Tag: cve
-
China-Nexus Threat Actor Targeting Critical VMware Flaw
A China-nexus bad actor is likely behind the rapid exploitation of a critical flaw in VMware’s vCenter management software that has spread across 361 victim IP addresses in almost four dozen countries. Exploitation of the vulnerability tracked as CVE-2026-59310 started five days after VMware owner Broadcom first disclosed the security flaw July 29,.. First seen…
-
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of…
-
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher…
-
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher…
-
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher…
-
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
Zoom patches a zero-click flaw that could let a meeting participant execute code on another user’s computer through the annotation feature. Zoom has patched four vulnerabilities, including a critical zero-click flaw, tracked as CVE-2026-53413, in its annotation feature. CVE-2026-53413 is a memory corruption issue found by A Security that could allow a meeting participant to…
-
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s First…
-
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability-coordination project has had a rocky few years, but a key leader says it will “flourish and improve.” First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cve-program-ai-black-hat-def-con/827477/
-
China-Linked Hackers Use N-able Flaw in Ransomware Attacks
Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure. Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM access, pivot into managed endpoints and rapidly deploy its new StormEncryptor ransomware. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-hackers-use-n-able-flaw-in-ransomware-attacks-a-32506
-
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the Rancher management plane and every downstream Kubernetes cluster it manages. This issue is tracked as CVE-2026-44945 and GHSA-v584-7w32-jwpq, affecting Rancher releases 2.11.0 through 2.11.15, 2.12.0 through 2.12.11, 2.13.0 through 2.13.7, and 2.14.0 through 2.14.1. Rancher has…
-
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, ransomware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tracked as CVE-2026-15409, is a server-side request forgery (SSRF) issue found in the Workplace interface of SonicWall SMA1000 appliances. It has…
-
CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files
Cisco has disclosed seven high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning by submitting specially crafted files. These vulnerabilities are tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348, and have been assigned a maximum CVSS score of 7.5. ClamAV Vulnerabilities The issues are detailed in the Cisco…
-
Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected hub cluster. This vulnerability is tracked as CVE-2026-10090 and affects the Application Subscription controller, specifically the multicluster-operators-subscription. It has a CVSS v3.1 score of 9.9…
-
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/metabase-sql-zero-day-attacks-wide-blast-radius
-
China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks
Microsoft Says Storm-1175 Exploited CVE-2026-18577 After Its Disclosure. Microsoft says China-linked Storm-1175 is exploiting N-able N-central authentication bypass CVE-2026-18577 to gain administrative RMM access, pivot into managed endpoints and rapidly deploy its new StormEncryptor ransomware. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/china-linked-hackers-exploit-n-able-flaw-in-ransomware-attacks-a-32506
-
CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable appliances, posing a significant risk to organizations that expose LoadMaster…
-
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
To help customers fend off ongoing attacks, N-able released a second security hotfix for N”‘central, its monitoring and management (RMM) solution popular with managed service … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/cve-2026-18577-n-central-hotfix-2-msps/
-
EUVD-2026-51270 / CVE-2026-66066 – Auslesen von Serverdateien via Bild-Uploads in Ruby on rails möglich
Tags: cveFirst seen on security-insider.de Jump to article: www.security-insider.de/rails-active-storage-luecke-dateien-auslesen-bild-upload-a-389d6d083f3d912e082f21addd068c3e/
-
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…
-
WordPress XSS2Shell Flaw Enables Attackers to Achieve Remote Code Execution
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login screen and can be chained into full remote code execution. Researchers at pwn.ai discovered the flaw, which carries a CVSS score of 8.9 and affects every actively maintained WordPress branch, a codebase…
-
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address Reconfiguration implementation. Researchers at Tencent Zhuque Lab’s Corvus AI project reported that a local attacker could leverage the flaw to escalate privileges to root and, in certain configurations, to escape from containers to the host.…
-
Critical macOS RCE Vulnerability Allows Attackers to Gain Root Access Without Password
Tags: access, apple, cve, cyber, data-breach, flaw, macOS, password, rce, remote-code-execution, update, vulnerabilityApple has shipped emergency macOS updates to close a critical vulnerability in Screen Sharing, tracked as CVE-2026-65400, which allows unauthenticated remote attackers to execute arbitrary code and access files with root-level privileges. The flaw is especially severe on systems where Screen Sharing is exposed to the public internet. Apple’s August 6 releases macOS Tahoe 26.6.1,…
-
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Tags: access, authentication, business, cve, data, exploit, flaw, intelligence, software, sql, vulnerability, zero-dayMetabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain…
-
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress”¯Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary First seen on…
-
CVE-2026-16812: Critical Command Injection in Arista VeloCloud Orchestrator
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cve-2026-16812-critical-command-injection-in-arista-velocloud-orchestrator
-
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server.Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai, First seen…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Contrast Security Launches CVE Shield for Runtime Exploit Protection
Contrast Security has launched CVE Shield, a runtime control that detects, monitors and blocks exploitation of known vulnerabilities in production applications and APIs while teams work on permanent fixes. Announced July 29 ahead of Black Hat USA 2026, CVE Shield operates inside running applications and uses a microsandbox for each supported CVE. Contrast said the..…
-
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which…
-
Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing deserialization protections within the platform’s Remoting library. This flaw, identified as SECURITY-3911, affects Jenkins environments where agents communicate with controllers via serialized Java objects over Remoting, typically deployed as agent.jar or remoting.jar. The Java serialization…

