Adobe has released security patches addressing critical vulnerabilities in its ColdFusion and Campaign Classic software. Among these are six flaws in ColdFusion and one in Campaign Classic, all having the highest CVSS severity score of 10.0. These vulnerabilities can lead to arbitrary code execution, posing significant risks to systems if not promptly patched.
One of the vulnerabilities, identified as CVE-2026-48282, is currently being exploited by hackers. This flaw allows attackers to remotely execute code on unpatched systems, making its immediate remediation crucial. Adobe and security organizations like CISA have stressed the need for users to update their systems as soon as possible.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, signaling the active exploitation of this vulnerability in the wild. This inclusion underscores the critical nature of the flaw and the priority for system administrators to apply the updates provided by Adobe.
Patching these flaws is imperative to protect against potential security breaches. Administrators of systems using ColdFusion and Campaign Classic should prioritize these updates to mitigate risks associated with the vulnerabilities, thus ensuring the security and integrity of their applications and data.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
CISA and Fortinet issued an alert regarding a critical FortiMail zero-day vulnerability (CVE-2026-104286) that is being actively exploited. The flaw allows attackers to write arbitrary files and potentially execute code, with patches not yet released.
A critical zero-day vulnerability in Fortinet FortiMail (CVE-2026-104286) is being actively exploited, allowing unauthenticated attackers to write arbitrary files on affected systems. CISA has added this flaw to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply patches or workarounds by October 4, 2026.
Debian has released a security advisory, DSA-6528-1, addressing numerous vulnerabilities in the Linux kernel. This advisory lists over 100 CVEs, indicating a broad range of security flaws that require patching to maintain system integrity and prevent potential exploits.
Fortinet issued a warning about a critical FortiMail vulnerability (CVE-2026-104286) with a CVSS score of 9.8, which is being actively exploited in zero-day attacks. The flaw allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests to the management interface, enabling unauthorized code execution.
A high-severity OS command injection vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS) was exploited by attackers between the patch release and public disclosure. Attackers used specially crafted SMTP requests to achieve remote code execution, deploy webshells, and exfiltrate credentials.
CISA has added a critical authentication bypass vulnerability (CVE-2026-76504) in Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. This flaw allows unauthenticated remote attackers to gain admin privileges, making it a significant concern for organizations using the platform.
Cisco released urgent patches for CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager that is actively being exploited. This flaw allows remote, unauthenticated attackers to gain administrative access, affecting all deployments regardless of configuration.
Threat actors are exploiting a critical pre-authentication command injection vulnerability (CVE-2026-88771) in Citrix NetScaler ADC and Gateway to install web shells and exfiltrate configuration data. The exploitation involves attacker-controlled usernames and the deployment of second-stage payloads that create superuser accounts and establish reverse shells, indicating activity beyond basic vulnerability validation.
Microsoft reported that attackers are exploiting CVE-2026-73570, a critical vulnerability in Zimbra Collaboration Suite, to steal email backups and authentication credentials. The flaw allows unauthenticated remote operating system command execution, impacting organizations across various sectors and regions.
Threat actors exploited a patched Zimbra Collaboration Suite (ZCS) vulnerability (CVE-2026-73570) to deploy web shells and access mailbox data. This flaw allowed remote code execution via a crafted SMTP request, impacting organizations across multiple regions and industries.
CISA issued a warning about CVE-2026-84411, a critical pre-authentication integer underflow vulnerability in MikroTik RouterOS that allows remote code execution or denial-of-service. The flaw affects RouterOS versions below 7.24, and users are advised to update to version 7.23 or later to mitigate the risk.
Cisco issued an advisory regarding active exploitation of CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager. This flaw allows unauthenticated remote attackers to gain administrative access to the Manager's API, posing a significant risk to affected organizations.
Cisco released security updates for a critical zero-day vulnerability (CVE-2026-76504) in its Catalyst SD-WAN Manager, which attackers are actively exploiting to gain administrative privileges. This vulnerability allows unauthenticated remote access due to improper handling of URI encoding in HTTP requests, bypassing authentication rules.
WatchGuard released patches for 15 vulnerabilities in Fireware OS, including a critical remote code execution (RCE) flaw (CVE-2026-86131) that allows remote attackers to execute commands with root privileges. Additionally, fixes were issued for two critical RCE flaws in WatchGuard Access Points, which could allow unauthenticated API session acquisition and arbitrary shell command execution. These updates address significant security risks in WatchGuard's network devices.
Mandiant and GTIG reported active exploitation of NetScaler zero-days CVE-2026-88771 and CVE-2026-88772 since early September, affecting government, financial, and other sectors. Attackers gained root access, deployed web shells and tunneling tools for internal network reconnaissance and credential theft, impacting dozens of organizations.
TeamViewer issued an urgent advisory for users to update their client and host software due to multiple high-severity vulnerabilities. These flaws, including a remote session access control bypass, could allow remote code execution or privilege escalation on affected systems. Updating to version 15.82 is recommended to mitigate potential exploitation.
Threat actors are exploiting a newly patched vulnerability (CVE-2026-88772) in Citrix NetScaler ADC and Gateway appliances to gain root access and deploy custom malware. The attacks, observed in North America and Europe, target government, financial, and technology sectors, enabling reconnaissance and credential theft.
OpenSSL and WolfSSL have released patches addressing multiple vulnerabilities, including high-severity flaws that could lead to data exposure, denial-of-service, or authentication bypass. These updates are critical for applications using these cryptographic libraries, such as VPNs, VoIP, IoT products, and various web servers, to maintain secure communication and prevent potential exploits.
Cybersecurity researchers have published technical details of CVE-2026-88772, a critical memory overflow vulnerability in Citrix NetScaler ADC and Gateway that is currently being exploited. This flaw allows for remote code execution or denial-of-service due to improper handling of Datagram Transport Layer Security (DTLS) fragment sizes, enabling attackers to write past buffer limits and potentially execute shellcode with root privileges.
Attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day vulnerability to deploy web shells, gain root access, and steal credentials from organizations in North America and Europe. Citrix released security updates for CVE-2026-88771 and CVE-2026-88772, both of which were exploited in unmitigated NetScaler deployments.
Mandiant and Google Threat Intelligence Group identified active exploitation of two zero-day vulnerabilities, CVE-2026-88772 and CVE-2026-88771, in Citrix NetScaler ADC and NetScaler Gateway appliances. The exploitation allows for authentication bypass and root-level access, impacting government, financial, education, and legal sectors in North America and Europe.
Three Artifactory vulnerabilities, including one critical and two high-severity, are under active exploitation, enabling authentication bypass and persistent administrator access on self-hosted instances. Attackers can chain these flaws to gain full control, leading to credential theft, arbitrary code execution, and persistence. Users with exposed instances should assume compromise and hunt for post-exploitation artifacts.
Government cybersecurity agencies in the US, UK, and Netherlands issued urgent warnings about two actively exploited zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler application delivery controllers (ADC) and Gateway devices. These vulnerabilities, with severity scores of 9.5 out of 10, allow threat actors to exploit critical network infrastructure, prompting CISA to mandate patching for federal agencies and advise all users to review Citrix advisories.
Citrix released patches for actively exploited vulnerabilities (CVE-2026-88771, CVE-2026-88772) in NetScaler ADC and Gateway, which allow for arbitrary command execution and remote code execution. Separately, cryptocurrency exchange Bitget resumed withdrawals after a $387 million hack, attributed to suspected North Korean actors, impacting its hot wallets.
Citrix released patches for two critical NetScaler zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, which are being actively exploited. These vulnerabilities, with CVSS scores of 9.5, affect NetScaler ADC and Gateway, prompting CISA to add them to its Known Exploited Vulnerabilities catalog and issue an alert.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two critical Citrix NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771, CVE-2026-88772) to its Known Exploited Vulnerabilities catalog. Threat actors are actively exploiting these flaws globally, which could allow unauthenticated command execution or remote code execution.
CISA has ordered U.S. government agencies to patch two critical Citrix NetScaler vulnerabilities (CVE-2026-88771 and CVE-2026-88772) by Wednesday. These flaws allow unauthenticated remote code execution and are actively being exploited in zero-day attacks, posing a significant risk to affected systems.
Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being actively exploited in attacks and released security updates. These zero-days affect NetScaler ADC and NetScaler Gateway appliances, posing a significant risk as these devices are often internet-facing and can provide attackers with an initial network foothold.
Two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, allowing remote code execution, are being actively exploited. These flaws are distinct from a previously patched authentication bypass and affect critical network edge devices, prompting some administrators to take appliances offline.
The ShinyHunters extortion group is using a URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate the Oracle PeopleSoft CVE-2026-35273 flaw. This technique allows the group to continue exploiting the vulnerability on servers that have not applied security updates, despite WAFs blocking the vulnerable endpoint.
Google has issued a warning about renewed mass exploitation of a known Oracle PeopleSoft vulnerability (CVE-2026-35273) by the ShinyHunters-linked group. The attackers are bypassing web application firewalls (WAFs) by URL-encoding a character in the request path, allowing them to deploy web shells and achieve remote code execution across various sectors globally.
