Vulnerabilities

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure 2026-08-17 at 11:13 By Eduard Kovacs The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure Read More »

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities 2026-08-14 at 14:57 By SecurityWeek News Noteworthy stories that might have slipped under the radar: government AI platform deal sparks outrage, North Korean IT worker breaches federal agency, DEF CON attendee blamed for Delta flight disruption. The post In Other News: Rapid7 Layoffs, […]

In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities Read More »

Hackers Exploiting Unpatched GeoServer Zero-Day

Hackers Exploiting Unpatched GeoServer Zero-Day 2026-08-14 at 10:01 By Ionut Arghire The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Exploiting Unpatched GeoServer Zero-Day Read More »

Beyond the Inbox: How BEC Leads to SSO Abuse

Beyond the Inbox: How BEC Leads to SSO Abuse 2026-08-13 at 20:40 By Jamie Mamroe and Federico Cedolini For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim’s mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money […]

Beyond the Inbox: How BEC Leads to SSO Abuse Read More »

Adobe Commerce Bug Targeted Immediately After Disclosure

Adobe Commerce Bug Targeted Immediately After Disclosure 2026-08-13 at 17:17 By Ionut Arghire The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Commerce Bug Targeted Immediately After Disclosure Read More »

Release the RAVEN: Kibana Under Siege

Release the RAVEN: Kibana Under Siege 2026-08-13 at 16:36 By Karl Biron In Parts 1 and 2, every command targeted port 9200. Every exploit, every reconnaissance query, every credential test hit the Elasticsearch REST API directly. But Elasticsearch rarely operates alone. Sitting alongside it on most deployments is Kibana, the visualization and management interface, quietly […]

Release the RAVEN: Kibana Under Siege Read More »

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

WordPress 7.0.4 Patches Remote Code Execution Vulnerability 2026-08-13 at 15:53 By Ionut Arghire Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress 7.0.4 Patches Remote Code Execution Vulnerability Read More »

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager 2026-08-13 at 13:40 By Ionut Arghire The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Read More »

SharePoint Vulnerability Exploited Shortly After PoC Release

SharePoint Vulnerability Exploited Shortly After PoC Release 2026-08-12 at 17:47 By Eduard Kovacs The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

SharePoint Vulnerability Exploited Shortly After PoC Release Read More »

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks 2026-08-12 at 11:45 By Ionut Arghire The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks Read More »

Ivanti EPM Update Patches Remotely Exploitable Flaws

Ivanti EPM Update Patches Remotely Exploitable Flaws 2026-08-12 at 11:14 By Ionut Arghire The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Ivanti EPM Update Patches Remotely Exploitable Flaws Read More »

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform 2026-08-12 at 10:31 By Ionut Arghire The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform Read More »

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks 2026-08-12 at 08:10 By Eduard Kovacs CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Patches Firewall Zero-Day Exploited for DoS Attacks Read More »

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day 2026-08-11 at 21:46 By Ionut Arghire A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. The post August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from […]

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Read More »

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws 2026-08-11 at 19:50 By Ionut Arghire The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Read More »

Zoom Patches Zero-Click Code Execution Vulnerability

Zoom Patches Zero-Click Code Execution Vulnerability 2026-08-11 at 18:49 By Ionut Arghire Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zoom Patches Zero-Click Code Execution Vulnerability Read More »

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities 2026-08-11 at 17:14 By Ionut Arghire SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Read More »

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC 2026-08-10 at 17:07 By Ionut Arghire Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Read More »

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability 2026-08-10 at 12:31 By Ionut Arghire The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Read More »

Scroll to Top