Tag: cve
-
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the…
-
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Tags: access, cve, cybersecurity, data, exploit, flaw, infrastructure, kev, network, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to First seen on…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user’s communications. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/zimbra-flaw-exploitation-shrinking-window-patch
-
Attackers Exploit Critical Flaw in MLflow, an AI Platform Downloaded 30M Times Monthly
The MLflow SSRF flaw CVE-2026-64849 can let unauthenticated attackers access internal services and cloud metadata, potentially exposing sensitive credentials and secrets. First seen on hackread.com Jump to article: hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
-
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system…
-
Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands
Threat actors are actively exploiting a critical operating system command injection vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the zimbra user. Zimbra Collaboration Suite Flaw The flaw specifically affects Zimbra deployments where the SNMP trap notification service is enabled…
-
Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands
Threat actors are actively exploiting a critical operating system command injection vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the zimbra user. Zimbra Collaboration Suite Flaw The flaw specifically affects Zimbra deployments where the SNMP trap notification service is enabled…
-
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete control of affected websites by escalating privileges to the administrator level. This vulnerability, tracked as CVE-2026-19598, carries a CVSS score of 9.8 and affects Pods Custom Content Types and Fields versions up to […]…
-
Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow
A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm. This flaw could potentially allow untrusted JavaScript to escape its V8 isolate and hijack control flow in the host process. The issue is tracked as GHSA-864f-rcv7-6rh4 and is awaiting CVE assignment. It affects isolated-vm versions before 7.0.1 and 6.2.0. Researchers have…
-
U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors…
-
91 Spring CVEs: The AI Vulnerability Consumption Problem
Tags: access, advisory, ai, attack, cloud, cve, cvss, data, data-breach, framework, guide, injection, intelligence, open-source, risk, service, software, tool, update, vulnerability<div cla TL;DR Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects. At the time of publishing, Sonatype Guide currently identifies 209,569 software components affected by the security event. The disclosure comes amid a dramatic rise in AI-assisted vulnerability discovery. Broadcom…
-
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
Tags: access, authentication, control, cve, cvss, cyber, cybersecurity, flaw, malicious, password, vulnerabilityCybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials and take control of a user’s password vault. This vulnerability, tracked as CVE-2026-15580, affects PassPortal version 3.49.5 and has a CVSS v4.0 base score of 9.4. It was patched…
-
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This week, GitLab pushed out an emergency patch to address this flaw, which could let an attacker with zero credentials remotely modify or…
-
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code execution and was…
-
Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind DN, granting them the ability to read or modify data stored in an application’s in-memory LDAP directory. This issue, tracked as CVE-2026-59270, was disclosed on August 20,…
-
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/
-
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring…
-
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant’s cloud-based identity and access management service. It was…
-
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.”A remote code execution vulnerability exists in…
-
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.The vulnerability (“GHSA-864f-rcv7-6rh4”), which has yet to be assigned a CVE identifier, impacts all versions of the library before and…
-
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access sensitive configuration files on affected systems. This vulnerability is tracked as CVE-2026-20320 and is characterized as an out-of-band blind XML External Entity (XXE) injection vulnerability in the Open Client Interface (OCI) XML Parser. Cisco assigned…
-
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August…
-
U.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an MLflow vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-64849 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-64849 is a critical server-side request forgery (SSRF) vulnerability in MLflow, a…
-
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Tags: access, ai, attack, authentication, cve, cyber, data-breach, flaw, Internet, jobs, rce, remote-code-execution, vulnerabilityResearchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI Scanner interfaces, an authentication flaw tracked as CVE-2026-41473, stored cross-site scripting (XSS) tracked as CVE-2026-41472, and CyberPanel’s built-in cron-job functionality. CyberPanel is…
-
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Tags: access, ai, attack, authentication, cve, cyber, data-breach, flaw, Internet, jobs, rce, remote-code-execution, vulnerabilityResearchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI Scanner interfaces, an authentication flaw tracked as CVE-2026-41473, stored cross-site scripting (XSS) tracked as CVE-2026-41472, and CyberPanel’s built-in cron-job functionality. CyberPanel is…
-
Zimbra RCE Vulnerability Lets Remote Attackers Execute System Commands
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform. This vulnerability, tracked as CVE-2026-73570, is an unauthenticated OS command injection issue that allows attackers to execute arbitrary shell commands as the zimbra user. Zimbra RCE Vulnerability The flaw affects Zimbra…

