Adobe has released security patches addressing critical vulnerabilities in its ColdFusion and Campaign Classic software. Among these are six flaws in ColdFusion and one in Campaign Classic, all having the highest CVSS severity score of 10.0. These vulnerabilities can lead to arbitrary code execution, posing significant risks to systems if not promptly patched.
One of the vulnerabilities, identified as CVE-2026-48282, is currently being exploited by hackers. This flaw allows attackers to remotely execute code on unpatched systems, making its immediate remediation crucial. Adobe and security organizations like CISA have stressed the need for users to update their systems as soon as possible.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog, signaling the active exploitation of this vulnerability in the wild. This inclusion underscores the critical nature of the flaw and the priority for system administrators to apply the updates provided by Adobe.
Patching these flaws is imperative to protect against potential security breaches. Administrators of systems using ColdFusion and Campaign Classic should prioritize these updates to mitigate risks associated with the vulnerabilities, thus ensuring the security and integrity of their applications and data.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Threat actors are exploiting a recently patched macOS Screen Sharing vulnerability, CVE-2026-65400, to gain root access and deploy Monero cryptominers on vulnerable systems. This high-severity authentication bypass allows remote attackers to log in without valid credentials, impacting macOS systems with Screen Sharing enabled and accessible from the internet.
A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, was exploited by attackers just three days after its public disclosure. This vulnerability, with a CVSS score of 10, allows for arbitrary code execution and compromise of internal components, posing a significant risk to affected organizations.
Attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing, to gain root access and install Monero cryptocurrency miners on compromised Macs with port 5900 exposed. CISA has increased the vulnerability's CVSS score from 7.1 to 9.8, classifying it as critical and automatable, following reports of active exploitation and the availability of public proof-of-concept code. This flaw allows attackers to authenticate without valid credentials, posing a significant risk to unpatched macOS systems.
Dutch officials have warned that a high-severity macOS vulnerability, CVE-2026-65400, is being actively exploited to gain root access and install crypto miners on affected systems. The flaw, residing in the macOS screen sharing capability, allows attackers to execute malicious code without credentials. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.
The Netherlands' National Cyber Security Centre (NCSC) reports that a macOS Screen Sharing authentication bypass vulnerability (CVE-2026-65400) is being actively exploited to install Monero cryptocurrency miners. The flaw allows attackers to gain root access without valid credentials when port 5900 is exposed to the internet. This exploitation highlights the importance of applying security updates and disabling unneeded remote access features.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, is actively being exploited in attacks just three days after a patch was released. This flaw allows unauthenticated attackers to execute arbitrary code, posing a significant risk to confidentiality, integrity, and availability for organizations using the e-commerce platform.
Threat actors are exploiting an unpatched zero-day SQL injection vulnerability in GeoServer, an open-source geospatial data platform, shortly after its public disclosure. This vulnerability, which can lead to remote code execution under certain configurations, affects GeoServer's jsonArrayContains function and impacts organizations using GeoServer across various industries.
A critical remote code execution vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited to install a reverse SSH tool for persistent remote access. This flaw allows unauthenticated attackers to execute arbitrary code, affecting 361 IP addresses across 47 countries within days of the patch release, posing a significant risk to organizations using vulnerable vCenter versions.
A critical-severity vulnerability in Adobe Commerce (CVE-2026-71362) was targeted by attackers immediately after its public disclosure, despite Adobe stating no evidence of in-the-wild exploitation. The flaw allows unauthenticated attackers to elevate privileges and access customer accounts, prompting Adobe to release an isolated patch for affected versions.
WordPress released version 7.0.4 to patch a high-severity remote code execution vulnerability (CVE-2026-65640) affecting installations using Imagick and Ghostscript. The flaw allowed authenticated attackers with Author-level permissions or higher to execute arbitrary code by uploading malicious Postscript files disguised as images. This update is important for WordPress users, especially those with multi-author sites, as it prevents a realistic threat of code execution through file uploads.
