Tag: cve
-
macOS CUPS Flaw Lets Local Attackers Write Arbitrary Files as Root
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protection (SIP), thereby gaining root ownership. This flaw, tracked as CVE-2026-39875, affects Apple devices running macOS Sonoma, Sequoia, and Tahoe versions before…
-
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vulnerability is tracked as CVE-2026-18574 and is detailed in Check Point Security Alert sk185222. It affects multiple legacy and current versions of their management platform.…
-
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows First seen…
-
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an…
-
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The issue, tracked as CVE-2026-17583, carries a CVSS v4 score of 8.2 and affects .fsa and .hid file outputs used in forensic…
-
The End of Centralized Enrichment: What NIST’s NVD Shift Means for Vulnerability Management
There’s an assumption baked into most vulnerability management programs that nobody ever wrote down, because nobody had to. When a CVE gets published, NVD enriches it. You get a severity score, product mappings, weakness categorization. All the context your tools and workflows need to actually do something. It was just how the system worked. In..…
-
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
-
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According…
-
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.Thermo Fisher tracks the issue as CVE-2026-17583 and…
-
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers. In the default configuration, applications that generate image variants may expose…
-
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.N-central is the remote monitoring and management platform First seen…
-
Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks
Tags: access, authentication, control, cve, cyber, exploit, flaw, monitoring, msp, network, vulnerabilityN-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform, following confirmation of active exploitation. This vulnerability, tracked as CVE-2026-18577, affects N-central servers running earlier than version 2026.3.1.7. It allows a remote, unauthenticated attacker to take over accounts and gain administrative control of the…
-
Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066. This submission poses an increased risk to applications that utilize the Vips image-processing backend. The proposed module is named `exploit/multi/http/rails_activestorage_vips_rce` and was introduced in Rapid7 Metasploit Framework pull request #21733 by contributor jburgess-r7.…
-
Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands
Arista Networks has issued a warning about attackers actively exploiting CVE-2026-16812, a critical unauthenticated OS command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments. This flaw carries a CVSS v3.1 and v4.0 severity score of 10.0, allowing a remote attacker with network access to the VCO web interface to access privileged internal functions and potentially…
-
Why CVE grading still matters for vulnerability management
First seen on scworld.com Jump to article: www.scworld.com/native/why-cve-grading-still-matters-for-vulnerability-management
-
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute…
-
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.It has been described as a case of incorrect authorization that could result in…
-
Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
Tags: access, authentication, cve, cyber, data-breach, flaw, network, remote-code-execution, risk, vulnerabilityJetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, tracked as CVE-2026-63077, affects all supported versions of TeamCity On-Premises and allows attackers with network access to bypass authentication checks and execute…
-
CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed on July 29, 2026, allows a remote, unauthenticated attacker to log in to vulnerable systems using a built-in low-privilege account and access sensitive data. First seen on thecyberexpress.com Jump to article:…
-
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/fastjson-rce-zero-day-actively-targets-organizations/
-
Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands
JetBrains has patched CVE-2026-63077, a critical TeamCity flaw that could let unauthenticated attackers execute server commands and compromise connected CI/CD pipelines. The post Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-critical-teamcity-rce-flaw/
-
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/
-
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt’s GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer…
-
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers. JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8). The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity…
-
Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers. The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to…
-
AI-Discovered Linux Kernel Zero-Day Enables Root Privilege Escalation
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) and arises from a use-after-free condition involving traffic-control action objects. AI-Discovered Linux Kernel Zero-Day Star Labs researcher developed a reliable exploit…
-
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already…
-
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel’s network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and…

