Tag: cvss
-
SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities
SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver Application Server ABAP. The most critical vulnerability, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects several SAP kernel releases used by NetWeaver AS ABAP. SAP has categorized this…
-
CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities
Tags: attack, cisa, cvss, cybersecurity, exploit, flaw, infrastructure, kev, malicious, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active zero-day attacks targeting the iCagenda and Balbooa extensions for Joomla. Both flaws carry the maximum CVSS severity score of 10.0 and can allow attackers to upload malicious files that ultimately lead to remote code execution. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.…
-
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below – CVE-2026-48939 – A vulnerability in the First…
-
Kritische Adobe-Sicherheitslücke aktiv ausgenutzt
Eine kritische Sicherheitslücke in Adobe ColdFusion mit dem maximalen CVSS-Wert 10 wird aktiv ausgenutzt. Angreifer reagierten innerhalb von zwei Stunden. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/adobe-sicherheitsluecke-ausgenutzt
-
HP Linux Imaging and Printing Software Flaw Enables Privilege Escalation Attacks
A critical vulnerability has been discovered in HP Linux Imaging and Printing Software (HPLIP), which exposes Linux systems to potential privilege escalation and remote code execution attacks. This vulnerability, tracked as CVE-2026-14544, has a CVSS v3 score of 9.8, indicating maximum severity due to its potential for network exploitation, low attack complexity, and lack of…
-
Sechs CVSS 10.0 Schwachstellen im Juni – Adobe reagiert auf KI-entdeckte Schwachstellen mit zweitem Patchday
First seen on security-insider.de Jump to article: www.security-insider.de/adobe-coldfusion-updates-zwei-wochen-zyklus-a-14d269a8881b5925842c520d440ce36d/
-
Hackers Exploit Maximum Severity Adobe ColdFusion Flaw
Threat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/exploit-maximum-severity-adobe/
-
Critical Cursor IDE Flaws Let Attackers Execute Code via Zero-Click Prompt Injection
Two significant remote code execution (RCE) vulnerabilities in the widely used Cursor ID expose developers to zero-click attacks driven by prompt injection. These vulnerabilities, tracked as CVE-2026-50548 and CVE-2026-50549, collectively known as >>DuneSlide,<< carry a CVSS score of 9.8. They demonstrate how development environments powered by large language models (LLMs) can unintentionally increase the attack…
-
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic.The ColdFusion updates “resolves critical and important vulnerabilities”¯that could lead to”¯arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass,” Adobe said in an alert released Tuesday.The vulnerabilities are listed First seen on thehackernews.com Jump to article:…
-
Adobe ColdFusion Critical Vulnerabilities Let Attackers Execute Arbitrary Code
Adobe has released an emergency security bulletin, APSB26-68, addressing 11 vulnerabilities in Adobe ColdFusion 2025 and ColdFusion 2023, with multiple vulnerabilities receiving the maximum CVSS base score of 10.0. Published on June 30, 2026, this bulletin carries Adobe’s highest Priority Rating of 1, indicating that these vulnerabilities are either actively targeted or pose an extremely…
-
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the API enabled, update now.Progress…
-
Splunk Secure Gateway RCE Vulnerability Lets Low-Privileged Attackers Execute Arbitrary Code
A newly disclosed high-severity vulnerability in Splunk Secure Gateway (SSG) allows low-privileged authenticated users to achieve remote code execution (RCE) on affected systems, significantly increasing the attack surface for enterprise Splunk deployments. This vulnerability, tracked as CVE-2026-20251, has been assigned a CVSS score of 8.8. It arises from the unsafe deserialization of user-controlled data using…
-
Critical Google Gemini CLI Flaw Lets Attackers Execute Code on Headless CI Platforms
A critical vulnerability has been identified in Google’s Gemini CLI and the associated run-gemini-cli GitHub Action. This flaw exposes headless continuous integration (CI) platforms to potential host-level code execution when processing untrusted workspaces. It is tracked as CVE-2026-12537, with the advisory identifying it as GHSA-wpqr-6v78-jr5g. Rated at the maximum severity under CVSS v4, the issue…
-
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1.11.1 and carries a CVSS 4.0 score of 9.2.libssh2…
-
Kritische Angriffskette in UniFi OS – Drei aktiv ausgenutzte CVSS-10.0-Schwachstellen in Ubiquiti UniFi OS
First seen on security-insider.de Jump to article: www.security-insider.de/ubiquiti-unifi-os-cve-2026-34908-34909-34910-angriffskette-a-13601a0b4f32b5e61a8e1b51dfba372a/
-
