vulnerability

Vulnerabilities from years ago still opening doors for attackers

Vulnerabilities from years ago still opening doors for attackers 2026-03-24 at 14:02 By Sinisa Markovic Exploitation timelines continued to compress in enterprise environments, with newly disclosed flaws reaching active use almost immediately and older weaknesses remaining active years after disclosure. (Source: Cisco Talos) Findings from Cisco Talos’ 2025 Year in Review show how attackers combined […]

Vulnerabilities from years ago still opening doors for attackers Read More »

Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn

Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn 2026-03-24 at 14:02 By Ionut Arghire An out-of-bounds read vulnerability can be exploited remotely without authentication to read sensitive information from memory. The post Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Citrix NetScaler Vulnerability Poised for Exploitation, Security Firms Warn Read More »

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992)

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) 2026-03-23 at 13:50 By Zeljka Zorz Oracle has released an out-of-band patch for a critical and easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The company did not say whether the vulnerability has been exploited as a zero-day, but

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) Read More »

QNAP Patches Four Vulnerabilities Exploited at Pwn2Own 

QNAP Patches Four Vulnerabilities Exploited at Pwn2Own  2026-03-23 at 13:50 By Ionut Arghire The flaws could allow attackers to access sensitive information, execute code, or cause unexpected behavior. The post QNAP Patches Four Vulnerabilities Exploited at Pwn2Own  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

QNAP Patches Four Vulnerabilities Exploited at Pwn2Own  Read More »

Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability

Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability 2026-03-23 at 09:18 By Eduard Kovacs CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.  The post Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability appeared first on SecurityWeek. This article is an excerpt from

Oracle Releases Emergency Patch for Critical Identity Manager Vulnerability Read More »

Critical Quest KACE Vulnerability Potentially Exploited in Attacks

Critical Quest KACE Vulnerability Potentially Exploited in Attacks 2026-03-21 at 13:00 By Eduard Kovacs The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector. The post Critical Quest KACE Vulnerability Potentially Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Critical Quest KACE Vulnerability Potentially Exploited in Attacks Read More »

Unpatched ScreenConnect servers open to attack (CVE-2026-3564)

Unpatched ScreenConnect servers open to attack (CVE-2026-3564) 2026-03-20 at 11:44 By Zeljka Zorz ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions by abusing ASP.NET machine keys to forge trusted authentication. About CVE-2026-3564 The ScreenConnect remote access platform is popular with managed service providers, IT departments, and technology solution

Unpatched ScreenConnect servers open to attack (CVE-2026-3564) Read More »

The Week in Vulnerabilities: Juniper, Cisco SD-WAN, and Critical ICS Exposure

The Week in Vulnerabilities: Juniper, Cisco SD-WAN, and Critical ICS Exposure 2026-03-20 at 11:15 By Ashish Khaitan Cyble Research & Intelligence Labs (CRIL) tracked 1,641 vulnerabilities between March 04 and March 10, 2026. Of these, 175 vulnerabilities already have publicly available Proof-of-Concept (PoC) exploits, significantly increasing the likelihood of real-world attacks.  A total of 200 vulnerabilities were rated critical under CVSS v3.1, while 61

The Week in Vulnerabilities: Juniper, Cisco SD-WAN, and Critical ICS Exposure Read More »

Critical Langflow Vulnerability Exploited Hours After Public Disclosure

Critical Langflow Vulnerability Exploited Hours After Public Disclosure 2026-03-20 at 10:42 By Ionut Arghire Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution. The post Critical Langflow Vulnerability Exploited Hours After Public Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Langflow Vulnerability Exploited Hours After Public Disclosure Read More »

Critical ScreenConnect Vulnerability Exposes Machine Keys

Critical ScreenConnect Vulnerability Exposes Machine Keys 2026-03-19 at 22:27 By Ionut Arghire Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys. The post Critical ScreenConnect Vulnerability Exposes Machine Keys appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical ScreenConnect Vulnerability Exposes Machine Keys Read More »

Russian APT Exploits Zimbra Vulnerability Against Ukraine

Russian APT Exploits Zimbra Vulnerability Against Ukraine 2026-03-19 at 16:53 By Ionut Arghire Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser. The post Russian APT Exploits Zimbra Vulnerability Against Ukraine appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Russian APT Exploits Zimbra Vulnerability Against Ukraine Read More »

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) 2026-03-19 at 13:32 By Zeljka Zorz CVE-2026-20963, a remote code execution (RCE) SharePoint vulnerability Microsoft fixed in January 2026, is being exploited by attackers. The confirmation comes from the US Cybersecurity and Infrastructure Security Agency (CISA), which added the flaw to its Known Exploited Vulnerabilities

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) Read More »

CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability

CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability 2026-03-19 at 12:02 By Eduard Kovacs The SharePoint remote code execution vulnerability CVE-2026-20963, which Microsoft patched in January, has been exploited in the wild. The post CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

CISA Warns of Attacks Exploiting Recent SharePoint Vulnerability Read More »

Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks

Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks 2026-03-19 at 11:01 By Eduard Kovacs Amazon found evidence that the FMC software vulnerability has been exploited since late January, and found links to Russia. The post Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks appeared first on SecurityWeek. This article is an

Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks Read More »

Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch

Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch 2026-03-18 at 12:47 By Eduard Kovacs Meta does not plan on fixing the vulnerability because it involves the use of a modified client application. The post Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch appeared first on SecurityWeek. This article is an excerpt

Researcher Discovers 4th WhatsApp View Once Bypass; Meta Won’t Patch Read More »

UK Companies House Exposed Details of Millions of Firms 

UK Companies House Exposed Details of Millions of Firms  2026-03-17 at 17:45 By Eduard Kovacs The government agency confirmed the vulnerability could have been exploited to obtain company details and alter records.   The post UK Companies House Exposed Details of Millions of Firms  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

UK Companies House Exposed Details of Millions of Firms  Read More »

CISA Flags Year-Old Wing FTP Vulnerability as Exploited

CISA Flags Year-Old Wing FTP Vulnerability as Exploited 2026-03-17 at 13:35 By Ionut Arghire Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application. The post CISA Flags Year-Old Wing FTP Vulnerability as Exploited appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

CISA Flags Year-Old Wing FTP Vulnerability as Exploited Read More »

Millions of UK firms on alert after Companies House data exposure

Millions of UK firms on alert after Companies House data exposure 2026-03-17 at 12:21 By Sinisa Markovic Companies House, the UK’s official company registry, said its WebFiling service is back online after being shut down on Friday to fix a security issue that may have exposed the personal data of millions of firms. An investigation

Millions of UK firms on alert after Companies House data exposure Read More »

Critical HPE AOS-CX Vulnerability Allows Admin Password Resets

Critical HPE AOS-CX Vulnerability Allows Admin Password Resets 2026-03-14 at 13:02 By Ionut Arghire The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls. The post Critical HPE AOS-CX Vulnerability Allows Admin Password Resets appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical HPE AOS-CX Vulnerability Allows Admin Password Resets Read More »

Chrome 146 Update Patches Two Exploited Zero-Days

Chrome 146 Update Patches Two Exploited Zero-Days 2026-03-13 at 09:50 By Ionut Arghire The flaws can be exploited to manipulate data and bypass security restrictions, potentially leading to code execution. The post Chrome 146 Update Patches Two Exploited Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 146 Update Patches Two Exploited Zero-Days Read More »

Scroll to Top