Tag: cvss
-
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.”SolarWinds…
-
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
-
Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack
Cisco has released a fix for a maximum-severity flaw in its Identity Services Engine (ISE) platform after confirming the bug was already being exploited by attackers. The vulnerability, tracked as CVE-2026-76460, carries a perfect CVSS score of 10.0 and was patched by Cisco on September 16, 2026. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisco-ise-cve-2026-76460/
-
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-2026-86863, affects installations using pgAdmin’s Webserver authentication mode and has a CVSS 3.1 score of 9.8 out of 10. The issue impacts pgAdmin 4 versions…
-
CVE Authorities Make Score 8 Look More Like the New 10
Exploit Maturity Can Lower Scores Until Attack Evidence or PoCs Emerge. CVSS 4.0 lets threat intelligence alter a vulnerability’s enriched score without changing its Base severity, prompting experts to warn that vendors and defenders must continuously reassess exploitation, exposure and patch priority. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cve-authorities-make-score-8-look-more-like-new-10-a-32829
-
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of…
-
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic…
-
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk
-
Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hackers-exploit-maximum-severity/
-
Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should…
-
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request…
-
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under…
-
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of…
-
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and achieve remote code execution. Adobe assigned the vulnerability a CVSS score of 10.0 and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/imperva-customers-protected-against-stylesmuggler-cve-2026-75650-in-adobe-commerce-and-magento-open-source/
-
CVSS 10 im SAP-Kernel: OVERPASS öffnet Angreifern den Weg zu kritischen Geschäftssystemen
SAP OVERPASS (CVE-2026-44756) erreicht CVSS 10,0 und betrifft zahlreiche SAP-Systeme. Qualys warnt vor Angriffen über HTTP, SAP GUI und RFC. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cvss-10-im-sap-kernel-overpass-oeffnet-angreifern-den-weg-zu-kritischen-geschaeftssystemen/a46377/
-
CVSS 10 im SAP-Kernel: OVERPASS öffnet Angreifern den Weg zu kritischen Geschäftssystemen
SAP OVERPASS (CVE-2026-44756) erreicht CVSS 10,0 und betrifft zahlreiche SAP-Systeme. Qualys warnt vor Angriffen über HTTP, SAP GUI und RFC. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cvss-10-im-sap-kernel-overpass-oeffnet-angreifern-den-weg-zu-kritischen-geschaeftssystemen/a46377/
-
CVSS 10 im SAP-Kernel: OVERPASS öffnet Angreifern den Weg zu kritischen Geschäftssystemen
SAP OVERPASS (CVE-2026-44756) erreicht CVSS 10,0 und betrifft zahlreiche SAP-Systeme. Qualys warnt vor Angriffen über HTTP, SAP GUI und RFC. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cvss-10-im-sap-kernel-overpass-oeffnet-angreifern-den-weg-zu-kritischen-geschaeftssystemen/a46377/
-
CVSS 10 im SAP-Kernel: OVERPASS öffnet Angreifern den Weg zu kritischen Geschäftssystemen
SAP OVERPASS (CVE-2026-44756) erreicht CVSS 10,0 und betrifft zahlreiche SAP-Systeme. Qualys warnt vor Angriffen über HTTP, SAP GUI und RFC. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cvss-10-im-sap-kernel-overpass-oeffnet-angreifern-den-weg-zu-kritischen-geschaeftssystemen/a46377/
-
Extended-Passport-Daten im SAP-Kernel gefährdet
SAP hat insgesamt 22 Security-Notes veröffentlicht, darunter fünf Hot-News-Einträge. Die schwerwiegendste Schwachstelle intern <> genannt, geführt als CVE-2026-44756 betrifft die Verarbeitung von Extended-Passport-Daten im SAP-Kernel und erreicht mit CVSS 10,0 den höchstmöglichen Wert. Ein nicht authentifizierter Angreifer kann über eine präparierte Netzwerkanfrage mit fehlerhaftem EPP-Header eine Speicherbeschädigung auslösen. Die Schwachstelle ist über mehrere […] First…