Threat actors are actively exploiting a critical-severity directory traversal vulnerability (CVE-2026-59310) in VMware vCenter's Syslog server, leading to remote code execution. This exploitation, identified by Quirso, began shortly after the vulnerability was disclosed and patched by Broadcom, affecting over 360 IP addresses across 47 countries.
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento e-commerce platforms is being actively exploited to hijack customer accounts. This flaw allows attackers to gain elevated access without authentication, enabling them to access victim accounts and private customer data.
North Korean hackers, identified as the Lazarus Group, exploited a Windows zero-day vulnerability (CVE-2026-68820) in their "Operation Dream Job" campaign to target defense-sector companies. Microsoft patched the flaw in its latest Patch Tuesday updates, confirming active exploitation since early July, allowing attackers to gain SYSTEM privileges.
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a Microsoft Windows vulnerability (CVE-2026-68820) by August 25, as it is actively being exploited by North Korean hackers in the "Operation Dream Job" campaign. This vulnerability allows attackers to gain remote access after an initial phishing compromise, impacting Winsock, a critical component for internet connectivity.
Adobe has issued updates to address multiple critical security flaws in ColdFusion, Commerce, and Campaign Classic, including several with CVSS scores of 10.0. These vulnerabilities could lead to arbitrary code execution or privilege escalation, and administrators are advised to apply the patches promptly.
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter, to gain persistent remote access. This exploitation, observed shortly after public disclosure, affects hundreds of IP addresses across multiple countries and allows for arbitrary code execution and the establishment of reverse SSH connections.
Ivanti released patches for four vulnerabilities across its Endpoint Manager (EPM) and Neurons for MDM products. These updates address high-severity flaws in EPM, including two that remote, unauthenticated attackers could exploit, and a medium-severity command injection vulnerability in Neurons for MDM.
SAP has released patches for a maximum-severity security flaw in Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability, along with three other critical flaws in Manufacturing Integration and Intelligence and Application Server ABAP, requires immediate patching to prevent potential system compromise and data loss.
SonicWall released patches for eight vulnerabilities across its Global Management System (GMS) and Email Security products, including critical remote code execution (RCE) flaws. These updates are important for users to apply to prevent potential exploitation, despite GMS being a discontinued product.
A security researcher released a proof-of-concept (PoC) for "ShieldBreak," a new zero-day vulnerability in Microsoft Defender for Windows. This PoC claims to bypass the patch for CVE-2026-50656 (RoguePlanet), which could allow SYSTEM-level privilege escalation. The vulnerability affects Windows 11 25H2, Windows Server 2025, and Windows 10, indicating that Microsoft's previous fix for RoguePlanet was incomplete.
Cisco has issued a warning about a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD Software that is being actively exploited in the wild. This flaw allows an unauthenticated, remote attacker to trigger a denial-of-service condition by sending a crafted HTTP request to the Remote Access SSL VPN service.
Cisco released patches for a zero-day vulnerability (CVE-2026-20349) affecting Secure Firewall ASA and FTD software, which was actively exploited to cause denial-of-service conditions. The vulnerability allows unauthenticated attackers to reload appliances by sending crafted HTTP requests to the Remote Access SSL VPN service. This matters because exploited security appliance flaws can disrupt network defenses and are being tracked by CISA.
Cisco issued a warning about a high-severity denial-of-service vulnerability, CVE-2026-20349, in its Secure Firewall ASA and Threat Defense (FTD) software that is being actively exploited to remotely crash devices. This flaw, caused by insufficient error checking in HTTP request processing, impacts devices with certain remote access services enabled and requires immediate patching to prevent service disruption.
Adobe released patches for over 50 vulnerabilities across its products, including critical flaws in ColdFusion, Campaign Classic, and Commerce that could lead to arbitrary code execution. These updates are rated with high priority due to the severity of the vulnerabilities, urging immediate application to prevent potential exploitation.
