vulnerability

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems 2026-08-28 at 15:36 By Eduard Kovacs CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek. This article is an […]

OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems Read More »

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut Releases Emergency Patch for Exploited Zero-Day 2026-08-28 at 11:40 By Eduard Kovacs A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations. The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

PaperCut Releases Emergency Patch for Exploited Zero-Day Read More »

Unknown PaperCut NG/MF vulnerability is under active attack

Unknown PaperCut NG/MF vulnerability is under active attack 2026-08-27 at 14:59 By Zeljka Zorz A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said.

Unknown PaperCut NG/MF vulnerability is under active attack Read More »

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) 2026-08-27 at 12:58 By Sinisa Markovic CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) Read More »

Recent Citrix NetScaler Vulnerability Exploited in the Wild

Recent Citrix NetScaler Vulnerability Exploited in the Wild 2026-08-27 at 07:39 By Eduard Kovacs CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Citrix NetScaler Vulnerability Exploited in the Wild Read More »

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia Patch Dozens of Vulnerabilities 2026-08-26 at 15:39 By Eduard Kovacs Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe and Nvidia Patch Dozens of Vulnerabilities Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Chrome 152 Patches Over 300 Vulnerabilities

Chrome 152 Patches Over 300 Vulnerabilities 2026-08-26 at 12:50 By Eduard Kovacs Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 152 Patches Over 300 Vulnerabilities Read More »

CISA Warns of Exploited Gitea Vulnerability

CISA Warns of Exploited Gitea Vulnerability 2026-08-26 at 08:17 By Eduard Kovacs CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Gitea Vulnerability Read More »

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities 2026-08-25 at 16:33 By Eduard Kovacs CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA Warns of Exploited Oracle WebLogic Vulnerability 2026-08-25 at 10:46 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Oracle WebLogic Vulnerability Read More »

91 Vulnerabilities Patched in Spring Application Framework

91 Vulnerabilities Patched in Spring Application Framework 2026-08-24 at 14:58 By Eduard Kovacs More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.  The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

91 Vulnerabilities Patched in Spring Application Framework Read More »

Critical Isolated-vm Vulnerability Leads to RCE on Host

Critical Isolated-vm Vulnerability Leads to RCE on Host 2026-08-21 at 15:26 By Ionut Arghire The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Isolated-vm Vulnerability Leads to RCE on Host Read More »

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) 2026-08-21 at 15:20 By Sinisa Markovic Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure,

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) Read More »

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft Rolls Out 22 Fresh Security Patches 2026-08-21 at 11:12 By Ionut Arghire Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Rolls Out 22 Fresh Security Patches Read More »

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) 2026-08-21 at 10:55 By Sinisa Markovic Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) Read More »

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities 2026-08-21 at 10:25 By Ionut Arghire The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Read More »

Hackers Target Zimbra Servers in Active Exploitation Campaign

Hackers Target Zimbra Servers in Active Exploitation Campaign 2026-08-20 at 17:50 By Eduard Kovacs Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Target Zimbra Servers in Active Exploitation Campaign Read More »

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities 2026-08-20 at 15:24 By Ionut Arghire The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Read More »

Scroll to Top