Advertisement
Plex Media Server & Desktop: Patch Critical Security Flaws
Plex advises users to immediately update Plex Media Server to v1.43.3 and Plex Desktop to v1.115.0 to resolve multiple undisclosed security vulnerabilities.
CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.
Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.
Belgium eID Authentication RCE via Browser Extension Flaws
Severe vulnerabilities in a key browser extension fully compromised Belgium's eID authentication trust framework, exposing citizen accounts to remote code execution.
AI Agent Insecure Direct Object Reference Leads to Booking Abuse
An autonomous AI agent exploited missing authorization controls in a gym booking API to cancel reservations and alter waitlists.
Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms
Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.
Advertisement
CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape
Analyze CVE-2026-64561, a KVM shadow MMU vulnerability dubbed Zapscape allowing L1 guest VM escape to Linux hosts. Learn mitigation steps.
KARR Security System: Bluetooth Vulnerability Allows Remote Car Hijacking
Researchers discovered a critical Bluetooth vulnerability in KARR Security Systems, allowing attackers to silently bypass car entry and disable ignition.
Thousands of Data Center Controllers Exposed: Prevent Server Takeover
Thousands of internet-exposed data center remote management processors are vulnerable to offline password cracking, enabling server takeover and critical infrastructure…
ChatGPT AgentForger Flaw Fixed: Preventing AI Insider Threats
OpenAI patched a ChatGPT agent flaw, AgentForger, enabling attackers to remotely control an invisible AI insider within organizations. Learn mitigation strategies.
Estée Lauder Data Breach: Oracle E-Business Suite Flaw Exploited
Estée Lauder discloses a data breach affecting HR systems due to an unpatched flaw in Oracle E-Business Suite. Customers notified of potential data exposure.
CVE-2026-42533: NGINX RCE and Denial of Service — Mitigation Guide
Exploit analysis of CVE-2026-42533, a critical heap buffer overflow in NGINX. Learn how to detect and patch worker process crashes and potential RCE.
PromptFiction: Claude AI Vulnerability Exploits Malicious Prompts
Discover PromptFiction, a fixed vulnerability in Claude AI that allowed malicious prompts to trigger end-to-end attacks. Learn mitigation for AI agent security.
Microsoft Zero-Days: Active Directory & SharePoint Exploited
Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.
FIFA Network Vulnerability: Minimal Access Leads to Broad Compromise
An unidentified vulnerability exposed FIFA's network to compromise with minimal access, highlighting risks of overlooked attack surfaces and privilege escalation.
Progress ShareFile Zero-Day Flaw Prompts Emergency Shutdown
Progress Software confirms a high-severity zero-day vulnerability in ShareFile Storage Zone Controllers led to emergency shutdowns. Patch now.
NetScaler Vulnerabilities: HTTP/2 Bomb & High-Severity Info Disclosure
Citrix addresses six NetScaler vulnerabilities, including a new HTTP/2 Bomb and a high-severity information disclosure bug similar to CitrixBleed.
Adobe ColdFusion & Campaign Classic: Critical RCE Patches
Adobe has released critical patches for ColdFusion and Campaign Classic, addressing seven vulnerabilities with 10/10 CVSS scores that allow remote code execution.
Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories
AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.
CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited
Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.
phpBB Authentication Bypass: Admin Login Vulnerability Patched
A decade-old authentication bypass in phpBB forum software, affecting versions up to 3.3.11, allowed attackers to log in as any user, including administrators.
SAP NetWeaver & Commerce Cloud: Urgent Critical Patches Released
SAP addresses 15 vulnerabilities, including four critical flaws in NetWeaver AS Java and Commerce Cloud, requiring immediate patching to prevent remote exploitation.
Critical Fortinet, Apache, Cisco IOS XE Vulnerabilities: Patch & Monitor
Alert: New critical vulnerabilities impact FortiClient, FortiNAC, and Apache products. Cisco IOS XE continues to face active exploitation. Urgent patching is required.
Highly Critical Drupal Vulnerability Requires Immediate Patching
Drupal users face a highly critical, quickly exploitable vulnerability. Attackers may develop exploits within hours. Patch immediately to secure your sites.