Tag: cvss
-
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that…
-
SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that…
-
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…
-
Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover
A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). This vulnerability, tracked as CVE-2026-76581, has a CVSS score of 9.8 and affects WPMU DEV Dashboard versions 5.0.1 and earlier. The plugin…
-
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations…
-
CVE vs CWE vs CAPEC vs MITRE ATTCK: What They Are and Why Your Content Needs Them
CVE, CWE, CAPEC, ATT&CK, CVSS, KEV, ATLAS. The security taxonomy acronyms get used interchangeably and they should not be. Here is what each one actually does, how they chain together, and why they matter more for your content strategy than most security marketers realize. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cve-vs-cwe-vs-capec-vs-mitre-attck-what-they-are-and-why-your-content-needs-them/
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Authentication From Service Accounts
Veeam has released security updates for a critical vulnerability in Veeam ONE that could allow an unauthenticated network attacker to coerce SMB authentication from the account running an affected service. Tracked as CVE-2026-65641, the vulnerability received a CVSS v4.0 severity score of 9.3. Veeam disclosed the issue through Knowledge Base article 4905, published on August…
-
Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code
WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026-57909, have CVSS v4.0 scores of 9.3 and 9.4, respectively. Both issues impact WatchGuard Agent versions earlier than 1.25.13.0000. If exploited, these vulnerabilities could give an…
-
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe issue, tracked as CVE-2026-66152, has a CVSS score of 8.8/10 and affects NetExtender Linux Client versions 10.3.5 and earlier.…
-
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19632, has a CVSS score of 9.8 and affects all TranslatePress versions up to 3.3.1. The flaw affects a plugin installed on over 400,000 WordPress sites. Security…
-
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to…
-
Multiple Zscaler Client Connector Flaws Enable Remote Code Execution
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context. This vulnerability, tracked as CVE-2026-59568, is rated as Critical, with a CVSS v3.1 score of 9.1. The attack vector is network-accessible and requires no privileges or user interaction. Multiple…
-
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later…
-
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring system…
-
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete control of affected websites by escalating privileges to the administrator level. This vulnerability, tracked as CVE-2026-19598, carries a CVSS score of 9.8 and affects Pods Custom Content Types and Fields versions up to […]…
-
91 Spring CVEs: The AI Vulnerability Consumption Problem
Tags: access, advisory, ai, attack, cloud, cve, cvss, data, data-breach, framework, guide, injection, intelligence, open-source, risk, service, software, tool, update, vulnerability<div cla TL;DR Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects. At the time of publishing, Sonatype Guide currently identifies 209,569 software components affected by the security event. The disclosure comes amid a dramatic rise in AI-assisted vulnerability discovery. Broadcom…
-
Six Maximum-Severity Flaws Found in Cisco Products
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe.…
-
Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access
Tags: access, authentication, control, cve, cvss, cyber, cybersecurity, flaw, malicious, password, vulnerabilityCybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials and take control of a user’s password vault. This vulnerability, tracked as CVE-2026-15580, affects PassPortal version 3.49.5 and has a CVSS v4.0 base score of 9.4. It was patched…
-
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below – First…
-
SAP-Patchday im August – SAP patcht CVSS-10-Sicherheitslücke in Commerce Cloud
First seen on security-insider.de Jump to article: www.security-insider.de/sap-patch-day-kritische-luecken-commerce-cloud-xmii-a-f2bda521fa9c7a68375cca6c06c659e5/
-
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August…
-
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL’s open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software’s spacecraft and instrument command bus.The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI First…
-
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances. Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches. Citrix NetScaler Flaw The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and…
-
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances. Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches. Citrix NetScaler Flaw The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and…
-
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.”The…
-
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
Tags: credentials, cve, cvss, cyber, data, exploit, extortion, hacker, ransomware, remote-code-execution, vulnerabilityThe Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additional attacker tooling. Tracked as CVE-2026-12569, the vulnerability is a CVSS 9.3 remote code execution issue affecting PTC Windchill PDMlink and…
-
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of…