The threat group UNC6240 (ShinyHunters) has renewed its mass exploitation campaign targeting Oracle PeopleSoft vulnerability CVE-2026-35273, expanding its global reach across multiple sectors. The group developed a WAF bypass technique by URL-encoding a character in the request path, allowing them to exploit systems protected by string-based WAF rules. This campaign follows an earlier zero-day exploitation and targets organizations that implemented WAF rules but did not patch the vulnerability.
A pre-authentication SQL injection vulnerability (CVE-2026-48842) in Roundcube Webmail's virtuser_query plugin is being actively exploited. This flaw allows unauthenticated attackers to inject SQL statements, potentially exposing mail account credentials and stored messages. Organizations using affected Roundcube versions should update immediately to mitigate the risk of data compromise.
Researchers detailed the full exploitation of CVE-2025-13032, a double-fetch vulnerability in Avast Antivirus's kernel driver, on Windows 11. The exploit achieved arbitrary kernel read/write and SYSTEM privilege escalation via token theft, demonstrating a method to bypass the antivirus sandbox.
A high-severity SQL injection vulnerability (CVE-2026-48842) in the open-source Roundcube webmail client is being actively exploited by threat actors. This flaw allows unauthenticated attackers to bypass security measures in the virtuser_query plugin, potentially leading to data tampering and unauthorized access to user information.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in WSO2 and Adobe Commerce/Magento to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These flaws could lead to remote code execution in WSO2 products and elevated access in Adobe Commerce, posing risks to affected organizations.
A high-severity SQL injection vulnerability in Roundcube Webmail (CVE-2026-48842), patched in May, is now being actively exploited in attacks. This flaw allows unauthenticated threat actors to bypass authentication, execute malicious database commands, and steal data from Roundcube databases, impacting thousands of services using the client.
CISA has warned that ransomware gangs are now exploiting a critical authentication bypass vulnerability (CVE-2026-63077) in JetBrains TeamCity On-Premises. This flaw allows unauthenticated attackers to execute arbitrary commands, potentially compromising CI/CD pipelines and sensitive data.
SolarWinds released patches for two critical remote code execution (RCE) vulnerabilities, CVE-2026-28324 and CVE-2026-28325, in its Observability Self-Hosted product. These flaws, which could allow unauthenticated remote attackers to execute code, affect all versions up to 2026.2.2 and were addressed in version 2026.2.3.
Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution vulnerability in its Security Gateway VPN, and CVE-2026-93616, a pre-authentication path traversal flaw. Attackers began exploiting these vulnerabilities on September 12, prompting CISA to add them to its Known Exploited Vulnerabilities catalog and urge federal agencies to apply fixes by September 25, 2026.
A vulnerability chain, dubbed MikroTrick, allows attackers to gain full administrative control over Internet-exposed MikroTik routers without requiring a password or SSH key. This chain combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug (CVE-2026-86060) in the RouterOS login process. The exploit was observed in logs before MikroTik released patches on September 3.
A recent InfraTrust Pulse report indicates a rise in attacks targeting network management systems, with several critical vulnerabilities actively exploited. This trend allows attackers to gain full control over compromised infrastructure, highlighting a shift in high-value targets for cybercriminals.
Arista Networks released security patches for CVE-2026-93952, an actively exploited zero-day vulnerability affecting VeloCloud Orchestrator (VCO) On-Prem deployments. The flaw allows remote attackers to access privileged internal VCO host functionality without authentication, prompting CISA to add it to its Known Exploited Vulnerabilities catalog.
Security firm DepthFirst released an exploit for a use-after-free vulnerability (CVE-2026-80521) in the Linux kernel's AF_UNIX socket subsystem that allows container escape and root access on the host. The flaw was fixed upstream in August, but Ubuntu has not yet patched its 26.04, 24.04, and 22.04 LTS releases, leaving many systems vulnerable to attack.
Arista has issued urgent patches for a critical-severity zero-day vulnerability (CVE-2026-93952) in its on-premises VeloCloud Orchestrator (VCO) deployments, which is actively being exploited. This flaw, an improper input validation issue, allows remote attackers to access privileged internal functionality, impacting the confidentiality, integrity, and availability of the orchestrator and its managed data.
F5 released hotfixes for a critical vulnerability (CVE-2026-94127) in BIG-IP Access Policy Manager (APM) that allows unauthenticated remote code execution. The flaw affects systems where APM functions as an OAuth authorization server and has been added to CISA's Known Exploited Vulnerabilities catalog.
F5 and CISA issued warnings about a critical vulnerability (CVE-2026-94127) in BIG-IP Access Policy Manager (APM) being actively exploited as a zero-day. The flaw allows unauthenticated remote code execution when specific configurations are present, prompting CISA to add it to its Known Exploited Vulnerabilities list.
F5 released security updates for a critical zero-day vulnerability in its BIG-IP APM product, which is actively being exploited for remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities Catalog, mandating U.S. federal agencies to patch by Friday due to the significant risk posed by such vulnerabilities.
Check Point released urgent patches for CVE-2026-93616, a critical directory traversal vulnerability in its Management Server products that has been actively exploited as a zero-day. This flaw allows unauthenticated attackers to upload and execute arbitrary scripts, impacting multiple Check Point security products.
Check Point reported that a zero-day vulnerability (CVE-2026-93616) in its Security Management Server was exploited in targeted attacks on July 23. The flaw, a path traversal bug, allowed attackers to run scripts on the server without authentication, prompting Check Point to release a fix on September 22.
A critical vulnerability (CVE-2026-90898) in Bifrost, an open-source AI gateway, allows unauthenticated attackers to execute arbitrary commands on the server. This flaw affects versions before 2.1.0 when management authentication is disabled by default, potentially exposing API keys for over 20 LLM providers.
Check Point Software released emergency hotfixes for a critical path traversal vulnerability (CVE-2026-93616) in its Security Management Server, which is actively being exploited in attacks. The flaw allows unauthenticated attackers to upload and execute arbitrary scripts, impacting multiple Check Point products.
D-Link issued a warning about a critical zero-day stack-based buffer overflow vulnerability in its DIR-822A routers, which can lead to remote code execution without authentication. A public proof-of-concept exploit exists, increasing the risk of immediate exploitation.
Arista announced that a new critical vulnerability (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) is being actively exploited. This flaw, with a CVSS 3.1 score of 10.0, affects VCO deployments configured for certificate-based authentication and can lead to full compromise of the orchestrator and managed Edge devices.
A Chinese threat actor has been exploiting CVE-2026-7273, a stack-based buffer overflow vulnerability in ZyXEL GS1900 switches, to exfiltrate sensitive information from devices in 48 countries. ZyXEL released patches in June, and the US CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it within three days.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Zyxel GS1900 series switch vulnerability (CVE-2026-7273) to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it by Thursday. This flaw, a stack-based buffer overflow, allows unprivileged attackers to execute OS commands and has been exploited to exfiltrate data from nearly 1,000 switches globally.
CISA added a patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273) to its Known Exploited Vulnerabilities catalog due to active exploitation. Separately, a local privilege escalation flaw in Veeam Agent for Windows (CVE-2026-32996) is also being actively exploited, allowing attackers to gain SYSTEM-level control.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the active exploitation of three Linux kernel vulnerabilities, one of which is rated critical and existed for 14 years. Federal agencies are mandated to apply security updates and mitigations by the end of today and conduct forensic triage on affected assets, as public exploits are available for two of the flaws.
Cisco issued a warning about an actively exploited maximum-severity authentication bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE). Separately, the U.S. government seized domains associated with the NightmareStresser DDoS-for-hire service, and researchers demonstrated using Anthropic's Claude Opus 5 to chain vulnerabilities for unauthorized access to OpenAI employee accounts.
The Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them immediately. These flaws, including a critical zero-length record handling issue, a race condition, and an out-of-bounds write, could lead to denial-of-service or memory corruption. The inclusion in the KEV catalog signifies active exploitation and mandates prompt remediation for government systems.
SolarWinds released security updates for Access Rights Manager (ARM) to fix a high-severity vulnerability (CVE-2026-28326) that allowed unauthenticated remote code execution due to a hard-coded key. This patch addresses a critical security risk in a widely used IT management product.
A critical unauthenticated remote code execution vulnerability, CVE-2026-58138, in Orkes Conductor versions 3.21.21 before 3.30.2 is being actively exploited in the wild. Attackers are submitting malicious JavaScript or Python expressions to the workflow API to execute arbitrary OS commands. This vulnerability allows attackers to bypass authentication and gain control over systems running affected versions of Orkes Conductor.
CISA has added three Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. These flaws could lead to memory disclosure, denial-of-service, or local privilege escalation, prompting Red Hat to issue high-priority advisories.
Microsoft patched a critical privilege escalation vulnerability (CVE-2026-85889) in Azure AI Foundry, which had a CVSS score of 10.0. This flaw allowed unauthorized attackers to elevate privileges over a network, but Microsoft has already mitigated the issue, requiring no customer action.
Check Point Software released security updates for a critical vulnerability, CVE-2026-91843, which allows attackers to execute code with root privileges on Security Management Server and Log Server instances. This flaw, a stack-based buffer overflow, enables unprivileged threat actors to achieve remote code execution with low complexity and no user interaction, impacting all Security Management Server deployments.
