Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
A newly disclosed Linux kernel vulnerability tracked as CVE 2026 46331 allows local users to gain root privileges by poisoning cached binaries in memory, affecting multiple Linux distributions.
Google owned Mandiant reveals attackers exploited Cisco Catalyst SD WAN vulnerability CVE 2026 20245 as a zero day, using anti forensic techniques to gain root access and conceal malicious activity.
CISA adds CVE 2026 54420 affecting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog, warning of root privilege escalation risks on shared hosting servers.