Tag: cve
-
Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
Attackers are exploiting CVE-2026-48842 against unpatched Roundcube servers months after a fix was released, raising urgency for organizations to update. The post Attackers Target Unpatched Roundcube Servers With CVE-2026-48842 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/attackers-target-unpatched-roundcube-servers-with-cve-2026-48842/
-
Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
Attackers are exploiting CVE-2026-48842 against unpatched Roundcube servers months after a fix was released, raising urgency for organizations to update. The post Attackers Target Unpatched Roundcube Servers With CVE-2026-48842 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/attackers-target-unpatched-roundcube-servers-with-cve-2026-48842/
-
WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution
Hackers are actively exploiting CVE-2026-87902, a critical WordPress flaw that can lead to remote code execution. Here’s what admins should do. The post WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-wordpress-cve-2026-87902-active-exploitation/
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
Attackers build “silent” cryptominer on victim’s machine and give themselves away
Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the intrusion stood out. The incident began in early September 2026 with the exploitation of CVE-2025-4632,…
-
ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical flaws that could allow unauthenticated attackers to execute arbitrary SQL commands, extract sensitive instance data, modify records, and escalate privileges. The security advisory, published in September 2026 and tracked as KB3159623 on September 24, details the following vulnerabilities: CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and…
-
CISA Flags WSO2 Security Flaw Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting WSO2, tracked as CVE-2026-5430, to its Known Exploited Vulnerabilities (KEV) catalog. CISA made this decision after evidence showed threat actors are actively exploiting the flaw. CISA added the vulnerability on September 24, 2026, and set a remediation deadline for affected federal…
-
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.The issue stems from a preg_replace() backslash First…
-
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Tags: adobe, authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products…
-
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Tags: adobe, authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products…
-
Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls
A recently disclosed high-severity vulnerability in Sudo could allow local, unprivileged Linux users to manipulate time-based authorization restrictions in sudoers policies. Tracked as CVE-2026-96512, this vulnerability arises from how Sudo handles the attacker-controlled TZ environment variable when evaluating NOTBEFORE and NOTAFTER constraints. Red Hat is monitoring this flaw under Bug 2539327, which is currently categorized…
-
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Tags: adobe, api, attack, cisa, control, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.The vulnerabilities are listed below – CVE-2026-5430 (CVS score: 9.8) – A path traversal vulnerability in WSO2 API Control Plane, First…
-
Breach Roundup: Thousands of AI Relays Hide China Users
Tags: ai, breach, china, cisa, cve, cybercrime, data, data-breach, flaw, google, jobs, north-korea, russia, scam, vpnAlso, CISA Ends Weekly CVE Bulletin After 22 Years, Check Point VPN Flaw Exploited. This week: AI relay servers connect to China, CISA ends weekly CVE bulletin, cybercriminal guilty pleas and sentences, drug dealers hijack Google Maps, Russian Burger King customers’ data leaked, North Korean fake job scams, SectopRAT, a Check Point VPN flaw and…
-
CISA Charts New Quality Era for Global CVE Program
CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-quality-era-global-cve-program/
-
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL injection attacks. This vulnerability, tracked as CVE-2026-48842, affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. On September 21, the Canadian Center for Cyber Security updated advisory AV26-503, warning that reports from the…
-
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Tags: attack, authentication, cve, cvss, cyber, exploit, flaw, hacker, rce, remote-code-execution, update, vpn, vulnerability, zero-dayCheck Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-85102 and the newly disclosed CVE-2026-93616. Both vulnerabilities have a CVSS score of 9.8 and allow for pre-authentication attacks, making immediate patching and reducing exposure essential. Check Point Flaws CVE-2026-85102 is an improper certificate-validation…
-
Apache Tomcat Update: 12 Security Flaws Fixed in Tomcat 11.0.26
The Apache Software Foundation has released Tomcat 11.0.26, an Apache Tomcat Update that resolves 12 security vulnerabilities. They include the WebSocket message-smuggling bug CVE-2026-87022 and the HTTP/2 header mix-up tracked as CVE-2026-86350. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/apache-tomcat-update-cve-2026-87022/
-
Apache Tomcat Update: 12 Security Flaws Fixed in Tomcat 11.0.26
The Apache Software Foundation has released Tomcat 11.0.26, an Apache Tomcat Update that resolves 12 security vulnerabilities. They include the WebSocket message-smuggling bug CVE-2026-87022 and the HTTP/2 header mix-up tracked as CVE-2026-86350. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/apache-tomcat-update-cve-2026-87022/
-
GNOME 50.5 security fixes patch a gvfs CVE and Epiphany code injection
GNOME 50.5, which the GNOME Release Team shipped on September 24, patches a CVE in the gvfs file system layer, a JavaScript injection flaw in the Epiphany web browser and a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/24/gnome-50-5-security-fixes/
-
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).”An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file First seen on…
-
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could allow a local user on a shared server to access calendar events and contacts from other hosting accounts. The issue affects cPanel/WHM version 120 and later, highlighting the risks associated with tenant isolation in shared-hosting environments.…
-
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company originally described it as a spoofing issue with a CVSS score of 6.5. In reality, it is an authenticated RCE flaw rated 8.8. That gap matters, because security teams that trusted the first label may…
-
Check Point Fixes a New Actively Exploited Critical Security Flaw
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to…
-
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server…
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication…
-
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used…
-
Critical Linux KVM Flaw Enables GuestHost Escape on ARM64 Systems
A critical vulnerability in the Linux Kernel-based Virtual Machine (KVM) for ARM64 systems could let attackers escape a virtual machine and gain read and write access to host kernel memory. This flaw, tracked as CVE-2026-89775, specifically affects ARM64 hosts with nested virtualization enabled and has been addressed in the mainline Linux kernel. Security researcher Hyunwoo…
-
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate…

