vulnerability

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA Warns of Exploited Oracle WebLogic Vulnerability 2026-08-25 at 10:46 By Eduard Kovacs The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Warns of Exploited Oracle WebLogic Vulnerability Read More »

91 Vulnerabilities Patched in Spring Application Framework

91 Vulnerabilities Patched in Spring Application Framework 2026-08-24 at 14:58 By Eduard Kovacs More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.  The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

91 Vulnerabilities Patched in Spring Application Framework Read More »

Critical Isolated-vm Vulnerability Leads to RCE on Host

Critical Isolated-vm Vulnerability Leads to RCE on Host 2026-08-21 at 15:26 By Ionut Arghire The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Isolated-vm Vulnerability Leads to RCE on Host Read More »

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) 2026-08-21 at 15:20 By Sinisa Markovic Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, […]

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) Read More »

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft Rolls Out 22 Fresh Security Patches 2026-08-21 at 11:12 By Ionut Arghire Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Rolls Out 22 Fresh Security Patches Read More »

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) 2026-08-21 at 10:55 By Sinisa Markovic Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible. “We strongly recommend that customers review the […]

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) Read More »

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities 2026-08-21 at 10:25 By Ionut Arghire The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Read More »

Hackers Target Zimbra Servers in Active Exploitation Campaign

Hackers Target Zimbra Servers in Active Exploitation Campaign 2026-08-20 at 17:50 By Eduard Kovacs Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska. The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Target Zimbra Servers in Active Exploitation Campaign Read More »

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities 2026-08-20 at 15:24 By Ionut Arghire The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Read More »

MLflow Vulnerability Exploited for Cloud Credential Theft

MLflow Vulnerability Exploited for Cloud Credential Theft 2026-08-20 at 15:05 By Ionut Arghire The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MLflow Vulnerability Exploited for Cloud Credential Theft Read More »

943 Patches Rolled Out With Oracle’s August 2026 Security Update

943 Patches Rolled Out With Oracle’s August 2026 Security Update 2026-08-19 at 12:14 By Ionut Arghire The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Oracle’s August 2026 Security Update appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

943 Patches Rolled Out With Oracle’s August 2026 Security Update Read More »

Chrome, Firefox Updates Patch Dozens of Vulnerabilities

Chrome, Firefox Updates Patch Dozens of Vulnerabilities 2026-08-19 at 11:19 By Ionut Arghire The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome, Firefox Updates Patch Dozens of Vulnerabilities Read More »

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model 2026-08-18 at 16:00 By Kevin Townsend Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores. The post AI-Driven Vulnerability Surge Breaks the Traditional Patching Model appeared first on SecurityWeek. This article is […]

AI-Driven Vulnerability Surge Breaks the Traditional Patching Model Read More »

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) 2026-08-18 at 14:38 By Sinisa Markovic GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before […]

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) Read More »

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer 2026-08-17 at 15:23 By Sinisa Markovic A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let […]

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer Read More »

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Recent macOS Screen Sharing Vulnerability Exploited in Attacks 2026-08-17 at 11:47 By Ionut Arghire Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent macOS Screen Sharing Vulnerability Exploited in Attacks Read More »

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure 2026-08-17 at 11:13 By Eduard Kovacs The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure Read More »

Adobe Commerce Bug Targeted Immediately After Disclosure

Adobe Commerce Bug Targeted Immediately After Disclosure 2026-08-13 at 17:17 By Ionut Arghire The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Adobe Commerce Bug Targeted Immediately After Disclosure Read More »

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

WordPress 7.0.4 Patches Remote Code Execution Vulnerability 2026-08-13 at 15:53 By Ionut Arghire Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress 7.0.4 Patches Remote Code Execution Vulnerability Read More »

Scroll to Top