vulnerability

SolarWinds fixes critical Web Help Desk RCE vulnerabilities, upgrade ASAP!

SolarWinds fixes critical Web Help Desk RCE vulnerabilities, upgrade ASAP! 2026-01-29 at 11:34 By Zeljka Zorz SolarWinds has fixed six critical and high-severity vulnerabilities in its popular Web Help Desk (WHD) support ticketing and asset management solution, and is urging customers to upgrade to v2026.1 as soon as possible. The vulnerabilities The WHD vulnerabilities fixed […]

SolarWinds fixes critical Web Help Desk RCE vulnerabilities, upgrade ASAP! Read More »

The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes

The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes 2026-01-28 at 12:33 By Ashish Khaitan Cyble Vulnerability Intelligence researchers tracked 1,031 vulnerabilities in the last week, and nearly 200 already have a publicly available Proof-of-Concept (PoC), significantly increasing the likelihood of real-world attacks on those vulnerabilities.  A total of 72 vulnerabilities were rated as critical under the CVSS v3.1 scoring system, while 33 received a critical severity rating based on

The Week in Vulnerabilities: Cyble Urges Oracle, OpenStack Fixes Read More »

High-Severity Remote Code Execution Vulnerability Patched in OpenSSL

High-Severity Remote Code Execution Vulnerability Patched in OpenSSL 2026-01-28 at 09:48 By Eduard Kovacs A total of 12 vulnerabilities have been fixed in OpenSSL, all discovered by a single cybersecurity firm. The post High-Severity Remote Code Execution Vulnerability Patched in OpenSSL appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

High-Severity Remote Code Execution Vulnerability Patched in OpenSSL Read More »

Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858)

Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858) 2026-01-28 at 02:21 By Zeljka Zorz Fortinet has begun releasing FortiOS versions that fix CVE-2026-24858, a critical zero-day vulnerability that allowed attackers to log into targeted organizations’ FortiGate firewalls. “This vulnerability was found being exploited in the wild by two malicious FortiCloud accounts, which were locked out

Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858) Read More »

Organizations Warned of Exploited Linux Vulnerabilities

Organizations Warned of Exploited Linux Vulnerabilities 2026-01-27 at 12:47 By Ionut Arghire The flaws allow threat actors to obtain root privileges or bypass authentication via Telnet and gain shell access as root. The post Organizations Warned of Exploited Linux Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Warned of Exploited Linux Vulnerabilities Read More »

Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms

Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms 2026-01-26 at 18:51 By Eduard Kovacs More than 20 vulnerabilities were found and patched in Dormakaba physical access control systems. The post Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms appeared first on SecurityWeek. This article is an excerpt

Access System Flaws Enabled Hackers to Unlock Doors at Major European Firms Read More »

2024 VMware Flaw Now in Attackers’ Crosshairs

2024 VMware Flaw Now in Attackers’ Crosshairs 2026-01-26 at 07:36 By Ionut Arghire The critical-severity vulnerability can be exploited via crafted network packets for remote code execution. The post 2024 VMware Flaw Now in Attackers’ Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

2024 VMware Flaw Now in Attackers’ Crosshairs Read More »

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026 2026-01-23 at 13:33 By Eduard Kovacs Pwn2Own participants disclosed a total of 76 vulnerabilities during the three-day event.  The post Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Infotainment, EV Charger Exploits Earn Hackers $1M at Pwn2Own Automotive 2026 Read More »

Furl Raises $10 Million for Autonomous Vulnerability Remediation

Furl Raises $10 Million for Autonomous Vulnerability Remediation 2026-01-22 at 13:11 By Ionut Arghire The startup will use the new funding to accelerate product development and deepen remediation capabilities. The post Furl Raises $10 Million for Autonomous Vulnerability Remediation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Furl Raises $10 Million for Autonomous Vulnerability Remediation Read More »

Atlassian, GitLab, Zoom Release Security Patches

Atlassian, GitLab, Zoom Release Security Patches 2026-01-22 at 11:49 By Ionut Arghire Fixes were rolled out for over two dozen vulnerabilities, including critical- and high-severity bugs. The post Atlassian, GitLab, Zoom Release Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, GitLab, Zoom Release Security Patches Read More »

Hackers Targeting Cisco Unified CM Zero-Day 

Hackers Targeting Cisco Unified CM Zero-Day  2026-01-22 at 11:07 By Eduard Kovacs Cisco has released patches for CVE-2026-20045, a critical vulnerability that can be exploited for unauthenticated remote code execution. The post Hackers Targeting Cisco Unified CM Zero-Day  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Targeting Cisco Unified CM Zero-Day  Read More »

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718?

