Tag: cve
-
Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation
Ubiquiti patched seven UniFi OS flaws, including critical CVE-2026-50746, which allows command injection in UniFi Connect Application. Ubiquiti released security updates for seven critical UniFi OS vulnerabilities, including a maximum-severity flaw, tracked as CVE-2026-50746 (CVSS score of 10.0), enabling command injection attacks. The issue affects UniFi Connect Application versions 3.4.16 and earlier, a platform used…
-
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.The list of vulnerabilities is as follows – CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an…
-
CISA Warns of Actively Exploited Adobe ColdFusion Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability is actively being exploited in the wild. Disclosed on July 7, 2026, this vulnerability involves a path traversal weakness that could allow attackers to execute arbitrary code…
-
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2026-48282 (CVSS score: 10.0) – A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the…
-
China-Aligned UNK_MassTraction Exploits Roundcube Servers to Target Universities
A suspected China-aligned cluster dubbed UNK_MassTraction that is exploiting n-day flaws in Roundcube webmail to compromise physics and engineering departments at U.S. and Canadian universities. The operators use a two-stage browser-to-server infection chain that begins with a Cross-Site Scripting (XSS) exploit against CVE-2024-42009 to execute JavaScript in the victim’s browser. Escalate to a credential- and…
-
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
Attackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2026-20896 (CVSS score of 9.8), which affects Gitea official Docker images before version 1.26.3. >>CVE-2026-20896 exploited 13 days after…
-
Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)
CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/07/adobe-coldfusion-cve-2026-48282-exploitation-detected/
-
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web…
-
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, First seen…
-
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign.The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, First seen…
-
16-Year-Old Januscape KVM Escape Vulnerability Lets Attackers Compromise Linux Hosts
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-53359 and named “Januscape,” reveals a 16-year-old flaw in KVM/x86 virtualization. This vulnerability allows guest virtual machines (VMs) to escape to the host under specific conditions, raising significant concerns for multi-tenant cloud environments. Discovered by security researcher Hyunwoo Kim, the issue lies within the shadow…
-
PHP PDO Emulated Prepares Expose pdo_pgsql to NULL Pointer Dereference Crash
A recent security audit of PHP’s PDO ecosystem uncovered a denial-of-service vector in the pdo_pgsql driver that can crash PHP processes when emulated prepared statements are enabled. PDO’s parser assumes a valid zend_string and dereferences it, triggering a NULL pointer dereference (SIGSEGV). The issue is tracked as CVE-2025-14180 and rated Moderate (6.3/10). PDO implements two…
-
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.”An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process First seen on thehackernews.com…
-
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices.The vulnerabilities are listed below – CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the First seen on thehackernews.com Jump…
-
EUVD-2026-37039 / CVE-2026-46331 – Riskante Schwachstelle im Linux-Kernel mit PoC und Exploits
First seen on security-insider.de Jump to article: www.security-insider.de/linux-kernel-cve-2026-46331-root-exploit-a-8c3cdcef7714685a7b5b036d893f4712/
-
Microsoft Edge High-Severity Vulnerability Allows Remote Code Execution
Microsoft has disclosed a high-severity remote code execution (RCE) vulnerability in its Chromium-based Edge browser, identified as CVE-2026-57992. This vulnerability could allow attackers to execute arbitrary code on affected systems under specific conditions. Publicly disclosed on July 3, 2026, it is classified as CWE-416 (Use-After-Free), which is a memory safety flaw. This issue occurs when…
-
CVE-2026-48282: Adobe ColdFusion RDS Path Traversal Leading to RCE
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/cve-2026-48282-adobe-coldfusion-rds-path-traversal-leading-to-rce
-
Adobe ColdFusion flaw CVE-2026-48282 now exploited in the wild