Zoom has released patches for four vulnerabilities, including a severe zero-click remote code execution (RCE) flaw (CVE-2026-53413) affecting its clients on all supported platforms. This RCE vulnerability allowed an attacker to execute code on a meeting participant's machine without interaction, posing a significant security risk to users.
SAP released 28 new security notes and two updates in its August 2026 Security Patch Day, including four critical vulnerabilities. These patches address issues like improper authorization, code injection, and memory corruption in various SAP products, which could lead to unauthorized access, system compromise, or data disclosure.
Cisco has issued a warning regarding two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) in ClamAV's ZIP archive parser, which could lead to denial-of-service attacks. These flaws affect ClamAV versions 1.5.0 through 1.5.3 and have publicly available proof-of-concept exploit code, making immediate patching crucial for affected systems, especially Windows platforms.
CISA has confirmed that ransomware gangs are actively exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a critical server-side request forgery (SSRF) flaw. These vulnerabilities affect secure remote access gateways used by large organizations, increasing the risk of network compromise for affected entities.
Cisco issued a warning regarding seven ClamAV vulnerabilities affecting its Secure Endpoint Connector products, with two having publicly available proof-of-concept (PoC) code. These flaws could lead to denial-of-service conditions, posing a high risk to Windows users due to privileged scanning processes.
Metabase released urgent patches for a critical SQL injection vulnerability actively exploited as a zero-day, allowing remote, unauthenticated attackers to gain administrative access and steal data. This vulnerability impacts self-hosted Metabase users who need to apply updates immediately to prevent potential compromise.
CISA has directed federal agencies to immediately patch a critical OS command injection vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster, which is actively being exploited. This flaw allows unauthenticated remote code execution and could provide initial access to critical internal services if exploited.
Metabase reported that a maximum-severity zero-day vulnerability in its business intelligence software is being actively exploited, allowing unauthenticated remote attackers to gain administrator access. The flaw, with a CVSS score of 10.0, enables SQL injection to compromise Metabase instances. This impacts users running self-hosted versions, who must apply security patches immediately to prevent unauthorized access and data theft.
N-able issued Hotfix 2 for its N-central RMM product to counter ongoing exploitation of CVE-2026-18577, a vulnerability allowing authentication bypass and account takeover. Threat actors are using this flaw to gain administrative access, leverage the Take Control feature, and establish persistence on managed systems. This hotfix is critical for customers as it includes additional hardening measures beyond the initial fix and addresses active attacks.
CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows unauthenticated attackers to execute arbitrary code on affected devices, prompting a directive for federal agencies to patch by August 10, 2026.
A critical SQL injection zero-day vulnerability in Metabase, affecting versions 1.58 and above, was actively exploited to breach customer instances and steal data. Metabase has released patches for both its Cloud SaaS platform and self-hosted installations, urging users to update immediately to prevent unauthorized administrator access and data exfiltration.
WordPress has released a patch for a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen, tracked as CVE-2026-64638, which affects all versions of the content management system. This high-severity vulnerability can be chained into PHP code execution on the server if a logged-in administrator interacts with an attacker-controlled page, making immediate updates critical for site security.
Novee Security discovered and presented vulnerabilities in Anthropic's Claude Code and Google's Gemini CLI that allowed unprivileged GitHub users to execute code on CI runners or exfiltrate API keys. Two CVEs were issued and subsequently patched, highlighting a recurring security failure in the code that orchestrates AI model interactions.
Cisco released updates addressing 12 security vulnerabilities in Catalyst SD-WAN and IOS XE Software, including three with CVSS scores of 9.9 and one with 9.8. These patches resolve issues like improper input validation, access control, and command injection, which could allow attackers to compromise affected systems.
A new KVM escape vulnerability, dubbed Zapscape (CVE-2026-64561), has been disclosed, allowing a guest virtual machine to escape to the host and execute commands with root privileges in KVM/x86 environments. This use-after-free flaw in the shadow MMU emulation poses a significant threat to guest-host isolation, particularly for multi-tenant public clouds that expose nested virtualization.