-
Extended-Passport-Daten im SAP-Kernel gefährdet
SAP hat insgesamt 22 Security-Notes veröffentlicht, darunter fünf Hot-News-Einträge. Die schwerwiegendste Schwachstelle intern <> genannt, geführt als CVE-2026-44756 betrifft die Verarbeitung von Extended-Passport-Daten im SAP-Kernel und erreicht mit CVSS 10,0 den höchstmöglichen Wert. Ein nicht authentifizierter Angreifer kann über eine präparierte Netzwerkanfrage mit fehlerhaftem EPP-Header eine Speicherbeschädigung auslösen. Die Schwachstelle ist über mehrere […] First…
-
Extended-Passport-Daten im SAP-Kernel gefährdet
SAP hat insgesamt 22 Security-Notes veröffentlicht, darunter fünf Hot-News-Einträge. Die schwerwiegendste Schwachstelle intern <> genannt, geführt als CVE-2026-44756 betrifft die Verarbeitung von Extended-Passport-Daten im SAP-Kernel und erreicht mit CVSS 10,0 den höchstmöglichen Wert. Ein nicht authentifizierter Angreifer kann über eine präparierte Netzwerkanfrage mit fehlerhaftem EPP-Header eine Speicherbeschädigung auslösen. Die Schwachstelle ist über mehrere […] First…
-
Extended-Passport-Daten im SAP-Kernel gefährdet
SAP hat insgesamt 22 Security-Notes veröffentlicht, darunter fünf Hot-News-Einträge. Die schwerwiegendste Schwachstelle intern <> genannt, geführt als CVE-2026-44756 betrifft die Verarbeitung von Extended-Passport-Daten im SAP-Kernel und erreicht mit CVSS 10,0 den höchstmöglichen Wert. Ein nicht authentifizierter Angreifer kann über eine präparierte Netzwerkanfrage mit fehlerhaftem EPP-Header eine Speicherbeschädigung auslösen. Die Schwachstelle ist über mehrere […] First…
-
Extended-Passport-Daten im SAP-Kernel gefährdet
SAP hat insgesamt 22 Security-Notes veröffentlicht, darunter fünf Hot-News-Einträge. Die schwerwiegendste Schwachstelle intern <> genannt, geführt als CVE-2026-44756 betrifft die Verarbeitung von Extended-Passport-Daten im SAP-Kernel und erreicht mit CVSS 10,0 den höchstmöglichen Wert. Ein nicht authentifizierter Angreifer kann über eine präparierte Netzwerkanfrage mit fehlerhaftem EPP-Header eine Speicherbeschädigung auslösen. Die Schwachstelle ist über mehrere […] First…
-
SAP September 2026 Security Update Fixes 4 Critical Vulnerabilities and 15 Other Flaws
SAP released 19 new Security Notes addressing four critical vulnerabilities and 15 additional flaws throughout its enterprise portfolio. The vendor also updated one note from August. The most urgent issue is CVE-2026-44756, a memory-corruption vulnerability in Extended Passport (EPP) Processing with a CVSS score of 10.0. This flaw affects numerous SAP Kernel and Web Dispatcher…
-
Why Vulnerability Management Must Move Beyond CVSS
Learn why vulnerability management must move beyond CVSS to prioritize real risk using exploitability, asset context, attack paths, and AI-driven analysis. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-why-vulnerability-management-moves-past-cvss/
-
Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
Microsoft’s August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. As of September 1, threat intelligence group Shadowserver has… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsoft-exchange-vulnerability-cve-2026-62911-what-administrators-should-do-and-how-zscaler-can-help/
-
Critical Cisco Nexus 9000 Flaw Lets Remote Attackers Execute Code as Root Without Authentication
Cisco has released security updates addressing a critical vulnerability in Nexus 9000 Series switches that could allow unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability, tracked as CVE-2026-20212, has a CVSS score of 9.8 and affects Nexus 9000 platforms that are equipped with Cisco Silicon One ASICs. Cisco Nexus 9000 Flaw…

