Tag: cve
-
Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers
Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances. This flaw, tracked as CVE-2026-104286, has a CVSS v3.1 score of 9.8. It enables unauthenticated attackers to write arbitrary files to the underlying system via specially crafted HTTP or HTTPS requests. Fortinet FortiMail Path Traversal Flaw…
-
EUVD-2026-56431 / CVE-2026-65660 – Angreifer nutzen SharePoint-Schwachstelle zur Codeausführung aus
Tags: cveFirst seen on security-insider.de Jump to article: www.security-insider.de/sharepoint-luecke-cve-2026-65660-aktiv-ausgenutzt-a-1843fdfe452225e6c07522e33343c1de/
-
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when…
-
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Tags: access, authentication, cisa, cisco, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with First seen on thehackernews.com…
-
Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation
TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related services. These vulnerabilities affect deployments on Windows, Linux, and macOS, and include issues such as remote code execution, session permission bypass, arbitrary privileged file writes, and local privilege escalation. Multiple TeamViewer Vulnerabilities CVE-2026-19743 Path […]…
-
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Tags: access, authentication, cisa, cisco, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with First seen on thehackernews.com…
-
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
Tags: access, authentication, cisa, cisco, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with First seen on thehackernews.com…
-
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in Cisco Catalyst SD-WAN Manager’s…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin
Cisco has disclosed a critical authentication bypass vulnerability in the Catalyst SD-WAN Manager, which could allow unauthenticated remote attackers to access the management API with administrator privileges. This vulnerability, tracked as CVE-2026-76504, has a CVSS v3.1 score of 9.8 and affects the Cisco Catalyst SD-WAN Manager regardless of its configuration. On September 30, 2026, Cisco…
-
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption…
-
Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used to obtain root access, establish persistent control, and collect mailbox authentication secrets. The issue resides in Zimbra’s SNMP notification processing path. An attacker can send a specially crafted SMTP request containing shell metacharacters, allowing attacker-controlled input to reach…
-
EUVD-2026-37030 / CVE-2026-7273 – Angriffe aus dem lokalen Netzwerk auf Zyxel-Switches
First seen on security-insider.de Jump to article: www.security-insider.de/zyxel-gs1900-cve-2026-7273-aktive-ausnutzung-a-f70c3ca42e1108342f52f0d3bb96dddd/
-
WatchGuard fixes critical Fireware OS flaw allowing remote code execution
WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with…
-
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol…
-
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol…
-
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager’s API as the admin user. Fixed releases are available, and there…
-
Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
A critical Docker vulnerability tracked as CVE-2026-17106, also known as CopyEscape, could allow a malicious container to overwrite files on the host machine when a user runs the `docker cp` command. This vulnerability affects copy-out operations, where Docker retrieves data from a container and extracts it onto the system running the Docker Command Line Interface…
-
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
>>Advanced and suspected state-sponsored threat actors<< are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/cve-2026-88772-netscaler-exploitation-zero-day/
-
Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution
Tags: cve, cvss, cyber, cybersecurity, infrastructure, remote-code-execution, service, vulnerabilityA critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a denial-of-service condition. This vulnerability, tracked as CVE-2026-84411, affects MikroTik RouterOS versions earlier than 7.24 and carries a CVSS v3 severity score of 9.8. The Cybersecurity and Infrastructure Security Agency (CISA) disclosed this issue on September…
-
Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug
Google has released Chrome version 154 for desktop platforms, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer. This update is being rolled out as version 154.0.8037.92/.93 for Windows and macOS, and version 154.0.8037.92 for Linux. Google Chrome 154 Update The most severe issue, tracked as CVE-2026-102331, is…
-
Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug
Google has released Chrome version 154 for desktop platforms, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer. This update is being rolled out as version 154.0.8037.92/.93 for Windows and macOS, and version 154.0.8037.92 for Linux. Google Chrome 154 Update The most severe issue, tracked as CVE-2026-102331, is…
-
Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells
Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated root-level access to vulnerable Application Delivery Controller (ADC) and Gateway appliances. After the initial compromise, they deploy custom PHP web shells and tools to tunnel within the internal network. Mandiant Consulting and the Google Threat Intelligence Group…
-
Attackers Use PaperCut RCE Chain to Steal Tokens and Access Domain Controller
Tags: access, authentication, cve, cyber, exploit, rce, remote-code-execution, service, threat, vulnerability, zero-dayThreat actors exploited a chained pair of PaperCut MF zero-day vulnerabilities to compromise an education-sector environment, steal a domain-privileged service account token, and reach a domain controller before attempting to extract the Active Directory database. The campaign abused CVE-2026-81578, an authentication-bypass vulnerability in PaperCut MF and NG’s web management interface, together with CVE-2026-82078, a critical…

