Vulnerabilities

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted 2026-09-24 at 13:40 By Ionut Arghire The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted Read More »

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Critical WordPress Vulnerability Exploited Immediately After Disclosure 2026-09-24 at 10:12 By Ionut Arghire Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical WordPress Vulnerability Exploited Immediately After Disclosure Read More »

Enumerating Users and MFA via Microsoft’s Password Reset Portal

Enumerating Users and MFA via Microsoft’s Password Reset Portal 2026-09-23 at 20:13 By Matthew Coady Microsoft’s Self-Service Password Reset (SSPR) portal is a legitimate feature designed to let users recover their accounts without calling the helpdesk. As it turns out, it also tells you quite a lot about the accounts in a tenant — whether […]

Enumerating Users and MFA via Microsoft’s Password Reset Portal Read More »

Adobe Patches Critical Flaws in Connect, AEM Forms

Adobe Patches Critical Flaws in Connect, AEM Forms 2026-09-23 at 14:40 By Ionut Arghire The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Patches Critical Flaws in Connect, AEM Forms Read More »

Arista Urges Immediate Patching of Exploited VCO Zero-Day

Arista Urges Immediate Patching of Exploited VCO Zero-Day 2026-09-23 at 11:33 By Ionut Arghire Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Arista Urges Immediate Patching of Exploited VCO Zero-Day Read More »

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day 2026-09-23 at 10:34 By Ionut Arghire Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day Read More »

Check Point Patches Exploited Management Server Zero-Day

Check Point Patches Exploited Management Server Zero-Day 2026-09-23 at 09:14 By Ionut Arghire The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Check Point Patches Exploited Management Server Zero-Day Read More »

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity 2026-09-22 at 16:26 By Eduard Kovacs Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.  The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity Read More »

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers 2026-09-22 at 14:55 By Ionut Arghire A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Read More »

WordPress Patches ‘Click2Shell’ Vulnerability

WordPress Patches ‘Click2Shell’ Vulnerability 2026-09-22 at 13:22 By Ionut Arghire The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Patches ‘Click2Shell’ Vulnerability Read More »

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities 2026-09-21 at 12:31 By Ionut Arghire Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities Read More »

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 2026-09-18 at 17:25 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical […]

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw Read More »

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products 2026-09-18 at 13:57 By Eduard Kovacs Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products Read More »

Critical Orkes Conductor Vulnerability Exploited in Attacks

Critical Orkes Conductor Vulnerability Exploited in Attacks 2026-09-18 at 11:42 By Ionut Arghire CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Orkes Conductor Vulnerability Exploited in Attacks Read More »

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities 2026-09-18 at 10:14 By Eduard Kovacs Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities Read More »

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot 2026-09-17 at 17:28 By Eduard Kovacs The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Read More »

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

ISC Patches 14 Vulnerabilities in BIND 9 Security Update 2026-09-17 at 15:39 By Ionut Arghire Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek. This article is an excerpt from […]

ISC Patches 14 Vulnerabilities in BIND 9 Security Update Read More »

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard 2026-09-17 at 15:17 By Ionut Arghire The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.   The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek. This article is an excerpt […]

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard Read More »

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day 2026-09-17 at 09:19 By Ionut Arghire Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Read More »

Scroll to Top