CVE

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) 2026-08-21 at 15:20 By Sinisa Markovic Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, […]

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) Read More »

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) 2026-08-21 at 10:55 By Sinisa Markovic Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) Read More »

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) 2026-08-18 at 14:38 By Sinisa Markovic GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) Read More »

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer 2026-08-17 at 15:23 By Sinisa Markovic A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer Read More »

Three in four AI-generated vulnerability patches leave something broken

Three in four AI-generated vulnerability patches leave something broken 2026-08-06 at 15:45 By Mirko Zorz Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time

Three in four AI-generated vulnerability patches leave something broken Read More »

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers 2026-08-05 at 21:45 By Mirko Zorz An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers Read More »

Russian hackers exploit unpatched Zimbra servers to steal emails

Russian hackers exploit unpatched Zimbra servers to steal emails 2026-07-24 at 15:09 By Sinisa Markovic Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and

Russian hackers exploit unpatched Zimbra servers to steal emails Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two

Multi-patch vulnerability fixes can leave open source exposed Read More »

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Estée Lauder discloses data breach tied to Oracle EBS vulnerability 2026-07-21 at 12:01 By Sinisa Markovic Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its

Estée Lauder discloses data breach tied to Oracle EBS vulnerability Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) 2026-07-14 at 20:40 By Zeljka Zorz SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise. If the outlined

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) Read More »

July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? 2026-07-10 at 10:30 By Help Net Security I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? Read More »

Vulnerability reports are arriving faster than GitHub can review them

Vulnerability reports are arriving faster than GitHub can review them 2026-06-30 at 08:25 By Anamarija Pogorelec Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects,

Vulnerability reports are arriving faster than GitHub can review them Read More »

Google fixes actively exploited Android vulnerability (CVE-2025-48595)

Google fixes actively exploited Android vulnerability (CVE-2025-48595) 2026-06-02 at 15:17 By Zeljka Zorz Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” About CVE-2025-48595 CVE-2025-48595 is an integer overflow vulnerability in the Android

Google fixes actively exploited Android vulnerability (CVE-2025-48595) Read More »

Boards want cyber risk in dollars, not CVE counts

Boards want cyber risk in dollars, not CVE counts 2026-05-25 at 08:11 By Help Net Security In this Help Net Security video, Ziv Levi, SVP of Technology at CYE, explains why translating cyber risk into dollars is one of the most pressing tasks for security leaders. Boards and executives want cyber exposure described in business

Boards want cyber risk in dollars, not CVE counts Read More »

Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585)

Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) 2026-05-20 at 11:49 By Zeljka Zorz Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. In the meantime, the company

Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) Read More »

Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root

Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root 2026-05-12 at 14:18 By Sinisa Markovic Recent disclosures have revealed that open-source networking tool dnsmasq is grappling with a serious set of vulnerabilities. The problems span memory safety and input validation, with researchers identifying heap buffer overflows, heap corruption, and code execution

Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root Read More »

cPanel zero-day exploited for months before patch release (CVE-2026-41940)

cPanel zero-day exploited for months before patch release (CVE-2026-41940) 2026-04-30 at 16:45 By Zeljka Zorz A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel, a popular web-based control panel for managing web hosting accounts, is being exploited by attackers in the wild. What’s more, attackers didn’t have to wait for watchTowr security researchers to release technical

cPanel zero-day exploited for months before patch release (CVE-2026-41940) Read More »

NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward

NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward 2026-04-16 at 19:48 By Zeljka Zorz NIST is overhauling how it manages the National Vulnerability Database (NVD) and switching to a risk-based model that prioritizes “enrichment” of only the most critical CVE-numbered security vulnerabilities. “This change is driven by a surge in

NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward Read More »

Scroll to Top