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718? 2026-01-21 at 22:22 By Zeljka Zorz CVE-2025-59718, a critical authentication bypass flaw that attackers exploited in December 2025 to compromise FortiGate appliances, appears to persist in newer, purportedly fixed releases of the underlying FortiOS. According to Fortinet, CVE-2025-59718 had been fixed in FortiOS versions 7.6.4 or

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718? Read More »

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045)

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045) 2026-01-21 at 20:57 By Zeljka Zorz Cisco has fixed a critical remote code execution vulnerability (CVE-2026-20045) in some of its unified communications solutions that’s being targeted by attackers in the wild, the company announced on Wednesday via a security advisory. About CVE-2026-20045 CVE-2026-20045 is

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045) Read More »

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure 2026-01-21 at 13:46 By Ionut Arghire Impacting Anthropic’s official MCP server, the vulnerabilities can be exploited through prompt injections. The post Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Anthropic MCP Server Flaws Lead to Code Execution, Data Exposure Read More »

Oracle’s First 2026 CPU Delivers 337 New Security Patches

Oracle’s First 2026 CPU Delivers 337 New Security Patches 2026-01-21 at 12:53 By Ionut Arghire Oracle’s January 2026 CPU resolves roughly 230 unique vulnerabilities across more than 30 products. The post Oracle’s First 2026 CPU Delivers 337 New Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Oracle’s First 2026 CPU Delivers 337 New Security Patches Read More »

Chainlit Vulnerabilities May Leak Sensitive Information

Chainlit Vulnerabilities May Leak Sensitive Information 2026-01-20 at 17:01 By Ionut Arghire The two bugs, an arbitrary file read and an SSRF bug, can be exploited without user interaction to leak credentials, databases, and other data. The post Chainlit Vulnerabilities May Leak Sensitive Information appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Chainlit Vulnerabilities May Leak Sensitive Information Read More »

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking 2026-01-19 at 17:21 By Eduard Kovacs The researcher who discovered the vulnerability saw more than 2,500 internet-exposed devices. The post TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

TP-Link Patches Vulnerability Exposing VIGI Cameras to Remote Hacking Read More »

New StackWarp Attack Threatens Confidential VMs on AMD Processors

New StackWarp Attack Threatens Confidential VMs on AMD Processors 2026-01-15 at 20:27 By Eduard Kovacs Researchers have disclosed technical details on a new AMD processor attack that allows remote code execution inside confidential VMs. The post New StackWarp Attack Threatens Confidential VMs on AMD Processors appeared first on SecurityWeek. This article is an excerpt from

New StackWarp Attack Threatens Confidential VMs on AMD Processors Read More »

PoC exploit for critical FortiSIEM vulnerability released (CVE-2025-64155)

PoC exploit for critical FortiSIEM vulnerability released (CVE-2025-64155) 2026-01-15 at 15:27 By Zeljka Zorz A critical vulnerability (CVE-2025-64155) in Fortinet’s FortiSIEM security platform has now been accompanied by publicly released proof-of-concept (PoC) exploit code, raising the urgency for organizations to patch immediately. About CVE-2025-64155 CVE-2025-64155 may allow unauthenticated, remote attackers to execute unauthorized code or

PoC exploit for critical FortiSIEM vulnerability released (CVE-2025-64155) Read More »

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact 2026-01-15 at 11:34 By Eduard Kovacs Only a dozen new advisories have been published this Patch Tuesday by industrial giants.  The post ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Aveva, Phoenix Contact Read More »

Scroll to Top