vulnerability

Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server

Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server 2026-05-05 at 17:46 By Ionut Arghire The most severe of these security defects could allow remote attackers to execute arbitrary code. The post Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP Server Read More »

Critical Remote Code Execution Vulnerability Patched in Android

Critical Remote Code Execution Vulnerability Patched in Android 2026-05-05 at 17:46 By Eduard Kovacs CVE-2026-0073 affects Android’s System component and it can be exploited without any user interaction.  The post Critical Remote Code Execution Vulnerability Patched in Android appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Remote Code Execution Vulnerability Patched in Android Read More »

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs 2026-05-05 at 13:20 By Ionut Arghire The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests. The post MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs Read More »

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities 2026-05-05 at 13:20 By Eduard Kovacs The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year. The post WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities Read More »

Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670)

Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670) 2026-05-04 at 18:59 By Zeljka Zorz Progress Software has fixed a critical authentication bypass (CVE-2026-4670) and a privilege escalation (CVE-2026-5174) vulnerability in MOVEit Automation, exploitation of which “may lead to unauthorized access, administrative control, and data exposure.” The vulnerabilities were reported privately by Airbus researchers and there’s

Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670) Read More »

Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge

Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge 2026-05-01 at 18:20 By Eduard Kovacs The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million. The post Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge appeared first

Google Adjusts Bug Bounties: Chrome Payouts Drop as Android Rewards Rise Amid AI Surge Read More »

SonicWall Urges Immediate Patching of Firewall Vulnerabilities

SonicWall Urges Immediate Patching of Firewall Vulnerabilities 2026-04-30 at 18:18 By Ionut Arghire The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls. The post SonicWall Urges Immediate Patching of Firewall Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Urges Immediate Patching of Firewall Vulnerabilities Read More »

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws 2026-04-30 at 16:45 By Ashish Khaitan The latest weekly vulnerability Insights report to clients by Cyble provides a detailed view of vulnerabilities tracked between April 15, 2026, and April 21, 2026. The findings highlight a slight dip in overall disclosures compared to the previous week, but the persistence

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws Read More »

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks 2026-04-30 at 16:02 By Eduard Kovacs An attacker could have planted a malicious configuration to execute commands outside the sandbox. The post Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks Read More »

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) 2026-04-30 at 15:31 By Zeljka Zorz Security researchers at Theori have disclosed a high-severity local privilege escalation (LPE) vulnerability (CVE-2026-31431) in the Linux kernel. The flaw, nicknamed “Copy Fail”, has affected virtually every major Linux distribution shipped since 2017, and a working proof-of-concept (PoC) exploit

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Read More »

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking 2026-04-30 at 15:31 By Eduard Kovacs Claroty researchers discovered two vulnerabilities that can be exploited for security bypass and remote code execution. The post EnOcean SmartServer Flaws Expose Buildings to Remote Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

EnOcean SmartServer Flaws Expose Buildings to Remote Hacking Read More »

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months 2026-04-30 at 14:51 By Ionut Arghire The authentication bypass flaw allows attackers to gain administrative access to vulnerable servers. The post Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months Read More »

38 Vulnerabilities Found in OpenEMR Medical Software

38 Vulnerabilities Found in OpenEMR Medical Software 2026-04-29 at 12:54 By Eduard Kovacs Some of the vulnerabilities discovered by Aisle can be exploited to access and alter sensitive patient information. The post 38 Vulnerabilities Found in OpenEMR Medical Software appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

38 Vulnerabilities Found in OpenEMR Medical Software Read More »

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety 2026-04-28 at 15:10 By Eduard Kovacs Vulnerabilities in Zero Motorcycles electric motorcycles and Yadea electric scooters can pose physical security and safety risks. The post Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety appeared first on SecurityWeek. This article

Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety Read More »

No Patch for New PhantomRPC Privilege Escalation Technique in Windows

No Patch for New PhantomRPC Privilege Escalation Technique in Windows 2026-04-28 at 15:09 By Ionut Arghire A fake RPC server can be used to listen for RPC requests and impersonate the target service to elevate privileges to System. The post No Patch for New PhantomRPC Privilege Escalation Technique in Windows appeared first on SecurityWeek. This

No Patch for New PhantomRPC Privilege Escalation Technique in Windows Read More »

Incomplete Windows Patch Opens Door to Zero-Click Attacks

Incomplete Windows Patch Opens Door to Zero-Click Attacks 2026-04-27 at 20:43 By Ionut Arghire The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries. The post Incomplete Windows Patch Opens Door to Zero-Click Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Incomplete Windows Patch Opens Door to Zero-Click Attacks Read More »

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years 2026-04-27 at 20:43 By Ionut Arghire A code reuse issue enabled comma characters in certificate principals to be interpreted as list separators. The post OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years appeared first on SecurityWeek. This article is an excerpt

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years Read More »

Firefox Vulnerability Allows Tor User Fingerprinting

Firefox Vulnerability Allows Tor User Fingerprinting 2026-04-27 at 11:49 By Eduard Kovacs The vulnerability is tracked as CVE-2026-6770 and it has been patched with the release of Firefox 150 and Tor 15.0.10. The post Firefox Vulnerability Allows Tor User Fingerprinting appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Firefox Vulnerability Allows Tor User Fingerprinting Read More »

Vulnerabilities Patched in CrowdStrike, Tenable Products

Vulnerabilities Patched in CrowdStrike, Tenable Products 2026-04-24 at 13:17 By Eduard Kovacs CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw. The post Vulnerabilities Patched in CrowdStrike, Tenable Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerabilities Patched in CrowdStrike, Tenable Products Read More »

The Week in Vulnerabilities: SharePoint, Fortinet, OpenClaw, and GPL Odorizers

The Week in Vulnerabilities: SharePoint, Fortinet, OpenClaw, and GPL Odorizers 2026-04-24 at 05:54 By Mihir Bagwe Cyble Research & Intelligence Labs (CRIL) weekly vulnerability report tracked 1,675 vulnerabilities, last week, reflecting continued high disclosure volume across enterprise software, cloud services, and emerging AI ecosystems. Of these, more than 205 vulnerabilities have publicly available Proof-of-Concept (PoC)

The Week in Vulnerabilities: SharePoint, Fortinet, OpenClaw, and GPL Odorizers Read More »

Scroll to Top