vulnerability

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day 2026-07-28 at 09:40 By Ionut Arghire Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Read More »

PTC Windchill Vulnerability Exploited in Ransomware Campaign

PTC Windchill Vulnerability Exploited in Ransomware Campaign 2026-07-27 at 16:19 By Ionut Arghire The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication. The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PTC Windchill Vulnerability Exploited in Ransomware Campaign Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS […]

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider 2026-07-23 at 18:09 By Kevin Townsend AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first […]

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider Read More »

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) 2026-07-23 at 13:42 By Zeljka Zorz Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain […]

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) Read More »

New Check Point Zero-Day Vulnerability Exploited in the Wild

New Check Point Zero-Day Vulnerability Exploited in the Wild 2026-07-23 at 12:06 By Eduard Kovacs The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New Check Point Zero-Day Vulnerability Exploited in the Wild Read More »

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft 2026-07-22 at 17:22 By Eduard Kovacs An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek. This […]

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft Read More »

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, […]

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks 2026-07-22 at 14:29 By Eduard Kovacs CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Read More »

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates 2026-07-22 at 12:33 By Eduard Kovacs Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI. The post Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Read More »

Cisco Launches Low-Cost AI Models for Source Code Security

Cisco Launches Low-Cost AI Models for Source Code Security 2026-07-21 at 20:44 By Kevin Townsend The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek. This […]

Cisco Launches Low-Cost AI Models for Source Code Security Read More »

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data 2026-07-21 at 13:19 By Eduard Kovacs A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure. The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Read More »

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure 2026-07-21 at 11:41 By Eduard Kovacs The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure Read More »

Zimbra Update Patches Critical Vulnerabilities

Zimbra Update Patches Critical Vulnerabilities 2026-07-21 at 11:20 By Ionut Arghire The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Zimbra Update Patches Critical Vulnerabilities Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection […]

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability 2026-07-20 at 15:32 By Ionut Arghire Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Read More »

Chrome 150 Update Patches Severe Memory Safety Bugs

Chrome 150 Update Patches Severe Memory Safety Bugs 2026-07-20 at 11:12 By Ionut Arghire The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 150 Update Patches Severe Memory Safety Bugs Read More »

WP2Shell WordPress Vulnerabilities Exploited in the Wild

WP2Shell WordPress Vulnerabilities Exploited in the Wild 2026-07-20 at 08:21 By Eduard Kovacs Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WP2Shell WordPress Vulnerabilities Exploited in the Wild Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137 […]

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Fresh SharePoint Vulnerability Exploited Soon After Disclosure 2026-07-17 at 10:15 By Ionut Arghire The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh SharePoint Vulnerability Exploited Soon After Disclosure Read More »

Scroll to Top