Tag: cve
-
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of July, JetBrains released security updates for TeamCity…
-
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Tags: access, cisa, cve, cybersecurity, data, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityA newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity…
-
Cisco Patches 7 IOS XE Vulnerability Classes, Including Critical Command Injection Flaws
Cisco has released security-hardening updates for IOS XE Software that address seven classes of vulnerabilities, including a critical command, operating system, and argument injection category identified as CVE-2026-20272. The advisory, released on August 5, has an overall CVSS score of 3.1 and 9.8 and provides no workarounds, meaning that upgrading is the only recommended solution.…
-
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
Tags: cisa, cve, cyber, cybersecurity, data-breach, exploit, flaw, infrastructure, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. This flaw allows unauthenticated remote code execution (RCE) on vulnerable TeamCity On-Premises servers exposed via HTTP or HTTPS. CISA Issues on TeamCity RCE…
-
U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first issue added to the catalog, tracked as CVE-2026-9198, is a critical issue in IBM…
-
OVSwrap Open vSwitch Flaw Lets Unprivileged Linux Users Gain Root Access
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch (OVS) implementation. This vulnerability could allow unprivileged local users to gain root-level access on affected systems. Researcher Asim Viladi Oglu Manizada reported this issue on July 28 after coordinating with the Linux kernel security team…
-
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by…
-
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.The file-read flaw is tracked as CVE-2026-59774, rated Critical with a…
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote attacker to execute arbitrary code on an affected agent host. This issue, identified as CVE-2026-64633, has received the highest CVSS v4.0 score of 10.0, indicating it is the most severe vulnerability addressed in…
-
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full…
-
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
A leaked n8n API key is only the start. GitGuardian’s research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/securing-agentic-ai-workflows-in-n8n-from-leaked-api-keys-to-encryption-key-compromise/
-
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CVE-2026-58048 (CVSS score of 9.4), that let an ordinary authenticated hosting customer,…
-
CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV
Tags: authentication, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability allows unauthenticated attackers to bypass authentication and potentially take over administrative accounts on vulnerable N-central servers. CISA added this flaw to the KEV Catalog on August…
-
Thermo Fisher Patches Forensic DNA File Tampering Flaw in Its Software
Thermo Fisher patched CVE-2026-17583 in five supported DNA analysis products by adding digital signatures that help laboratories detect modified forensic files. First seen on hackread.com Jump to article: hackread.com/thermo-fisher-forensic-dna-file-tampering-flaw/
-
U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an…
-
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.The database bug is tracked as CVE-2026-58048 (CVSS 4.0…
-
Critical Gitea Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers and escalate to remote code execution (RCE). This vulnerability is tracked as CVE-2026-59774 and GHSA-6v53-hr58-556r, affecting Gitea versions from 1.22.11.22.11.22.1 to 1.27.01.27.01.27.0. It has been assigned a critical CVSS score of 3.1, with an attack…
-
macOS CUPS Flaw Lets Local Attackers Write Arbitrary Files as Root
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protection (SIP), thereby gaining root ownership. This flaw, tracked as CVE-2026-39875, affects Apple devices running macOS Sonoma, Sequoia, and Tahoe versions before…
-
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vulnerability is tracked as CVE-2026-18574 and is detailed in Check Point Security Alert sk185222. It affects multiple legacy and current versions of their management platform.…
-
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows First seen…
-
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an…
-
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The issue, tracked as CVE-2026-17583, carries a CVSS v4 score of 8.2 and affects .fsa and .hid file outputs used in forensic…
-
The End of Centralized Enrichment: What NIST’s NVD Shift Means for Vulnerability Management
There’s an assumption baked into most vulnerability management programs that nobody ever wrote down, because nobody had to. When a CVE gets published, NVD enriches it. You get a severity score, product mappings, weakness categorization. All the context your tools and workflows need to actually do something. It was just how the system worked. In..…
-
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
-
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According…
-
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.Thermo Fisher tracks the issue as CVE-2026-17583 and…
-
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers. In the default configuration, applications that generate image variants may expose…
-
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.N-central is the remote monitoring and management platform First seen…
-
Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks
Tags: access, authentication, control, cve, cyber, exploit, flaw, monitoring, msp, network, vulnerabilityN-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform, following confirmation of active exploitation. This vulnerability, tracked as CVE-2026-18577, affects N-central servers running earlier than version 2026.3.1.7. It allows a remote, unauthenticated attacker to take over accounts and gain administrative control of the…