A critical unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor is being actively exploited. The flaw allows attackers to execute arbitrary system commands by submitting malicious JavaScript or Python expressions to the workflow API endpoint, impacting organizations using vulnerable versions of the open-source framework.
Check Point, Kaspersky, and Tanium have released patches for severe vulnerabilities in their products, some of which could lead to remote code execution. These updates address critical security risks across various enterprise security solutions, requiring immediate action from affected customers to prevent potential exploitation.
Check Point has released a fix for a critical vulnerability (CVE-2026-91843) in its Security Management and Log Servers that could allow unauthenticated attackers to execute code as root. The flaw is a stack overflow in the login process, triggered by a long username, and affects multiple Check Point software versions. This vulnerability is significant because it allows remote code execution on critical security infrastructure without authentication, though there is no indication of active exploitation.
Docker has patched a critical vulnerability, CVE-2026-77179, in Docker Sandboxes for macOS that allowed malicious code within a guest VM to read and modify files outside its shared project directory on the host system. This flaw undermines the isolation provided by the sandbox, potentially leading to host compromise if an AI coding agent or other malicious code is exploited.
NLnet Labs disclosed a critical heap overflow vulnerability (CVE-2026-81642) in all Unbound DNS resolver versions before 1.26.1, which could lead to remote code execution via a malicious DNS zone. The flaw, along with eight others, including another RCE-possible bug (CVE-2026-82717), is fixed in Unbound 1.26.1, released on the same day.
Cisco released patches for numerous critical-severity vulnerabilities across its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard products. These updates address issues including remote code execution, SQL injection, and authentication bypass, some of which were publicly disclosed or actively exploited.
Cisco released security updates for a maximum-severity Identity Services Engine (ISE) vulnerability, CVE-2026-76460, which is being actively exploited. This flaw allows remote attackers to bypass authentication on ISE and ISE Passive Identity Connector (ISE-PIC) via an API weakness. Organizations must apply the updates immediately as no workarounds exist, and CISA has ordered federal agencies to patch within three days.
Cisco has issued a warning about a critical zero-day vulnerability (CVE-2026-76460, CVSS 10.0) in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that is currently under active exploitation. This flaw allows unauthenticated remote attackers to bypass authentication and gain unauthorized access, potentially leading to root-level command execution.
A critical vulnerability, CVE-2026-89026, in the Issabel Framework is being actively exploited, allowing unauthenticated attackers to execute arbitrary OS commands. The flaw stems from a hard-coded JSON Web Token (JWT) signing key, which enables attackers to forge valid bearer tokens and control the system. Users are advised to apply the patch released on August 1, 2026, to secure their installations.
Google released security updates for Pixel devices, addressing a high-severity privilege escalation flaw (CVE-2026-58704) in its cellular modem that has seen limited, targeted exploitation. This vulnerability allows remote privilege escalation without user interaction and has been added to CISA's Known Exploited Vulnerabilities catalog, requiring federal agencies to apply fixes.
Acronis has reported that a high-severity local privilege escalation vulnerability (CVE-2026-87886) in its Backup plugin for cPanel and Web Host Manager (WHM) has been actively exploited in limited, targeted attacks. This flaw allows low-privileged attackers to escalate permissions on Linux systems, potentially leading to unauthorized actions or arbitrary code execution, and requires immediate patching by affected users.
A critical security flaw (CVE-2026-5430) in WSO2 API Manager and related products is under active exploitation, allowing unauthorized access and potential account takeover. The vulnerability stems from improper cryptographic signature verification in JWT authentication, enabling attackers to bypass security with forged tokens. This flaw impacts multiple versions of WSO2 products and could lead to compromise of administrative accounts and API backend endpoints.
Threat actors are exploiting three high-severity vulnerabilities (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329) in JFrog Artifactory to bypass authentication, gain administrative privileges, and install backdoors. These flaws allow attackers to deploy persistent admin accounts, execute arbitrary code, and exfiltrate sensitive data from compromised Artifactory instances. Organizations using self-managed Artifactory deployments are advised to update to patched versions immediately.
CISA has added five security flaws affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. These vulnerabilities include issues leading to privilege escalation, unauthorized access, and denial-of-service, posing risks to organizations using these products.
The Dutch National Cyber Security Centrum (NCSC) has issued a warning about the imminent exploitation of two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in Check Point VPN products. These flaws could allow remote code execution, enabling attackers to gain full system control, access sensitive data, or disrupt operations, necessitating immediate patching.
Threat actors are exploiting critical vulnerabilities in JFrog Artifactory, including CVE-2026-42018 and CVE-2026-42016, to bypass authentication, gain administrative privileges, and deploy a Rust-based backdoor on self-hosted servers. This allows attackers to execute arbitrary commands, steal configuration data, and establish persistence, affecting a significant percentage of internet-exposed Artifactory instances.
Check Point released patches for two critical-severity vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its gateway and firewall products. These flaws, with a CVSS score of 9.8, could allow unauthenticated remote code execution via VPN functionality, impacting Security Gateway, Spark Firewall, and Security Management Server.
Attackers exploited two patched JFrog Artifactory vulnerabilities (CVE-2026-42018 and CVE-2026-42016) between August 15 and September 8 to gain administrator control and install backdoors on self-hosted servers. The attack chain allowed unauthenticated users to obtain administrator tokens, leading to the creation of new admin accounts and deployment of malicious plugins or Rust backdoors.
Cisco reported that two recently patched Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have been actively exploited by three distinct threat clusters. These exploits led to credential theft, deployment of web shells, and Qilin ransomware attacks, prompting CISA to add one vulnerability to its Known Exploited Vulnerabilities catalog.
Cisco Talos reported that two recently patched Secure Firewall Management Center (FMC) vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have been actively exploited by three threat clusters, including ransomware affiliates and state-sponsored actors. Attackers used these flaws to deploy web shells, steal credentials, and deploy malware like Qilin ransomware and Cyclops Blink, underscoring the critical need for immediate patching of network security infrastructure.
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that a critical NetScaler vulnerability, CVE-2026-19490, is being actively exploited in attacks. This flaw affects NetScaler ADC and Gateway appliances and was patched by Citrix on August 19, with exploitation observed since at least September 3.
Check Point has released patches for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its firewall and management products related to VPN certificate handling. These flaws, rated 9.8 CVSS, could allow unauthenticated remote code execution under specific conditions, affecting Security Gateways and Security Management Servers. The patches are important for organizations using Check Point products to prevent potential remote code execution by attackers.
CISA has added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by September 12, 2026. These flaws include authentication bypasses and a heap-based buffer overflow, which have been observed in active attacks, including espionage and malware delivery.
Cisco and CISA issued warnings about active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC). Attackers can gain root access to affected devices, with state-sponsored and financially motivated groups already utilizing the flaw to deploy malware and steal credentials.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a critical remote code execution vulnerability (CVE-2025-14733) in WatchGuard Firebox firewalls. This flaw allows unauthenticated attackers to execute malicious code and affects Fireware OS versions 11.x, 12.x, and 2025.1 through 2025.1.3, posing a risk to organizations using unpatched devices.
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2025-25249) in Fortinet products to deploy the PivotC2 RAT. This flaw, patched in January, has led to the infection of 178 devices, primarily targeting US entities and resulting in data exfiltration.
Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software, is being actively exploited. This flaw allows unauthenticated, remote attackers to execute commands as root, posing a significant risk to affected organizations.
Fortinet released patches for 10 vulnerabilities, including two critical flaws in FortiMonitorOnSight and its Privileged Access Agent Chrome extension. These vulnerabilities could allow remote, unauthenticated attackers to bypass authentication or proxy user traffic. The patches address significant security risks across multiple Fortinet products.
Ivanti released security updates for its Neurons for ITSM, Sentry, and Endpoint Manager Mobile (EPMM) products, addressing multiple critical and high-severity vulnerabilities. These patches fix issues including remote code execution and authentication bypass flaws, which could allow unauthorized access or control over affected systems.
cPanel has patched a vulnerability, CVE-2026-67401, in its web hosting control panel software that allowed an authenticated hosting account with mail-related privileges to execute code as the root user on the server. This flaw affects all supported versions of cPanel and WHM, enabling an attacker to gain full administrative access to the server and compromise all hosted accounts.
SAP released security updates addressing a critical vulnerability, CVE-2026-44756, in its Extended Passport (EPP) Processing with a CVSS score of 10.0. This flaw allows unauthenticated remote code execution on SAP hosts, potentially leading to a total compromise of business data and processes. The patch is crucial for preventing unauthorized access and data breaches across various SAP components.
CISA added a critical N-able N-central pre-authentication remote code execution vulnerability (CVE-2026-86218) to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 11, 2026. This flaw, patched in N-central 2026.3 Hotfix 4, has been observed under active exploitation, posing a significant risk to affected organizations.
SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw (CVE-2026-44756, "OVERPASS") in the SAP Kernel and a missing authentication vulnerability (CVE-2026-58240, "S4GET") in NetWeaver Message Server. The OVERPASS flaw allows unprivileged attackers to execute arbitrary commands with administrative privileges, potentially compromising over 10,000 internet-facing SAP systems, while S4GET enables unauthenticated remote code execution across SAP clusters.