F5 patcht NGINX-Speicherfehler mit CVSS 9.2 außerplanmäßig – Kritische NGINX-Lücken in HTTP/3- und HTTP/2-Modulen
Tags: cvssFirst seen on security-insider.de Jump to article: www.security-insider.de/nginx-http3-http2-schwachstellen-speicherfehler-a-60ce4bcf839f0b1e1ab6f6c795d551a6/
-
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files
A critical memory corruption vulnerability in FFmpeg has been disclosed, allowing for remote code execution through specially crafted media files. This flaw, tracked as CVE-2026-8461 and named “PixelSmash,” affects the MagicYUV decoder within FFmpeg’s libavcodec library and has a CVSS score of 8.8. Discovered by JFrog Security Research, the vulnerability arises from a heap out-of-bounds…
-
Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets
A critical security vulnerability has been identified in libssh2, a widely used client-side SSH library. This flaw allows remote attackers to execute code by sending specially crafted SSH packets. The vulnerability, tracked as CVE-2026-55200, has a CVSS score of 9.2 and affects libssh2 versions up to and including 1.11.1. The issue has been resolved in…
-
Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites
A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-8713 and assigned a CVSS score of 9.1, the vulnerability affects all plugin versions up to…
-
Miggo adds SSVC scoring as CISA moves beyond CVSS-based vulnerability prioritization
First seen on scworld.com Jump to article: www.scworld.com/brief/miggo-adds-ssvc-scoring-as-cisa-moves-beyond-cvss-based-vulnerability-prioritization
-
Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data
Threat actors are actively exploiting a critical security flaw in the widely used Gravity SMTP WordPress plugin to extract sensitive configuration data, including API keys and authentication tokens. The vulnerability, tracked as CVE-2026-4020 with a CVSS score of 5.3, affects all versions up to and including 2.1.4 and exposes more than 100,000 websites to potential…
-
Fortra Access Manager Security Flaw Exposes Systems to Command Injection
Fortra has reported a critical command injection vulnerability in its Core Privileged Access Manager (BoKS) platform, which could allow remote attackers to execute arbitrary commands with elevated privileges. This could potentially lead to a full system compromise. Tracked as CVE-2026-9862 and assigned a CVSS v3.1 score of 9.8, the flaw exists in the boks_autoregisterd service,…
-
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild.The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0.”A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker…
-
Splunk Urges Immediate Patching of Critical Flaw Enabling Arbitrary File Operations
A newly disclosed security vulnerability in Splunk Enterprise has prompted urgent patching efforts after researchers revealed that the flaw could allow unauthenticated attackers to perform arbitrary file operations and potentially achieve remote code execution. The issue, identified as CVE-2026-20253, affects certain versions of Splunk Enterprise and carries a critical CVSS score of 9.8. First seen on thecyberexpress.com Jump to article:…
-
Critical Wazuh Flaw Enables Threat Actors to Alter Alerts and Remove Logs
A critical security flaw in Wazuh Manager could allow unauthenticated threat actors to tamper with alerts, delete forensic evidence, and execute arbitrary OpenSearch operations by exploiting an input validation weakness in the platform’s new inventory synchronization pipeline. Tracked under GitHub advisory GHSA-ff9g-85jq-r3g3, the vulnerability affects Wazuh Manager version 5.0.0-beta1 and carries a maximum CVSS score…
-
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution.The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system.”In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary…
-
Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases
Tags: api, authentication, cve, cvss, cyber, flaw, rce, remote-code-execution, service, vulnerabilityA critical pre-authentication remote code execution (RCE) vulnerability in Splunk Enterprise has been disclosed, carrying a near-perfect CVSS score of 9.8. Tracked asCVE-2026-20253, the flaw was published by Splunk on June 10, 2026, and affects thePostgreSQL Sidecar Serviceintroduced in Splunk version 10. The root cause of CVE-2026-20253 lies in the PostgreSQL Sidecar Service’s HTTP API…
-
Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases
Tags: api, authentication, cve, cvss, cyber, flaw, rce, remote-code-execution, service, vulnerabilityA critical pre-authentication remote code execution (RCE) vulnerability in Splunk Enterprise has been disclosed, carrying a near-perfect CVSS score of 9.8. Tracked asCVE-2026-20253, the flaw was published by Splunk on June 10, 2026, and affects thePostgreSQL Sidecar Serviceintroduced in Splunk version 10. The root cause of CVE-2026-20253 lies in the PostgreSQL Sidecar Service’s HTTP API…

