Topic: security patch
-
CISA Warns of Active VMware RCE Attacks
A critical command injection vulnerability (CVE-2026-22719) in VMware Aria Operations is under active exploitation, allowing unauthenticated attackers to execute arbitrary commands and potentially take full control of systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has m...
Read More » -
Critical Windows Notepad Flaw (CVE-2026-20841) Enables RCE via Markdown
A critical vulnerability (CVE-2026-20841) in Windows Notepad, stemming from its new Markdown support, allowed remote code execution via malicious links in Markdown files. Exploitation required user interaction, such as clicking a crafted link, but was made easier as Markdown files are often perce...
Read More » -
CISA Alerts: SmarterMail RCE Flaw Actively Exploited in Ransomware
A critical, unauthenticated remote code execution flaw (CVE-2026-24423) in SmarterMail is being actively exploited by ransomware groups, prompting urgent warnings from CISA. The vulnerability, stemming from a missing authentication check, allows attackers to take control of unpatched systems, and...
Read More » -
Cisco Patches Actively Exploited Zero-Day RCE Vulnerability
Cisco has patched a critical, actively exploited zero-day vulnerability (CVE-2026-20045) that allows remote attackers to gain root control over its communication platforms by sending malicious HTTP requests. The flaw impacts multiple products including Unified Communications Manager and Webex Cal...
Read More » -
Critical React & Node.js Flaw Patched: Update Now (CVE-2025-55182)
A critical remote code execution vulnerability (CVE-2025-55182) affects React versions 19.0.0 through 19.2.0, requiring an immediate update to version 19.2.1. The flaw involves unsafe deserialization in React Server Components, impacting not only React but also major dependent frameworks like Nex...
Read More » -
Critical SonicWall SonicOS Flaw Lets Hackers Crash Firewalls
SonicWall has issued an urgent warning about a high-severity security flaw (CVE-2025-40601) in its SonicOS SSLVPN service, which could allow attackers to crash affected firewalls via a denial-of-service attack, impacting Gen7 and Gen8 hardware and virtual firewalls. The company states there is no...
Read More » -
Critical RCE Flaw Found in Popular expr-eval JavaScript Library
A critical remote code execution vulnerability (CVE-2025-12735) has been found in the widely used expr-eval JavaScript library, affecting over 800,000 weekly downloads and posing severe risks to dependent applications. The flaw arises from improper validation in the Parser.evaluate() function, al...
Read More » -
October Android Update Fixes Pixel Display & UI Issues
Google has released the first Android 16 QPR1 update with the October security patch for various Pixel devices, addressing UI and display issues without fixing any security vulnerabilities. The update includes specific fixes for display glitches, such as screen flickering on Pixel 7 models and fr...
Read More » -
Clop Hackers Use Oracle Zero-Day to Steal Executive Data
Oracle has patched a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite, which hackers exploited to steal sensitive personal data from corporate executives without needing login credentials. The hacking group Clop has been linked to this mass exploitation campaign, sending e...
Read More » -
American Archive of Public Broadcasting Patches Security Flaw
A security flaw in the American Archive of Public Broadcasting (AAPB) website allowed unauthorized downloads of protected media files for years, which was exploited since at least 2021 and has now been fixed. The vulnerability was an Insecure Direct Object Reference (IDOR) flaw that let users byp...
Read More » -
Cisco patches critical flaw in enterprise comms platform (CVE-2025-20309)
Cisco has released an urgent patch for a critical vulnerability (CVE-2025-20309) involving default root credentials, allowing attackers remote administrative access to affected systems. The flaw impacts Cisco Unified Communications Manager and its Session Management Edition, affecting specific En...
Read More » -
eScan AV Users Hit by Malicious Update Attack
Unknown attackers compromised eScan's update server, weaponizing it to deploy a malicious downloader that disabled the antivirus and blocked future security updates. The breach, detected in January 2026, forced the vendor to take its global update system offline and required many users to manuall...
Read More » -
5-Year-Old FortiOS 2FA Flaw Actively Exploited, Fortinet Warns
A critical 2020 Fortinet FortiGate firewall vulnerability (CVE-2020-12812) is still being actively exploited, allowing attackers to bypass two-factor authentication by manipulating username case during login. Despite patches being available for over five years, exploitation continues, particularl...
Read More » -
Critical Vulnerability Found in W3 Total Cache WordPress Plugin
A critical security flaw (CVE-2025-9501) in the W3 Total Cache WordPress plugin allows unauthenticated attackers to execute arbitrary PHP commands via specially crafted comments, affecting all versions before 2.8.13. The vulnerability, located in the `_parse_dynamic_mfunc()` function, was fixed i...
Read More » -
Active Attack Exploits Critical Adobe Commerce, Magento Flaw
Security researchers have identified active exploitation of a critical Adobe Commerce and Magento vulnerability (CVE-2025-54236, SessionReaper), which allows attackers to hijack customer accounts and potentially execute remote code, with over 250 attack attempts blocked in a single day. The vulne...
Read More » -
ServiceNow bug exposed some customer data to the internet
ServiceNow patched a vulnerability on June 5 that allowed unrestricted internet access to customer data without authentication, leaving sensitive information exposed. The flaw affected customer instances globally, not just in Australia as stated by ServiceNow, with an IP address (51.159.98.241) f...
Read More » -
CISA Warns Hackers Exploit Langflow AI Flaw
A critical vulnerability (CVE-2026-33017) in the Langflow AI framework enables unauthenticated remote code execution, prompting an urgent CISA warning and a federal patching deadline of April 8. Exploitation began rapidly on March 19, with attackers scanning for and compromising systems to steal ...
Read More » -
Urgent: CISA Confirms Active Attacks Exploiting Critical Microsoft SCCM Flaw
A critical SQL injection vulnerability (CVE-2024-43468) in Microsoft Configuration Manager is now being actively exploited, allowing unauthenticated attackers to execute arbitrary code with the highest privileges. The Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal ag...
Read More » -
SonicWall SMA1000 Zero-Day Exploited in Active Attacks
SonicWall has issued an urgent alert for SMA1000 appliance users to apply a critical update, as active attacks exploit a new medium-severity local privilege escalation flaw (CVE-2025-40602) chained with a previously patched critical bug to achieve remote code execution with root privileges. The v...
Read More » -
Ivanti warns of critical code execution flaw in Endpoint Manager
A critical vulnerability (CVE-2025-10573) in Ivanti's Endpoint Manager allows unauthenticated attackers to execute arbitrary code by tricking an administrator into viewing a compromised dashboard. Ivanti has released a patch, but the risk is heightened as hundreds of EPM instances are exposed onl...
Read More »