Cisco released patches for two dozen vulnerabilities across its product line, including critical flaws in Catalyst SD-WAN, IOS XE, and Secure Firewall Management Center (FMC). The most severe vulnerability is an authentication bypass in FMC (CVE-2026-20079) with a CVSS score of 10, allowing remote attackers to gain root privileges. These patches are important for maintaining the security and integrity of network infrastructure for organizations using Cisco products.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical remote code execution vulnerability (CVE-2026-63077) in on-premise versions of JetBrains TeamCity as actively exploited in the wild. This deserialization flaw allows unauthenticated attackers to bypass authentication and execute arbitrary commands, posing a significant risk to CI/CD pipelines and sensitive data.
The US cybersecurity agency CISA has issued a warning that threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-63077) in JetBrains TeamCity, a continuous integration/continuous delivery (CI/CD) platform. This deserialization flaw allows unauthenticated attackers to achieve remote code execution, bypassing authentication checks and executing arbitrary operating system commands on affected TeamCity On-Premises versions. The active exploitation means organizations using TeamCity On-Premises need to apply patches immediately to prevent potential compromise of their software development and deployment infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. These flaws allow for remote code execution and administrative account hijacking, posing significant risks to affected systems.
CISA has issued a warning about three vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat that are actively being exploited by threat actors. These vulnerabilities include remote code execution, authentication bypass, and an EncryptInterceptor bypass, posing risks to affected systems.
CISA has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. These include a code injection flaw in Langflow, a data encryption bypass in Apache Tomcat, and an authentication bypass in N-able N-central, with one Tomcat exploit linked to an AI-enabled hacking campaign.
Security researchers at Forescout have identified 15 new vulnerabilities in TP-Link's Omada zero-touch provisioning (ZTP) systems, with some flaws allowing for full network takeover when chained together. These vulnerabilities could enable attackers to gain administrative control over cloud controllers and internal networks, impacting organizations using Omada devices for automated network configuration.
CISA has added a high-severity N-able N-central vulnerability (CVE-2026-18577) to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw, an incomplete patch of a previous vulnerability, allows authentication bypass and account takeover, enabling attackers to gain administrative access and pivot into managed endpoints.
N-able issued a warning about active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting its N-central RMM servers. The company released hotfix 2026.3.1.7 to address the flaw, which allows administrative account takeover and impacts all N-central versions before 2026.3. This is significant because N-central is a widely used RMM platform, and compromise could extend attacks beyond N-able's direct customers.
The INC Ransomware group has become the primary threat actor exploiting recently disclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These flaws, CVE-2026-15409 and CVE-2026-15410, allow for arbitrary command execution and device takeover, impacting organizations globally. The exploitation enables long-term persistent access and lateral movement within corporate networks, leading to ransomware deployment.
N-able has released patches for CVE-2026-18577, an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) product that has been actively exploited. This vulnerability allows attackers to gain administrative access to N-central servers, potentially compromising customer systems managed by MSPs. The exploitation of this flaw could lead to widespread access to client networks, enabling further malicious activities.
The INC Ransomware group is actively exploiting two recently patched SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to compromise organizations and deploy ransomware. These vulnerabilities allow unauthenticated remote attackers to gain root privileges and have been added to CISA's Known Exploited Vulnerabilities catalog, indicating their active use in attacks.
Attackers exploited an authentication bypass vulnerability in N-able N-central, gaining remote administrative access to servers and subsequently customer systems. An initial fix for the vulnerability proved incomplete, allowing attackers to maintain access through Cloudflare tunnels even after N-central servers were updated.
Adobe released security updates for Campaign Classic (ACC) to fix a critical vulnerability (CVE-2026-48449) with a CVSS score of 10.0, allowing arbitrary code execution without user interaction. The company also addressed eight critical flaws in Adobe Bridge that could lead to privilege escalation and arbitrary code execution. These updates are important for users of Adobe's marketing automation platform and creative software to prevent potential security breaches.