SAP released security updates addressing 20 vulnerabilities, including a critical memory corruption flaw (CVE-2026-44756) in its Extended Passport Processing (EPP) with a CVSS score of 10/10. This vulnerability, dubbed OVERPASS, could allow unauthenticated attackers to execute arbitrary system commands and access sensitive data, impacting various SAP products.
N-able has issued an urgent hotfix for a critical unauthenticated remote code execution (RCE) vulnerability, CVE-2026-86218, in its N-central endpoint management platform, which has been actively exploited as a zero-day. This vulnerability allows pre-authenticated access to the N-central server and requires on-premises users to apply the 2026.3 HF4 hotfix immediately to mitigate risk.
N-able released hotfixes for critical N-central vulnerabilities, including a maximum-severity flaw allowing remote code execution, while Google patched a Chrome 0-day vulnerability actively exploited in the wild. These updates address significant security risks in widely used software and platforms. Organizations using N-central and Chrome should apply these patches immediately to prevent potential exploitation.
Security firm TantoSec released a public exploit for a patched vulnerability chain in Telerik UI for ASP.NET AJAX, enabling unauthenticated remote code execution. The exploit targets a specific non-default configuration, and Progress Software issued a fix in July.
N-able issued its fourth hotfix in five weeks for its N-central RMM platform, addressing a critical unauthenticated remote code execution vulnerability (CVE-2026-86218) with a CVSS score of 10.0. This flaw affects all on-premises N-central builds prior to 2026.3.1.14, requiring immediate upgrades for affected customers.
N-able issued an emergency hotfix for a critical remote code execution (RCE) vulnerability, CVE-2026-86218, affecting its N-central remote monitoring and management (RMM) platform. This flaw allows unprivileged attackers to execute malicious code on unpatched systems, and while N-able has not confirmed active exploitation, cybersecurity firm Huntress flagged it as a potential zero-day, urging immediate patching for the nearly 1,500 N-central servers exposed online.
JetBrains' Cadence cloud service was breached last month due to the exploitation of a critical vulnerability (CVE-2026-63077) in TeamCity, leading to the compromise of AWS credentials and user data. Cadence users are advised to revoke and rotate all credentials and treat project data as potentially untrusted. This incident highlights the risks associated with unpatched software in critical infrastructure.
Broadcom released security updates for VMware Workstation and Fusion, addressing two vulnerabilities, including a critical integer-overflow flaw (CVE-2026-59346) that allows local administrative users on a VM to execute code on the host. These patches are important as VMware products are frequently targeted, and similar flaws have seen active exploitation recently.
Threat actors are exploiting newly disclosed PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to steal credentials from K-12 schools and universities in the U.S. and Europe. The attacks involve authentication bypass and remote code execution, leading to reconnaissance, privileged account creation, and deployment of credential-harvesting tools.
A critical remote code execution vulnerability (CVE-2026-66066) in Ruby on Rails ActiveStorage, dubbed KindaRails2Shell, received an emergency patch. The vulnerability, rated 9.5/10 CVSS, was exploited shortly after its disclosure, prompting rapid deployment of hotfixes across client systems, including government agencies.
HPE has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical remote code execution (RCE) flaws. These updates address vulnerabilities that could allow unauthenticated attackers to achieve RCE with elevated privileges, impacting enterprise network security.
A critical authentication bypass vulnerability in Citrix NetScaler (CVE-2026-19490) is now being actively exploited in the wild, according to vulnerability intelligence company Previdian. This flaw allows unprivileged attackers to bypass authentication remotely when NetScaler is configured as an AAA virtual server or Gateway, posing a significant risk to organizations using affected appliances.
A critical-severity SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox, an enterprise VoIP solution, is being actively exploited by threat actors. CISA has added this flaw, along with several others, to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply patches promptly.
Broadcom released patches for two critical vulnerabilities, CVE-2026-59346 and CVE-2026-59347, affecting VMware Workstation and Fusion. These flaws could allow a malicious actor with local administrative privileges on a virtual machine to execute code on the host system. The patches are important because VMware products are frequently targeted by threat actors, and these vulnerabilities have no workarounds.
HPE has released patches for a critical remote code execution vulnerability (CVE-2026-73749) in its ArubaOS-CX network operating system, which could allow unauthenticated attackers to execute code with elevated privileges. This update addresses a buffer overflow issue and 23 other security flaws affecting enterprise-grade network switches.
Cisco has released patches for a critical vulnerability (CVE-2026-20212) in 10 Silicon One-based Nexus 9000 switches that could allow unauthenticated remote attackers to execute code with root privileges. This flaw matters because it affects network infrastructure, potentially leading to full device compromise and disruption if exploited, though Cisco is not aware of active exploitation.
Cisco has issued a warning about two publicly disclosed, unpatched medium-severity vulnerabilities in its Secure Email product and released patches for multiple critical-severity flaws in IOS XR and Nexus 9000 series switches. The Secure Email flaws could allow attackers to intercept and modify encrypted email traffic, while the switch vulnerabilities could lead to remote code execution and other attacks.
CISA has added seven security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation by attackers. These flaws affect products from SonicWall, Sangoma, JFrog, Kludex, Kestra, and Berri LiteLLM, with some being used to deploy reverse shells and crypto miners.
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox VoIP platforms, to deploy reverse shells and execute remote code. This flaw allows attackers to gain control over business phone systems, impacting approximately 4,000 internet-exposed devices, primarily in the United States.
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being actively exploited to create administrative access tokens. This flaw allows unauthenticated attackers to gain full control over Artifactory instances, potentially compromising software supply chains by replacing trusted artifacts with malicious code.
Rockwell Automation released patches and workarounds for more than a dozen vulnerabilities across its industrial automation products. These include critical and high-severity denial-of-service issues in RSLinx Classic, remote code execution in FactoryTalk Historian, and privilege escalation flaws, impacting operational technology security.
A new authentication bypass vulnerability, CVE-2026-84115, has been discovered in the Cleo Harmony file transfer application, with an exploit now publicly available. This flaw allows remote attackers to elevate privileges by manipulating JWT refresh token logic, posing a significant risk to organizations using the software.
SonicWall has released security updates for two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting its Secure Mobile Access (SMA) 1000 series VPN appliances that are being actively exploited. These flaws, if chained together, could allow remote attackers to execute arbitrary code on affected devices.
GeoNetwork, an open-source geospatial metadata catalog used by government geoportals, patched two vulnerabilities (CVE-2026-63219 and CVE-2026-58400) that could be chained for unauthenticated remote code execution. The fix was released on July 8, 2026, addressing a critical security flaw affecting numerous internet-exposed deployments, many of which are government-related.
Threat actors are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3, to achieve remote code execution. This flaw allows attackers to deploy reverse shells and execute arbitrary commands, impacting approximately 4,000 internet-exposed instances, primarily in the U.S.
SonicWall issued a warning about two new zero-day vulnerabilities in its SMA1000 appliances that are being actively exploited in remote code execution attacks. These flaws, a maximum-severity command injection (CVE-2026-83548) and another command injection (CVE-2026-83549), allow attackers to execute arbitrary OS commands on vulnerable devices. The exploitation of these vulnerabilities poses a significant risk to large enterprises, government, and critical infrastructure organizations that use SMA1000 for secure remote access.
SonicWall has issued an urgent advisory for customers using its SMA1000 series secure remote access gateways to patch two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which are actively being exploited. These flaws could allow remote attackers to access sensitive functionality or execute arbitrary OS commands, posing a significant risk to affected organizations.
Threat actors are exploiting CVE-2026-0768, an unauthenticated remote code execution vulnerability in Langflow versions 1.4.2 and earlier, to steal OpenAI API keys and AWS credentials. This critical flaw allows attackers to execute arbitrary code with root privileges by manipulating the code validator in Langflow's custom component editor, impacting users of the open-source AI application framework.
Threat actors are actively exploiting CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory, to gain administrative privileges. This flaw allows unauthenticated attackers to mint admin tokens and could lead to software supply chain compromise, affecting organizations using self-managed Artifactory instances.
Threat actors are actively exploiting CVE-2026-0768, a critical remote code execution vulnerability in the AI low-code platform Langflow, affecting all versions up to 1.4.2. This exploitation allows attackers to execute arbitrary code as root without authentication, posing a significant risk to users of the platform.
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is reportedly being exploited in the wild, allowing unauthenticated attackers to gain administrative privileges. JFrog released patches on August 28, and self-hosted users are advised to update immediately to prevent potential compromise of their software artifact management systems.
The Linux kernel is nearing 2,000 CVEs per release, a significant increase from 500, primarily because AI and large language models are extensively scanning its 40 million lines of code for vulnerabilities. This surge in findings, many of which are low-priority or questionable, is overwhelming human maintainers and leading to the removal of old, rarely used driver code.
WatchGuard released patches for over two dozen vulnerabilities, including five critical flaws that could lead to remote code execution (RCE) and account takeover in its Fireware OS and Dimension products. These updates address significant security risks for users of WatchGuard network security devices and management software.
Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails, for credential harvesting and remote code execution. VulnCheck observed over 360 exploitation attempts since August 30, 2026, with traffic primarily from Russia targeting systems in the U.K.
ServiceNow has released patches for four vulnerabilities, including three critical code injection flaws (CVSS 10/10) in its AI platform and one high-severity sandbox escape vulnerability. These flaws could allow unauthenticated attackers to execute arbitrary code, modify data, elevate privileges, or execute SQL statements, impacting both hosted and self-hosted instances of the platform.
