exploited

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication 2026-10-08 at 17:04 By Eduard Kovacs Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The post Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication Read More »

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI 

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI  2026-10-05 at 14:00 By Ionut Arghire CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI  Read More »

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier 2026-10-05 at 08:14 By Eduard Kovacs Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek. This article is an […]

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier Read More »

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks 2026-10-02 at 12:34 By Ionut Arghire The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks Read More »

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action 2026-10-02 at 11:07 By Ionut Arghire CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action Read More »

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure 2026-10-01 at 15:55 By Ionut Arghire Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure Read More »

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

Zammad Zero-Days Exploited in AI-Powered DIVD Hack 2026-10-01 at 13:42 By Ionut Arghire The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zammad Zero-Days Exploited in AI-Powered DIVD Hack Read More »

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability 2026-10-01 at 11:26 By Ionut Arghire The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability Read More »

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks 2026-09-30 at 15:48 By Eduard Kovacs Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks Read More »

Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 

Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’  2026-09-29 at 09:18 By Eduard Kovacs Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950. The post Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’  Read More »

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug 2026-09-28 at 10:29 By Eduard Kovacs Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The post Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug Read More »

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks 2026-09-27 at 12:23 By Eduard Kovacs CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks Read More »

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Roundcube Webmail Vulnerability in Attackers’ Crosshairs 2026-09-25 at 09:57 By Ionut Arghire Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Roundcube Webmail Vulnerability in Attackers’ Crosshairs Read More »

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Critical WordPress Vulnerability Exploited Immediately After Disclosure 2026-09-24 at 10:12 By Ionut Arghire Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical WordPress Vulnerability Exploited Immediately After Disclosure Read More »

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Arista Urges Immediate Patching of Exploited VCO Zero-Day 2026-09-23 at 11:33 By Ionut Arghire Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Arista Urges Immediate Patching of Exploited VCO Zero-Day Read More »

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day 2026-09-23 at 10:34 By Ionut Arghire Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day Read More »

Check Point Patches Exploited Management Server Zero-Day

Check Point Patches Exploited Management Server Zero-Day 2026-09-23 at 09:14 By Ionut Arghire The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Check Point Patches Exploited Management Server Zero-Day Read More »

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers 2026-09-22 at 14:55 By Ionut Arghire A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Read More »

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities 2026-09-21 at 12:31 By Ionut Arghire Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities Read More »

Critical Orkes Conductor Vulnerability Exploited in Attacks

Critical Orkes Conductor Vulnerability Exploited in Attacks 2026-09-18 at 11:42 By Ionut Arghire CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Orkes Conductor Vulnerability Exploited in Attacks Read More »

Scroll to Top