JetBrains released patches for a critical-severity vulnerability (CVE-2026-63077) in TeamCity On-Premises that allowed unauthenticated remote code execution. This flaw could enable attackers to bypass authentication, execute arbitrary commands, and potentially compromise CI/CD pipelines, making immediate patching crucial for affected organizations.
JetBrains has issued a warning about a critical authentication bypass vulnerability, CVE-2026-63077, in TeamCity On-Premises that could lead to remote code execution. This flaw allows attackers with HTTPS access to bypass authentication and execute arbitrary commands, potentially compromising CI/CD pipelines and sensitive data. Administrators are advised to update to patched versions or apply a security plugin immediately.
Broadcom released security updates for five vulnerabilities in VMware products, including three critical flaws that could lead to authentication bypass, arbitrary code execution, or virtual machine escapes. These vulnerabilities affect widely used VMware virtualization platforms and require immediate patching to prevent unauthorized access and system compromise.
South Korean authorities and security firms disclosed a state-sponsored campaign that exploited vulnerabilities in AnySign4PC financial-security software through compromised domestic websites. This allowed attackers to install SIGNBT or COPPERHEDGE backdoors on targeted visitors' systems without user interaction. The campaign highlights the risk of supply chain attacks targeting widely used software in specific regions.
Cisco has disclosed a critical vulnerability in its Firepower Management Center (FMC) that involves static credentials, which has been actively exploited as a zero-day. This vulnerability allows an unauthenticated attacker to gain root access to affected devices, posing a significant risk to network security.
Cisco released patches for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting its Secure Firewall Management Center (FMC) product. This vulnerability, rated high severity, involves static credentials for a low-privilege user, allowing attackers to access sensitive data and potentially escalate privileges when chained with other flaws. The exploitation of this vulnerability highlights the ongoing need for organizations to promptly apply security updates and monitor for indicators of compromise in critical network infrastructure.
CISA added a zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities catalog, confirming active exploitation. The flaw, CVE-2026-20316, allows unauthenticated remote attackers to access sensitive data using static low-privilege credentials. This vulnerability is critical as it can be chained with other flaws to escalate privileges, posing a significant risk to affected systems.
Cisco has issued a warning regarding a high-severity static credential vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC) software, which is being actively exploited in zero-day attacks. This flaw allows unauthenticated remote attackers to gain unauthorized access to affected systems, potentially leading to privilege escalation when combined with other vulnerabilities. Cisco has released hot fixes for multiple FMC releases and advises immediate installation.
A critical security flaw (CVE-2026-59726) in Ruflo, an AI multi-agent orchestration platform, allows unauthenticated attackers to execute remote commands and poison AI memory. The vulnerability impacts all versions before 3.16.3 and exposes 233 tools, including shell command execution, through an unauthenticated Model Context Protocol (MCP) bridge.
Broadcom released security updates addressing multiple vulnerabilities in VMware products, including three critical flaws. These critical vulnerabilities could allow authentication bypass, arbitrary code execution, and code execution on the host system.
Nebula Security reported a patched Firefox JIT vulnerability, CVE-2026-10702, which allowed arbitrary code execution by visiting a malicious webpage and affected Tor Browser versions incorporating vulnerable Firefox releases. This flaw highlights a critical browser security risk, as it required no user interaction beyond page visitation and could be a first stage in more complex exploit chains.
Broadcom released patches for multiple vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three critical flaws. These vulnerabilities include a VM escape in ESXi, an authentication bypass in vCenter, and a remote code execution flaw in vCenter, necessitating immediate updates for affected systems.
Cybersecurity researchers have released technical details and a public proof-of-concept (PoC) for a critical authentication bypass vulnerability (CVE-2026-16232) in Check Point Security Management Server and Multi-Domain Security Management Server. This flaw allows unauthenticated remote attackers to gain full administrative privileges, and Check Point has confirmed active exploitation as a zero-day against a limited number of customers.
vBulletin released patches for a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-61511, affecting versions 5.x and 6.x up to 5.7.5 and 6.2.1. The flaw allows unauthenticated attackers to execute arbitrary PHP code through template rendering, and a public proof-of-concept exploit is available, increasing the risk for unpatched servers.