JetBrains' Cadence cloud development service was compromised after attackers exploited a critical TeamCity vulnerability (CVE-2026-63077) on an unpatched server belonging to JetBrains itself. This incident led to the potential exposure of credentials, configuration files, and source code, impacting users of the Cadence service and JetBrains employees.
A critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. Cosmos Labs was aware of the vulnerability since April 25 and had confirmed its impact on all Cosmos EVM chains by August 13, but did not follow its own emergency disclosure policy.
CISA added a critical ownCloud vulnerability (CVE-2023-49105) to its Known Exploited Vulnerabilities catalog after reports of a Chinese-speaking threat actor using it to target a Philippine nuclear research body. This flaw allows unauthenticated file access via WebDAV API if a username is known and the default configuration (no signing-key) is used, enabling data theft from affected ownCloud instances.
ServiceNow has released patches for four security vulnerabilities in its AI Platform, including three with a CVSS score of 10.0 that could allow unauthenticated attackers to execute arbitrary code or SQL. These critical flaws affect hosted and self-hosted instances, requiring immediate action for organizations managing their own deployments. The patches address severe risks of data access, modification, and privilege escalation.
VulnCheck discovered two previously undocumented factory implants, SPEAKINGSTONE and DARKLANTERN, in firmware for routers manufactured by Shenzhen Zhibotong Electronics (ZBT). These implants allow unauthenticated remote attackers to execute commands as root on affected devices, posing a significant security risk due to their ability to bypass network defenses and exfiltrate sensitive data.
ServiceNow has released security patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. These flaws could be exploited by unauthenticated attackers with low complexity, impacting the platform used by many Fortune 500 companies.
cPanel released patches for a critical security flaw, CVE-2026-65643, in cPanel and WebHost Manager (WHM) that could allow an authenticated user to achieve root code execution. This vulnerability impacts all supported versions and could give an attacker full control of a server.
Vercel released security patches for two critical remote code execution (RCE) vulnerabilities in the Next.js web framework. These flaws, one involving AVIF image processing and another a Windows path traversal, could allow unauthenticated attackers to execute code remotely, necessitating immediate upgrades for affected deployments.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical remote code execution (RCE) vulnerability (CVE-2026-8452) in Citrix NetScaler appliances by Saturday. This directive follows reports of active exploitation of the flaw, which was initially downplayed by Citrix as a denial-of-service vulnerability but later shown to allow RCE.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity flaw in Citrix NetScaler ADC and NetScaler Gateway. This addition signifies that these vulnerabilities are actively being exploited in the wild, requiring immediate attention from organizations to mitigate potential risks.
CISA has issued an urgent directive for government organizations to patch a Citrix NetScaler vulnerability (CVE-2026-8452) that is actively being exploited. This vulnerability, initially described as a high-severity memory overflow, has been demonstrated to allow unauthenticated remote code execution, posing a significant risk to affected systems.
A critical vulnerability chain (CVE-2026-18431) in the Avada WordPress theme and Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code. The flaw, rated 9.8 critical, affects versions up to Avada 7.16 and Fusion Builder 3.16, enabling full website compromise. ThemeFusion has released fixes in Avada 7.16.1 and Fusion Builder 3.16.1.
Ubiquiti released security patches for three maximum-severity vulnerabilities that could allow unauthenticated remote exploitation in UniFi Protect, UniFi Talk, and UniFi OS. These flaws include an authentication bypass and command injection, posing a risk to devices exposed online, which have historically been targeted by threat actors.
CERT/CC disclosed two unpatched vulnerabilities, CVE-2026-19913 and CVE-2026-19912, in Kaltura's HTML5 video player library (mwEmbed/html5lib). These flaws allow unauthenticated remote attackers to read arbitrary files and execute code on affected servers due to unsafe deserialization in the mwEmbedLoader.php endpoint. The vulnerabilities affect both individual customer installations and Kaltura's shared CDN infrastructure, posing a risk to multiple tenants.
Marimo has patched a high-severity security vulnerability (CVE-2026-75149) in its notebook software that permitted arbitrary Model Context Protocol (MCP) commands to execute as a local subprocess when a specially crafted notebook was opened in edit mode. This flaw allowed code injection before any notebook cells ran, affecting versions prior to 0.23.15, and required no attacker authentication.
Threat actors have compromised over 270 Zimbra Collaboration Suite (ZCS) instances by exploiting a high-severity remote code execution vulnerability, CVE-2026-73570. This ongoing exploitation impacts organizations globally, including businesses and government agencies that rely on Zimbra for email and collaboration.
CISA has instructed government organizations to immediately patch a critical remote code execution vulnerability (CVE-2026-21962) in Oracle WebLogic servers, which has been actively exploited since January 2026. This flaw, affecting Oracle HTTP Server and the WebLogic Server Proxy plugin, allows unauthenticated exploitation and requires urgent attention to prevent server compromise.
CISA has added a critical Oracle HTTP Server and Oracle WebLogic Server vulnerability (CVE-2026-21962) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows unauthenticated attackers to gain unauthorized access or modify critical data, posing a significant risk to affected systems.
A vulnerability (CVE-2026-75501) in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create port-forwarding rules, bypassing NAT and exposing local network devices. This flaw affects devices running EXOS/6.6.47 firmware and impacts users of multiple U.S. broadband providers that deploy these routers.
Broadcom's Spring application development framework released updates patching 91 vulnerabilities, including one critical and over a dozen high-severity issues. These patches are significant for developers using Spring, as the vulnerabilities affect various projects and could lead to exploits like remote code execution and information disclosure.
Red Hat and the Keycloak project released patches for a critical security flaw (CVE-2026-18963) in the Keycloak identity and access management server. This vulnerability allows an unauthenticated remote attacker to reset any user's password and take over their account, including administrative accounts, due to improper state validation in the password recovery mechanism.
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. This flaw allows unauthenticated attackers to achieve remote code execution, posing a significant risk to organizations using the popular email and collaboration platform.
Cisco released security updates for its Crosswork and Secure Workload platforms, addressing nine vulnerabilities, five of which have a CVSS score of 10.0. These patches resolve issues including SQL injection, missing authentication, and improper access control, found during an internal security review. The updates are important for users to apply to prevent potential exploitation of these critical flaws.
A recently patched high-severity vulnerability in Zimbra Collaboration, tracked as CVE-2026-73570, is being actively exploited in the wild, according to CERT Polska. This flaw allows unauthenticated attackers to execute arbitrary OS commands on affected servers, potentially leading to full system control and data theft.
A critical security flaw (GHSA-864f-rcv7-6rh4) has been discovered in isolated-vm, a popular Node.js sandbox library, allowing untrusted JavaScript to escape its sandboxed environment and potentially corrupt host memory or achieve remote code execution. This vulnerability undermines the core security purpose of isolated-vm, which is used to run untrusted JavaScript code safely.
Citrix released updates for NetScaler ADC and NetScaler Gateway to fix two security flaws, including a critical authentication bypass vulnerability (CVE-2026-19490) with a CVSS score of 9.3. This bypass affects appliances configured as a Gateway or an AAA virtual server, potentially allowing unauthorized access. Organizations using affected customer-managed NetScaler deployments need to apply these updates to prevent potential security breaches.
A security vulnerability in Zimbra Collaboration (ZCS) affecting the optional zimbra-snmp package, CVE-2026-73570, is now being actively exploited. This flaw allows unauthenticated remote code execution due to improper input sanitization during SNMP notification processing, impacting organizations using affected Zimbra versions.
Atlassian and Splunk released patches for over 250 vulnerabilities across their products, including numerous critical and high-severity flaws. These updates address potential remote code execution, denial-of-service, and information theft risks, impacting a wide range of their enterprise software.
Citrix has issued an urgent warning for administrators to patch two new vulnerabilities in NetScaler Gateway and NetScaler ADC products. These flaws, including an authentication bypass (CVE-2026-19490) and a denial-of-service vulnerability (CVE-2026-19489), could allow remote attackers to compromise systems, making immediate updates critical for affected organizations.
A critical unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-64849, in the MLflow AI engineering platform is being actively exploited to steal cloud credentials and secrets. The US cybersecurity agency CISA has added this flaw to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch affected systems within two weeks.
Cisco released patches for 15 vulnerabilities across its products, addressing critical-severity flaws in Crosswork and Secure Workload, and a high-severity defect in BroadWorks. These updates prevent potential remote code execution, authentication bypass, and sensitive information disclosure, which is important for organizations using these Cisco products to maintain security.
CISA has added a critical MLflow vulnerability, CVE-2026-64849, to its catalog of actively exploited flaws, mandating U.S. federal agencies to patch affected systems within two weeks. This DNS-rebinding server-side request forgery (SSRF) bypass allows unauthenticated attackers to remotely access internal services or cloud metadata configurations, potentially leading to the theft of cloud credentials.
A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS) is now being actively exploited by attackers. This flaw allows unauthenticated attackers to execute arbitrary operating system commands, posing a significant risk to organizations using ZCS.