Attackers are exploiting the critical Adobe ColdFusion flaw CVE-2026-48282, which allows remote code execution on unpatched servers. Attackers have started exploiting CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion. The flaw is a path traversal issue that could result in arbitrary code execution without authentication. It affects ColdFusion 2025.9, 2023.20, and earlier versions, allowing remote attackers…
-
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A use-after-free bug in Linux’s KVM hypervisor can be triggered from a guest virtual machine to corrupt the shadow-page state of the host kernel that runs it.Dubbed ‘Januscape’ and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the…
-
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the “X-WEBAUTH-USER” header from any source IP address, effectively allowing an unauthenticated internet client to get elevated…
-
Max severity Adobe ColdFusion flaw now exploited in attacks
Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, the Canadian Center for Cyber Security (CCCS) warned on Thursday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/
-
Veeam Backup BinaryFormatter Flaw Enables Remote Code Execution
A newly discovered deserialization vulnerability, tracked as CVE-2026-44963, affects Veeam Backup & Replication. This vulnerability allows authenticated domain users to execute remote code on backup servers by exploiting weaknesses in the handling of BinaryFormatter. The issue, detailed by SecureLayer7 Labs, is part of a concerning trend of flaws in Veeam’s .NET Remoting attack surface, where…
-
IBM WebSphere Application Server Hit by Critical XSS and Path Traversal Vulnerabilities
IBM has disclosed several security vulnerabilities in its WebSphere Application Server that put enterprise environments at risk of cross-site scripting (XSS) and path-traversal attacks. These vulnerabilities could allow attackers to compromise administrative sessions and access sensitive data. The issues, identified as CVE-2026-11712, CVE-2026-11595, and CVE-2026-11708, affect widely deployed versions 8.5 and 9.0 of the application…
-
PHP TLS Flaw Lets Remote Server Trigger DoS and Crash Entire FPM Process
A newly disclosed high-severity vulnerability in PHP, tracked as CVE-2026-12184, poses a significant risk to web applications by allowing a remotely triggerable denial-of-service (DoS) condition. This vulnerability can cause entire PHP-FPM process pools to crash. Details of the issue are outlined in the GitHub advisory GHSA-mhmq-mmqj-2v39. It affects multiple supported PHP branches, including versions before…
-
ModSecurity Security Flaws Enable WAF Rule Evasion With Crafted HTTP Requests
ModSecurity, a widely used open-source web application firewall (WAF), has multiple security vulnerabilities that allow attackers to bypass detection with specially crafted HTTP requests. These vulnerabilities, identified as CVE-2026-52761 and CVE-2026-52747, affect ModSecurity versions up to 3.0.15. They have been addressed in version 3.0.16. These issues reveal significant inconsistencies in input transformation and request parsing,…
-
Bad Epoll Linux Kernel UAF Flaw Lets Unprivileged Attackers Gain Root on Linux and Android
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46242 and dubbed “Bad Epoll,” exposes a critical race-condition use-after-free (UAF) flaw in the epoll subsystem that allows unprivileged users to escalate privileges to root across Linux systems and potentially Android devices. The flaw was discovered and exploited by security researcher Jaeyoung Chung as part of Google’s…
-
Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files
A newly disclosed vulnerability in Microsoft Exchange, identified as CVE-2026-45504 (CVSS score: 8.8), exposes a critical server-side request forgery (SSRF) flaw. This issue allows authenticated low-privileged users to access and read arbitrary files from vulnerable Exchange servers. The vulnerability, discovered by security researcher Batuhan Er from HawkTrace, affects Microsoft Exchange Server 2019. Microsoft Exchange SSRF…
-
CitrixBleed Vulnerability Exploitation Within 24 Hours of Disclosure
Citrix NetScaler appliances are currently facing significant threats due to the rapid exploitation of a newly disclosed memory disclosure vulnerability, CVE-2026-8451, which is part of the evolving “CitrixBleed” class. This high-severity flaw (CVSS 8.8), disclosed on June 30, 2026, in Citrix advisory CTX696604, was observed being exploited in the wild within just 24 hours of…
-
CVE-2026-11374 gefährdet vier ManageEngine-Produkte – Kritische ManageEngine-Lücke ermöglicht Account-Übernahme per SSO
Tags: cveFirst seen on security-insider.de Jump to article: www.security-insider.de/manageengine-cve-2026-11374-sso-account-takeover-ad360-a-a532a531017e55df0b7a7d6befdca066/
-
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates…