JetBrains has released updates and a security patch for a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary operating system commands. This flaw could lead to exposure of TeamCity data, configurations, and credentials, making immediate patching crucial for affected organizations.
Arista Networks released patches for a critical OS injection vulnerability (CVE-2026-16812) in its VeloCloud Orchestrator (VCO) platform, which is being actively exploited as a zero-day. This flaw allows remote attackers to access privileged functionality without authentication, impacting the confidentiality, integrity, and availability of the orchestrator and its managed data.
A critical command injection vulnerability (CVE-2026-16812) in on-premises versions of Arista VeloCloud Orchestrator (VCO) is being actively exploited. This flaw allows remote attackers to execute arbitrary code, potentially compromising the orchestrator and managed data.
Arista has released patches for a maximum-severity command injection vulnerability (CVE-2026-16812) in on-premises VeloCloud Orchestrator deployments that is being actively exploited. This flaw allows unauthenticated remote attackers to compromise the orchestrator and its managed data, affecting specific VCO versions.
Details and a proof-of-concept for a pre-authentication remote code execution vulnerability in vBulletin (CVE-2026-61511) were publicly released on July 27. This flaw affects versions 6.2.1 and earlier, and 6.1.6 and earlier, allowing unauthenticated attackers to execute code on unpatched vBulletin forum servers. The public release of exploit details increases the urgency for administrators to apply patches, as the vulnerability requires no user interaction or authentication.
n8n has patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) that allowed authenticated workflow editors to execute operating system commands on the server running the automation platform. This flaw could expose sensitive data like encryption keys and provide access to connected databases, making immediate updates critical for affected n8n users.
Check Point disclosed a critical zero-day vulnerability, CVE-2026-16232, in its Security Management and Multi-Domain Management products, which has been actively exploited. This authentication bypass allows attackers full administrator privileges, leading CISA to add it to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch it by July 25.
Check Point Software has addressed an actively exploited zero-day vulnerability (CVE-2026-16232) in its SmartConsole graphical user interface admin panel. This authentication bypass allows unauthenticated attackers to gain administrator privileges and modify security configurations. The Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw to its catalog of known exploited vulnerabilities, mandating U.S. federal agencies to patch by July 25.
CISA has mandated U.S. government agencies to urgently patch a critical RCE vulnerability, CVE-2026-0770, in the Langflow framework, which is currently being exploited by threat actors. This flaw can allow unauthenticated attackers to execute code with root privileges, posing significant risks to federal operations.
SonicWall disclosed two critical vulnerabilities in SMA1000 appliances that were exploited as zero-days by attackers, leading to custom malware installation. The flaws allow unauthorized access to internal applications and management services, impacting security for users of affected VPN devices.
SonicWall's CVE-2026-15409 and CVE-2026-15410 vulnerabilities were actively exploited for weeks before patches were issued. The breaches allowed attackers using custom malware to access sensitive information on SMA1000 appliances.
A previously unknown threat actor exploited SonicWall Secure Mobile Access (SMA) 1000 series VPN vulnerabilities before their public disclosure. The vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, allow for arbitrary command execution, leading to potential root takeover of affected devices.
CISA has directed U.S. government agencies to prioritize patching two critical vulnerabilities in Fortinet's FortiSandbox. Exploitation allows unauthenticated attackers to remotely execute code, necessitating immediate upgrades to mitigate risks.
CISA has added CVE-2026-25089, an unauthenticated OS command injection vulnerability in FortiSandbox, to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability allows attackers to inject commands through the web interface without authentication, elevating the risk for affected users as this is the third FortiSandbox exploit detected this year.
F5 released patches for eight vulnerabilities affecting NGINX Plus, NGINX Open Source, and BIG-IP, including a critical flaw with a CVSS score of 9.2. These updates are significant as they address potential exploits leading to denial-of-service (DoS) conditions and unauthorized memory access.