Citrix released patches for a critical authentication bypass vulnerability (CVE-2026-19490) in NetScaler ADC and NetScaler Gateway, which allows remote, unauthenticated attackers to bypass authentication. This vulnerability is expected to be exploited soon due to the widespread deployment of NetScaler products in enterprise networks, making immediate patching crucial for affected organizations.
Attackers are actively exploiting a critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-64849) in MLflow, an open-source AI platform, to steal cloud credentials and secrets. Malicious scanning and exploitation efforts are also targeting a separate vulnerability (CVE-2026-25895) in FUXA, an open-source SCADA/HMI software. This activity highlights the immediate risk to organizations using these platforms, particularly those with exposed instances.
CISA has added a critical remote code execution (RCE) vulnerability in the open-source Ray distributed computing framework to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The flaw, CVE-2025-62593, allows RCE via browser-based DNS rebinding attacks, primarily affecting developers in testing environments.
A newly patched VMware vCenter vulnerability (CVE-2026-59310) is being actively exploited by a suspected China-nexus APT group, leading to backdoor deployment and Babuk-derived ransomware. Additionally, a critical macOS Screen Sharing flaw (CVE-2026-65400) has been exploited in the wild to install a cryptocurrency miner. These incidents highlight the ongoing exploitation of recently disclosed vulnerabilities for various malicious purposes.
Threat actors are exploiting a recently patched macOS Screen Sharing vulnerability, CVE-2026-65400, to gain root access and deploy Monero cryptominers on vulnerable systems. This high-severity authentication bypass allows remote attackers to log in without valid credentials, impacting macOS systems with Screen Sharing enabled and accessible from the internet.
A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, was exploited by attackers just three days after its public disclosure. This vulnerability, with a CVSS score of 10, allows for arbitrary code execution and compromise of internal components, posing a significant risk to affected organizations.
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310, a severe directory-traversal vulnerability, and have compromised 361 unique victim IP addresses across 47 countries.
Attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing, to gain root access and install Monero cryptocurrency miners on compromised Macs with port 5900 exposed. CISA has increased the vulnerability's CVSS score from 7.1 to 9.8, classifying it as critical and automatable, following reports of active exploitation and the availability of public proof-of-concept code. This flaw allows attackers to authenticate without valid credentials, posing a significant risk to unpatched macOS systems.
A maximum-severity vulnerability in SAP Commerce Cloud, CVE-2026-58231, is being actively exploited just three days after a patch was released. This flaw allows unauthenticated attackers to achieve arbitrary code execution and compromise internal components, posing a high risk to confidentiality, integrity, and availability.
A critical authentication vulnerability (CVE-2026-65400) in Apple macOS Screen Sharing is being actively exploited to install Monero cryptocurrency miners on systems with port 5900 exposed to the internet. This flaw allows unauthorized network attackers to bypass credential validation and gain root access, highlighting the importance of applying recent macOS security updates.
Dutch officials have warned that a high-severity macOS vulnerability, CVE-2026-65400, is being actively exploited to gain root access and install crypto miners on affected systems. The flaw, residing in the macOS screen sharing capability, allows attackers to execute malicious code without credentials. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.
The Netherlands' National Cyber Security Centre (NCSC) reports that a macOS Screen Sharing authentication bypass vulnerability (CVE-2026-65400) is being actively exploited to install Monero cryptocurrency miners. The flaw allows attackers to gain root access without valid credentials when port 5900 is exposed to the internet. This exploitation highlights the importance of applying security updates and disabling unneeded remote access features.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, is actively being exploited in attacks just three days after a patch was released. This flaw allows unauthenticated attackers to execute arbitrary code, posing a significant risk to confidentiality, integrity, and availability for organizations using the e-commerce platform.
Threat actors are exploiting an unpatched zero-day SQL injection vulnerability in GeoServer, an open-source geospatial data platform, shortly after its public disclosure. This vulnerability, which can lead to remote code execution under certain configurations, affects GeoServer's jsonArrayContains function and impacts organizations using GeoServer across various industries.
A zero-day SQL injection vulnerability in GeoServer, disclosed on August 12, 2026, was actively exploited, leading to potential remote code execution. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to address this critical flaw, assigned GHSA-mqjf-5f49-2fjh with a CVSS score of 9.8.
A critical remote code execution vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited to install a reverse SSH tool for persistent remote access. This flaw allows unauthenticated attackers to execute arbitrary code, affecting 361 IP addresses across 47 countries within days of the patch release, posing a significant risk to organizations using vulnerable vCenter versions.
A critical-severity vulnerability in Adobe Commerce (CVE-2026-71362) was targeted by attackers immediately after its public disclosure, despite Adobe stating no evidence of in-the-wild exploitation. The flaw allows unauthenticated attackers to elevate privileges and access customer accounts, prompting Adobe to release an isolated patch for affected versions.
WordPress released version 7.0.4 to patch a high-severity remote code execution vulnerability (CVE-2026-65640) affecting installations using Imagick and Ghostscript. The flaw allowed authenticated attackers with Author-level permissions or higher to execute arbitrary code by uploading malicious Postscript files disguised as images. This update is important for WordPress users, especially those with multi-author sites, as it prevents a realistic threat of code execution through file uploads.
Threat actors are actively exploiting a critical-severity directory traversal vulnerability (CVE-2026-59310) in VMware vCenter's Syslog server, leading to remote code execution. This exploitation, identified by Quirso, began shortly after the vulnerability was disclosed and patched by Broadcom, affecting over 360 IP addresses across 47 countries.
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento e-commerce platforms is being actively exploited to hijack customer accounts. This flaw allows attackers to gain elevated access without authentication, enabling them to access victim accounts and private customer data.
North Korean hackers, identified as the Lazarus Group, exploited a Windows zero-day vulnerability (CVE-2026-68820) in their "Operation Dream Job" campaign to target defense-sector companies. Microsoft patched the flaw in its latest Patch Tuesday updates, confirming active exploitation since early July, allowing attackers to gain SYSTEM privileges.
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a Microsoft Windows vulnerability (CVE-2026-68820) by August 25, as it is actively being exploited by North Korean hackers in the "Operation Dream Job" campaign. This vulnerability allows attackers to gain remote access after an initial phishing compromise, impacting Winsock, a critical component for internet connectivity.
Adobe has issued updates to address multiple critical security flaws in ColdFusion, Commerce, and Campaign Classic, including several with CVSS scores of 10.0. These vulnerabilities could lead to arbitrary code execution or privilege escalation, and administrators are advised to apply the patches promptly.
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, to gain persistent remote access. This exploitation, observed shortly after public disclosure, affects hundreds of IP addresses across multiple countries and allows for arbitrary code execution and the establishment of reverse SSH connections.
Ivanti released patches for four vulnerabilities across its Endpoint Manager (EPM) and Neurons for MDM products. These updates address high-severity flaws in EPM, including two that remote, unauthenticated attackers could exploit, and a medium-severity command injection vulnerability in Neurons for MDM.
SAP has released patches for a maximum-severity security flaw in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability, along with three other critical flaws in Manufacturing Integration and Intelligence and Application Server ABAP, requires immediate patching to prevent potential system compromise and data loss.
SonicWall released patches for eight vulnerabilities across its Global Management System (GMS) and Email Security products, including critical remote code execution (RCE) flaws. These updates are important for users to apply to prevent potential exploitation, despite GMS being a discontinued product.
A security researcher released a proof-of-concept (PoC) for "ShieldBreak," a new zero-day vulnerability in Microsoft Defender for Windows. This PoC claims to bypass the patch for CVE-2026-50656 (RoguePlanet), which could allow SYSTEM-level privilege escalation. The vulnerability affects Windows 11 25H2, Windows Server 2025, and Windows 10, indicating that Microsoft's previous fix for RoguePlanet was incomplete.
Cisco has issued a warning about a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD Software that is being actively exploited in the wild. This flaw allows an unauthenticated, remote attacker to trigger a denial-of-service condition by sending a crafted HTTP request to the Remote Access SSL VPN service.
Cisco released patches for a zero-day vulnerability (CVE-2026-20349) affecting Secure Firewall ASA and FTD software, which was actively exploited to cause denial-of-service conditions. The vulnerability allows unauthenticated attackers to reload appliances by sending crafted HTTP requests to the Remote Access SSL VPN service. This matters because exploited security appliance flaws can disrupt network defenses and are being tracked by CISA.
Cisco issued a warning about a high-severity denial-of-service vulnerability, CVE-2026-20349, in its Secure Firewall ASA and Threat Defense (FTD) software that is being actively exploited to remotely crash devices. This flaw, caused by insufficient error checking in HTTP request processing, impacts devices with certain remote access services enabled and requires immediate patching to prevent service disruption.
Adobe released patches for over 50 vulnerabilities across its products, including critical flaws in ColdFusion, Campaign Classic, and Commerce that could lead to arbitrary code execution. These updates are rated with high priority due to the severity of the vulnerabilities, urging immediate application to prevent potential exploitation.
Zoom has released patches for four vulnerabilities, including a severe zero-click remote code execution (RCE) flaw (CVE-2026-53413) affecting its clients on all supported platforms. This RCE vulnerability allowed an attacker to execute code on a meeting participant's machine without interaction, posing a significant security risk to users.
