Tag: vulnerability

Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.

cPanel Releases Security Updates For Critical Database And Server Vulnerabilities

cPanel has patched a critical privilege escalation flaw alongside two additional security issues affecting database access, HTTP request handling, and Exim mail server components.

Adobe Releases Security Updates For Adobe Campaign Classic And Adobe Bridge Flaws

Adobe has released security updates for Adobe Campaign Classic and Adobe Bridge, addressing critical vulnerabilities that could allow arbitrary code execution, privilege escalation, and file system access.

CISA Adds Exploited Microsoft SharePoint CVE 2026 58644 Zero Day To Known Exploited Vulnerabilities Catalog

CISA has added the actively exploited Microsoft SharePoint vulnerability CVE 2026 58644 to its Known Exploited Vulnerabilities catalog and urged organizations to apply security updates immediately.

Critical Progress Kemp LoadMaster Vulnerability Allows Pre Authentication Root Command Execution 

A critical vulnerability tracked as CVE 2026 8037 in Progress Kemp LoadMaster could allow unauthenticated attackers to execute root level commands through the API. Security updates are available for affected versions.

Weekly Cybersecurity Recap Highlights Linux Kernel Flaw, AI Driven Malware, Turla Backdoor, And Infostealer Threats 

This week's cybersecurity roundup covers the DirtyClone Linux kernel vulnerability, AI focused malware techniques, Turla's STOCKSTAY backdoor, major malware disruptions, OpenAI updates, and emerging cyber threats.

Linux Pedit COW Vulnerability Allows Local Users To Gain Root Access Through Cached Binary Poisoning

A newly disclosed Linux kernel vulnerability tracked as CVE 2026 46331 allows local users to gain root privileges by poisoning cached binaries in memory, affecting multiple Linux distributions.

Cisco Catalyst SD WAN Zero Day Exploited To Gain Root Level Access Before Public Disclosure

Google owned Mandiant reveals attackers exploited Cisco Catalyst SD WAN vulnerability CVE 2026 20245 as a zero day, using anti forensic techniques to gain root access and conceal malicious activity.

CISA Warns Of Active Exploitation Targeting Critical Lantronix EDS5000 Vulnerability

CISA has warned that attackers are actively exploiting the critical Lantronix EDS5000 vulnerability CVE 2025 67038 while researchers also report ongoing attacks targeting OpenWRT LuCI devices and UniFi OS flaws.

Claude Code GitHub Action Flaw Exposed Public Repositories To Repository Hijacking Risks

A security flaw in Anthropic’s Claude Code GitHub Action allowed attackers to potentially hijack public repositories through a single malicious GitHub issue.

Microsoft Warns Of Active Exploitation Targeting Exchange Server CVE 2026 42897 Through Crafted Emails

Microsoft has disclosed active exploitation of CVE 2026 42897 affecting on premises Exchange Server deployments, allowing spoofing and JavaScript execution through crafted emails in Outlook Web Access.

Instructure Reaches Ransom Agreement With ShinyHunters After 3.65TB Canvas Data Breach

Instructure confirms an agreement with ShinyHunters following a Canvas breach involving 3.65TB of stolen data impacting nearly 9000 institutions, with threat actors leveraging a vulnerability to exfiltrate sensitive education records.

PAN OS CVE-2026-0300 Exploited In Active Attacks Enables Root Level Remote Code Execution

Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.

Recent articles

spot_img