Two vulnerabilities in SonicWall's SMA 1000 series are actively exploited, one allowing arbitrary command execution. SonicWall urges immediate patching to mitigate risks associated with these serious security flaws.
SonicWall has issued an urgent patch for its SMA1000 appliances following the discovery of two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410. These vulnerabilities pose serious threats, including server-side request forgery and code injection risks, affecting enterprise security significantly.
SonicWall has disclosed two critical vulnerabilities in SMA1000 products being actively exploited in zero-day attacks. Patching is essential as both issues could allow unauthorized access and control over affected appliances.
SAP has released security updates to address critical vulnerabilities in its NetWeaver and Commerce Cloud products, including a CVSS 9.9 flaw in the NetWeaver ABAP server. This flaw could allow authenticated attackers to gain unauthorized access or modify data, impacting the integrity of systems across affected deployments.
Adobe has released updates for 12 products fix 88 vulnerabilities, with 13 identified in ColdFusion, including eight critical bugs allowing for arbitrary code execution. The urgency of these patches is underscored by their high priority rating, indicating immediate action is necessary to protect systems from potential exploitation.
SAP has released security updates addressing 16 vulnerabilities, including three critical flaws in NetWeaver and Commerce Cloud. These flaws pose serious risks such as data breaches and service disruptions, making it crucial for companies using these platforms to apply the patches promptly.
SAP has released 20 new security notes addressing critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-2026-44747, could allow attackers to modify data and disrupt services, highlighting the importance of timely patching for enterprise software security.
CISA has issued a warning regarding actively exploited remote code execution vulnerabilities in Joomla extensions iCagenda and Balbooa Forms. The flaws enable attackers to upload malicious files, potentially leading to website compromise, prompting federal agencies to implement security updates immediately.
Critical vulnerabilities in Balbooa Forms and iCagenda Joomla extensions allow unauthenticated attackers to achieve remote code execution (RCE). Both vulnerabilities, tracked as CVE-2026-56291 and CVE-2026-48939, are actively exploited, prompting immediate patching recommendations from CISA for federal agencies and all organizations.
CISA has listed two critical vulnerabilities affecting Joomla extensions iCagenda and Balbooa Forms due to reported zero-day exploits. Both vulnerabilities allow arbitrary file uploads leading to remote code execution, significantly threatening Joomla site security.
CISA has warned about actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions. These flaws allow for remote code execution and are critical, with CISA urging immediate action from federal agencies to patch them.
CISA has mandated that federal agencies patch a critical ColdFusion vulnerability (CVE-2026-48282) by June 10 due to its active exploitation risk. Adobe's security update, released recently, is crucial to prevent unauthorized remote code execution on affected systems.
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting active exploitation. These include vulnerabilities in Adobe ColdFusion, Joomla, and Langflow, with CVSS scores up to 10.0, requiring immediate attention from users and administrators.
A critical vulnerability in Adobe ColdFusion, CVE-2026-48282, is being exploited by threat actors for arbitrary code execution following its disclosure. The flaw, with a CVSS score of 10, was patched by Adobe, but attacks began within two hours of the vulnerability becoming public, emphasizing urgent risk for users.
A severe vulnerability in Adobe ColdFusion, CVE-2026-48282, is now being actively exploited by attackers. This flaw allows remote code execution on unpatched systems, prompting Adobe to urge immediate patching of affected versions.
Adobe released patches for seven critical vulnerabilities in ColdFusion and Campaign Classic that could allow arbitrary code execution. These updates address maximum-severity flaws identified by CVSS scores of 10.0, underscoring the importance of these patches for users operating these systems.
Adobe has released security updates for ColdFusion and Campaign Classic, addressing six maximum severity vulnerabilities, including critical flaws allowing arbitrary code execution. These updates come amid increased scrutiny on application security as threat actors rapidly exploit weaknesses.