SAP released 28 new security notes and two updates in its August 2026 Security Patch Day, including four critical vulnerabilities. These patches address issues like improper authorization, code injection, and memory corruption in various SAP products, which could lead to unauthorized access, system compromise, or data disclosure.
Cisco has issued a warning regarding two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser, which could lead to denial-of-service attacks. These flaws affect ClamAV versions 1.5.0 through 1.5.3 and have publicly available proof-of-concept exploit code, making immediate patching crucial for affected systems, especially Windows platforms.
CISA has confirmed that ransomware gangs are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a critical server-side request forgery (SSRF) flaw. These vulnerabilities affect secure remote access gateways used by large organizations, increasing the risk of network compromise for affected entities.
Cisco issued a warning regarding seven ClamAV vulnerabilities affecting its Secure Endpoint Connector products, with two having publicly available proof-of-concept (PoC) code. These flaws could lead to denial-of-service conditions, posing a high risk to Windows users due to privileged scanning processes.
Metabase released urgent patches for a critical SQL injection vulnerability actively exploited as a zero-day, allowing remote, unauthenticated attackers to gain administrative access and steal data. This vulnerability impacts self-hosted Metabase users who need to apply updates immediately to prevent potential compromise.
CISA has directed federal agencies to immediately patch a critical OS command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster, which is actively being exploited. This flaw allows unauthenticated remote code execution and could provide initial access to critical internal services if exploited.
Metabase reported that a maximum-severity zero-day vulnerability in its business intelligence software is being actively exploited, allowing unauthenticated remote attackers to gain administrator access. The flaw, with a CVSS score of 10.0, enables SQL injection to compromise Metabase instances. This impacts users running self-hosted versions, who must apply security patches immediately to prevent unauthorized access and data theft.
N-able issued Hotfix 2 for its N-central RMM product to counter ongoing exploitation of CVE-2026-18577, a vulnerability allowing authentication bypass and account takeover. Threat actors are using this flaw to gain administrative access, leverage the Take Control feature, and establish persistence on managed systems. This hotfix is critical for customers as it includes additional hardening measures beyond the initial fix and addresses active attacks.
CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows unauthenticated attackers to execute arbitrary code on affected devices, prompting a directive for federal agencies to patch by August 10, 2026.
A critical SQL injection zero-day vulnerability in Metabase, affecting versions 1.58 and above, was actively exploited to breach customer instances and steal data. Metabase has released patches for both its Cloud SaaS platform and self-hosted installations, urging users to update immediately to prevent unauthorized administrator access and data exfiltration.
WordPress has released a patch for a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen, tracked as CVE-2026-64638, which affects all versions of the content management system. This high-severity vulnerability can be chained into PHP code execution on the server if a logged-in administrator interacts with an attacker-controlled page, making immediate updates critical for site security.
Novee Security discovered and presented vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged GitHub users to execute code on CI runners or exfiltrate API keys. Two CVEs were issued and subsequently patched, highlighting a recurring security failure in the code that orchestrates AI model interactions.
Cisco released updates addressing 12 security vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three with CVSS scores of 9.9 and one with 9.8. These patches resolve issues like improper input validation, access control, and command injection, which could allow attackers to compromise affected systems.
A new KVM escape vulnerability, dubbed Zapscape (CVE-2026-64561), has been disclosed, allowing a guest virtual machine to escape to the host and execute commands with root privileges in KVM/x86 environments. This use-after-free flaw in the shadow MMU emulation poses a significant threat to guest-host isolation, particularly for multi-tenant public clouds that expose nested virtualization.
Cisco released patches for two dozen vulnerabilities across its product line, including critical flaws in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The most severe vulnerability is an authentication bypass in FMC (CVE-2026-20079) with a CVSS score of 10, allowing remote attackers to gain root privileges. These patches are important for maintaining the security and integrity of network infrastructure for organizations using Cisco products.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical remote code execution vulnerability (CVE-2026-63077) in on-premise versions of JetBrains TeamCity as actively exploited in the wild. This deserialization flaw allows unauthenticated attackers to bypass authentication and execute arbitrary commands, posing a significant risk to CI/CD pipelines and sensitive data.
The US cybersecurity agency CISA has issued a warning that threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-63077) in JetBrains TeamCity, a continuous integration/continuous delivery (CI/CD) platform. This deserialization flaw allows unauthenticated attackers to achieve remote code execution, bypassing authentication checks and executing arbitrary operating system commands on affected TeamCity On-Premises versions. The active exploitation means organizations using TeamCity On-Premises need to apply patches immediately to prevent potential compromise of their software development and deployment infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. These flaws allow for remote code execution and administrative account hijacking, posing significant risks to affected systems.
CISA has issued a warning about three vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat that are actively being exploited by threat actors. These vulnerabilities include remote code execution, authentication bypass, and an EncryptInterceptor bypass, posing risks to affected systems.
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These include a code injection flaw in Langflow, a data encryption bypass in Apache Tomcat, and an authentication bypass in N-able N-central, with one Tomcat exploit linked to an AI-enabled hacking campaign.
Security researchers at Forescout have identified 15 new vulnerabilities in TP-Link's Omada zero-touch provisioning (ZTP) systems, with some flaws allowing for full network takeover when chained together. These vulnerabilities could enable attackers to gain administrative control over cloud controllers and internal networks, impacting organizations using Omada devices for automated network configuration.
CISA has added a high-severity N-able N-central vulnerability (CVE-2026-18577) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw, an incomplete patch of a previous vulnerability, allows authentication bypass and account takeover, enabling attackers to gain administrative access and pivot into managed endpoints.
N-able issued a warning about active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting its N-central RMM servers. The company released hotfix 2026.3.1.7 to address the flaw, which allows administrative account takeover and impacts all N-central versions before 2026.3. This is significant because N-central is a widely used RMM platform, and compromise could extend attacks beyond N-able's direct customers.
The INC Ransomware group has become the primary threat actor exploiting recently disclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These flaws, CVE-2026-15409 and CVE-2026-15410, allow for arbitrary command execution and device takeover, impacting organizations globally. The exploitation enables long-term persistent access and lateral movement within corporate networks, leading to ransomware deployment.
N-able has released patches for CVE-2026-18577, an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) product that has been actively exploited. This vulnerability allows attackers to gain administrative access to N-central servers, potentially compromising customer systems managed by MSPs. The exploitation of this flaw could lead to widespread access to client networks, enabling further malicious activities.
The INC Ransomware group is actively exploiting two recently patched SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to compromise organizations and deploy ransomware. These vulnerabilities allow unauthenticated remote attackers to gain root privileges and have been added to CISA's Known Exploited Vulnerabilities catalog, indicating their active use in attacks.
Attackers exploited an authentication bypass vulnerability in N-able N-central, gaining remote administrative access to servers and subsequently customer systems. An initial fix for the vulnerability proved incomplete, allowing attackers to maintain access through Cloudflare tunnels even after N-central servers were updated.
Adobe released security updates for Campaign Classic (ACC) to fix a critical vulnerability (CVE-2026-48449) with a CVSS score of 10.0, allowing arbitrary code execution without user interaction. The company also addressed eight critical flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution. These updates are important for users of Adobe's marketing automation platform and creative software to prevent potential security breaches.
JetBrains released patches for a critical-severity vulnerability (CVE-2026-63077) in TeamCity On-Premises that allowed unauthenticated remote code execution. This flaw could enable attackers to bypass authentication, execute arbitrary commands, and potentially compromise CI/CD pipelines, making immediate patching crucial for affected organizations.
JetBrains has issued a warning about a critical authentication bypass vulnerability, CVE-2026-63077, in TeamCity On-Premises that could lead to remote code execution. This flaw allows attackers with HTTPS access to bypass authentication and execute arbitrary commands, potentially compromising CI/CD pipelines and sensitive data. Administrators are advised to update to patched versions or apply a security plugin immediately.
Broadcom released security updates for five vulnerabilities in VMware products, including three critical flaws that could lead to authentication bypass, arbitrary code execution, or virtual machine escapes. These vulnerabilities affect widely used VMware virtualization platforms and require immediate patching to prevent unauthorized access and system compromise.
South Korean authorities and security firms disclosed a state-sponsored campaign that exploited vulnerabilities in AnySign4PC financial-security software through compromised domestic websites. This allowed attackers to install SIGNBT or COPPERHEDGE backdoors on targeted visitors' systems without user interaction. The campaign highlights the risk of supply chain attacks targeting widely used software in specific regions.
Cisco has disclosed a critical vulnerability in its Firepower Management Center (FMC) that involves static credentials, which has been actively exploited as a zero-day. This vulnerability allows an unauthenticated attacker to gain root access to affected devices, posing a significant risk to network security.
Cisco released patches for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting its Secure Firewall Management Center (FMC) product. This vulnerability, rated high severity, involves static credentials for a low-privilege user, allowing attackers to access sensitive data and potentially escalate privileges when chained with other flaws. The exploitation of this vulnerability highlights the ongoing need for organizations to promptly apply security updates and monitor for indicators of compromise in critical network infrastructure.
CISA added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The flaw, CVE-2026-20316, allows unauthenticated remote attackers to access sensitive data using static low-privilege credentials. This vulnerability is critical as it can be chained with other flaws to escalate privileges, posing a significant risk to affected systems.
