to execute arbitrary commands within a CI (Continuous Integration) context. GitLab Duo Claude AI Agent Flaw The issue, tracked as CVE-2026-18252, arises from…
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Authentication From Service Accounts
Veeam has released security updates for a critical vulnerability in Veeam ONE that could allow an unauthenticated network attacker to coerce SMB authentication from the account running an affected service. Tracked as CVE-2026-65641, the vulnerability received a CVSS v4.0 severity score of 9.3. Veeam disclosed the issue through Knowledge Base article 4905, published on August…
-
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, linux, remote-code-execution, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2019-1068 – A remote code execution vulnerability in First seen on thehackernews.com Jump…
-
274 Zimbra Servers Compromised as 8,200 Remain Unpatched
Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-zimbra-cve-2026-73570-servers-compromised/
-
274 Zimbra Servers Compromised as 8,200 Remain Unpatched
Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-zimbra-cve-2026-73570-servers-compromised/
-
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player…
-
Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code
WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026-57909, have CVSS v4.0 scores of 9.3 and 9.4, respectively. Both issues impact WatchGuard Agent versions earlier than 1.25.13.0000. If exploited, these vulnerabilities could give an…
-
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe issue, tracked as CVE-2026-66152, has a CVSS score of 8.8/10 and affects NetExtender Linux Client versions 10.3.5 and earlier.…
-
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/gitea-cve-2026-60004-exploited-in-the-wild/
-
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19632, has a CVSS score of 9.8 and affects all TranslatePress versions up to 3.3.1. The flaw affects a plugin installed on over 400,000 WordPress sites. Security…
-
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, open-source, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for…
-
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from Oasis Security discovered that NemoClaw’s local Ollama configuration exposes an unauthenticated API, making it susceptible to DNS rebinding attacks.…
-
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code execution on exposed on-premises servers. The flaws, tracked as CVE-2026-55040 and CVE-2026-63520, affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft SharePoint Flaws The urgency has increased after Defused reported…
-
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Tags: access, attack, cve, cybersecurity, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as…
-
Zimbra Exploitation Spreads as Thousands Stay Unpatched
More Than 8,000 Unpatched Instances Remain Exposed to CVE-2026-73570. Attackers have compromised at least 267 Zimbra installations through a likely CVE-2026-73570 campaign, while more than 8,000 unpatched servers remain exposed to unauthenticated remote code execution that can give attackers access to mail data and system resources. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/zimbra-exploitation-spreads-as-thousands-stay-unpatched-a-32654
-
Actively Exploited Oracle WebLogic Bug Gets Patch Order
Federal Agencies Must Apply Oracle’s January Patch by Aug. 27. CISA ordered federal agencies to patch CVE-2026-21962 by Aug. 27 after confirming active exploitation of the maximum-severity Oracle middleware flaw, which lets unauthenticated attackers use crafted HTTP requests to access or modify critical data. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/actively-exploited-oracle-weblogic-bug-gets-patch-order-a-32650
-
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to…
-
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck’s CVE Numbering Authority (CNA) record.The CNA record says the command can run as a local subprocess when the notebook is opened in edit…
-
Multiple Zscaler Client Connector Flaws Enable Remote Code Execution
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context. This vulnerability, tracked as CVE-2026-59568, is rated as Critical, with a CVSS v3.1 score of 9.1. The attack vector is network-accessible and requires no privileges or user interaction. Multiple…
-
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.…
-
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.…
-
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/zimbra-cve-2026-73570-compromised/
-
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability…
-
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later…
-
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.The vulnerabilities, as disclosed by Patchstack, are listed below – CVE-2026-61979 (CVSS score: 8.1) – An unauthenticated privilege escalation…
-
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the…