Cisco has issued a warning regarding a high-severity static credential vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC) software, which is being actively exploited in zero-day attacks. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems, potentially leading to privilege escalation when combined with other vulnerabilities. Cisco has released hot fixes for multiple FMC releases and advises immediate installation.
A critical security flaw (CVE-2026-59726) in Ruflo, an AI multi-agent orchestration platform, allows unauthenticated attackers to execute remote commands and poison AI memory. The vulnerability impacts all versions before 3.16.3 and exposes 233 tools, including shell command execution, through an unauthenticated Model Context Protocol (MCP) bridge.
Broadcom released security updates addressing multiple vulnerabilities in VMware products, including three critical flaws. These critical vulnerabilities could allow authentication bypass, arbitrary code execution, and code execution on the host system.
Nebula Security reported a patched Firefox JIT vulnerability, CVE-2026-10702, which allowed arbitrary code execution by visiting a malicious webpage and affected Tor Browser versions incorporating vulnerable Firefox releases. This flaw highlights a critical browser security risk, as it required no user interaction beyond page visitation and could be a first stage in more complex exploit chains.
Broadcom released patches for multiple vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three critical flaws. These vulnerabilities include a VM escape in ESXi, an authentication bypass in vCenter, and a remote code execution flaw in vCenter, necessitating immediate updates for affected systems.
Cybersecurity researchers have released technical details and a public proof-of-concept (PoC) for a critical authentication bypass vulnerability (CVE-2026-16232) in Check Point Security Management Server and Multi-Domain Security Management Server. This flaw allows unauthenticated remote attackers to gain full administrative privileges, and Check Point has confirmed active exploitation as a zero-day against a limited number of customers.
vBulletin released patches for a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-61511, affecting versions 5.x and 6.x up to 5.7.5 and 6.2.1. The flaw allows unauthenticated attackers to execute arbitrary PHP code through template rendering, and a public proof-of-concept exploit is available, increasing the risk for unpatched servers.
JetBrains has released updates and a security patch for a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary operating system commands. This flaw could lead to exposure of TeamCity data, configurations, and credentials, making immediate patching crucial for affected organizations.
Arista Networks released patches for a critical OS injection vulnerability (CVE-2026-16812) in its VeloCloud Orchestrator (VCO) platform, which is being actively exploited as a zero-day. This flaw allows remote attackers to access privileged functionality without authentication, impacting the confidentiality, integrity, and availability of the orchestrator and its managed data.
A critical command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. This flaw allows remote attackers to execute arbitrary code, potentially compromising the orchestrator and managed data.
Arista has released patches for a maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises VeloCloud Orchestrator deployments that is being actively exploited. This flaw allows unauthenticated remote attackers to compromise the orchestrator and its managed data, affecting specific VCO versions.
Details and a proof-of-concept for a pre-authentication remote code execution vulnerability in vBulletin (CVE-2026-61511) were publicly released on July 27. This flaw affects versions 6.2.1 and earlier, and 6.1.6 and earlier, allowing unauthenticated attackers to execute code on unpatched vBulletin forum servers. The public release of exploit details increases the urgency for administrators to apply patches, as the vulnerability requires no user interaction or authentication.
n8n has patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) that allowed authenticated workflow editors to execute operating system commands on the server running the automation platform. This flaw could expose sensitive data like encryption keys and provide access to connected databases, making immediate updates critical for affected n8n users.
Check Point disclosed a critical zero-day vulnerability, CVE-2026-16232, in its Security Management and Multi-Domain Management products, which has been actively exploited. This authentication bypass allows attackers full administrator privileges, leading CISA to add it to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch it by July 25.
Check Point Software has addressed an actively exploited zero-day vulnerability (CVE-2026-16232) in its SmartConsole graphical user interface admin panel. This authentication bypass allows unauthenticated attackers to gain administrator privileges and modify security configurations. The Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of known exploited vulnerabilities, mandating U.S. federal agencies to patch by July 25.
CISA has mandated U.S. government agencies to urgently patch a critical RCE vulnerability, CVE-2026-0770, in the Langflow framework, which is currently being exploited by threat actors. This flaw can allow unauthenticated attackers to execute code with root privileges, posing significant risks to federal operations.
SonicWall disclosed two critical vulnerabilities in SMA1000 appliances that were exploited as zero-days by attackers, leading to custom malware installation. The flaws allow unauthorized access to internal applications and management services, impacting security for users of affected VPN devices.
SonicWall's CVE-2026-15409 and CVE-2026-15410 vulnerabilities were actively exploited for weeks before patches were issued. The breaches allowed attackers using custom malware to access sensitive information on SMA1000 appliances.
A previously unknown threat actor exploited SonicWall Secure Mobile Access (SMA) 1000 series VPN vulnerabilities before their public disclosure. The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, allow for arbitrary command execution, leading to potential root takeover of affected devices.
CISA has directed U.S. government agencies to prioritize patching two critical vulnerabilities in Fortinet's FortiSandbox. Exploitation allows unauthenticated attackers to remotely execute code, necessitating immediate upgrades to mitigate risks.
CISA has added CVE-2026-25089, an unauthenticated OS command injection vulnerability in FortiSandbox, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability allows attackers to inject commands through the web interface without authentication, elevating the risk for affected users as this is the third FortiSandbox exploit detected this year.
F5 released patches for eight vulnerabilities affecting NGINX Plus, NGINX Open Source, and BIG-IP, including a critical flaw with a CVSS score of 9.2. These updates are significant as they address potential exploits leading to denial-of-service (DoS) conditions and unauthorized memory access.
Two vulnerabilities in SonicWall's SMA 1000 series are actively exploited, one allowing arbitrary command execution. SonicWall urges immediate patching to mitigate risks associated with these serious security flaws.
SonicWall has issued an urgent patch for its SMA1000 appliances following the discovery of two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. These vulnerabilities pose serious threats, including server-side request forgery and code injection risks, affecting enterprise security significantly.
SonicWall has disclosed two critical vulnerabilities in SMA1000 products being actively exploited in zero-day attacks. Patching is essential as both issues could allow unauthorized access and control over affected appliances.
SAP has released security updates to address critical vulnerabilities in its NetWeaver and Commerce Cloud products, including a CVSS 9.9 flaw in the NetWeaver ABAP server. This flaw could allow authenticated attackers to gain unauthorized access or modify data, impacting the integrity of systems across affected deployments.
Adobe has released updates for 12 products fix 88 vulnerabilities, with 13 identified in ColdFusion, including eight critical bugs allowing for arbitrary code execution. The urgency of these patches is underscored by their high priority rating, indicating immediate action is necessary to protect systems from potential exploitation.
SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in NetWeaver and Commerce Cloud. These flaws pose serious risks such as data breaches and service disruptions, making it crucial for companies using these platforms to apply the patches promptly.
SAP has released 20 new security notes addressing critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-2026-44747, could allow attackers to modify data and disrupt services, highlighting the importance of timely patching for enterprise software security.
CISA has issued a warning regarding actively exploited remote code execution vulnerabilities in Joomla extensions iCagenda and Balbooa Forms. The flaws enable attackers to upload malicious files, potentially leading to website compromise, prompting federal agencies to implement security updates immediately.
Critical vulnerabilities in Balbooa Forms and iCagenda Joomla extensions allow unauthenticated attackers to achieve remote code execution (RCE). Both vulnerabilities, tracked as CVE-2026-56291 and CVE-2026-48939, are actively exploited, prompting immediate patching recommendations from CISA for federal agencies and all organizations.
CISA has listed two critical vulnerabilities affecting Joomla extensions iCagenda and Balbooa Forms due to reported zero-day exploits. Both vulnerabilities allow arbitrary file uploads leading to remote code execution, significantly threatening Joomla site security.
CISA has warned about actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions. These flaws allow for remote code execution and are critical, with CISA urging immediate action from federal agencies to patch them.
CISA has mandated that federal agencies patch a critical ColdFusion vulnerability (CVE-2026-48282) by June 10 due to its active exploitation risk. Adobe's security update, released recently, is crucial to prevent unauthorized remote code execution on affected systems.
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting active exploitation. These include vulnerabilities in Adobe ColdFusion, Joomla, and Langflow, with CVSS scores up to 10.0, requiring immediate attention from users and administrators.
A critical vulnerability in Adobe ColdFusion, CVE-2026-48282, is being exploited by threat actors for arbitrary code execution following its disclosure. The flaw, with a CVSS score of 10, was patched by Adobe, but attacks began within two hours of the vulnerability becoming public, emphasizing urgent risk for users.
A severe vulnerability in Adobe ColdFusion, CVE-2026-48282, is now being actively exploited by attackers. This flaw allows remote code execution on unpatched systems, prompting Adobe to urge immediate patching of affected versions.
Adobe released patches for seven critical vulnerabilities in ColdFusion and Campaign Classic that could allow arbitrary code execution. These updates address maximum-severity flaws identified by CVSS scores of 10.0, underscoring the importance of these patches for users operating these systems.
Adobe has released security updates for ColdFusion and Campaign Classic, addressing six maximum severity vulnerabilities, including critical flaws allowing arbitrary code execution. These updates come amid increased scrutiny on application security as threat actors rapidly exploit weaknesses.