Tag: cvss
20 articles

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens
A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

WordPress Flaws Expose Sites to Takeover, Code Execution
Critical vulnerabilities in popular WordPress plugins and themes have been exposed, putting sites at risk of takeover, remote code execution, and full compromise. Five flaws with near-maximum severity ratings have been disclosed, affecting specific versions of WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP.

NASA AIT-GUI Flaws Expose Spacecraft to Unauthorized Command Issuance
A chain of flaws in NASA's AIT-GUI system could put spacecraft at risk of receiving unauthorized commands, with a potentially massive blast radius of affected instrument commands. Security researchers at Cycode have sounded the alarm on this vulnerability, rated a near-critical 9.4 on the CVSS scale.

Elementor Pro Flaw Enables Unauthenticated Code Execution
A critical vulnerability in Elementor Pro, rated CVSS 9.0, allows hackers to execute malicious code remotely - and it's surprisingly easy to exploit, thanks to a logic flaw in the plugin's Forms module. This loophole lets attackers bypass security checks and write PHP files to a public uploads directory.

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion
GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks
SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

SAP Patches Critical Flaw Allowing Unauthenticated Code Execution
A critical flaw in SAP Commerce Cloud, rated 10.0 on the CVSS scale, allows hackers to execute malicious code without any authentication, putting your entire system at risk. This severe vulnerability can be exploited with specially crafted input, making it essential to patch ASAP.

Metabase Zero-Day Exploits Grant Admin Access
A critical zero-day vulnerability in Metabase allows hackers to gain admin access and wreak havoc on your data, with a perfect 10.0 CVSS score highlighting the severity of this threat. Attackers can inject malicious SQL, steal sensitive credentials, and export data, making immediate patching a top priority.

CISA Warns of Active Exploitation of Adobe, Joomla, and Langflow Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on four high-severity vulnerabilities in Adobe, Joomla, and Langflow that are being actively exploited by hackers. Federal agencies have until July 10, 2026, to patch these flaws and avoid potential breaches.

Fortinet, Ivanti, SAP Patch Critical Vulnerabilities
This week, Fortinet, Ivanti, and SAP issued urgent patch rollouts to fix critical vulnerabilities that could allow hackers to execute remote code or gain unauthorized access to sensitive systems. The flaws, affecting sandboxing infrastructure, mobile gateway software, and core enterprise apps, carry high severity scores and demand immediate attention.

Protobuf.js Vulnerabilities Expose Node.js Apps to Code Execution, DoS
A single malicious protobuf schema could be all it takes to trigger crashes, corrupt runtimes, or even execute code in vulnerable Node.js apps, warns Cyera security researcher Assaf Morag. Six newly identified vulnerabilities in protobuf.js, known as Proto6, carry high severity scores and could put your app at risk.

CISA Flags Oracle WebLogic Flaw as Actively Exploited
The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged a high-severity Oracle WebLogic flaw, CVE-2024-21182, as actively exploited, prompting federal agencies to apply fixes by June 4, 2026. This critical vulnerability, rated 7.5 by CVSS, was added to CISA's Known Exploited Vulnerabilities Catalog after evidence of active exploitation was confirmed.

India's CERT-In Urges 12-Hour Patch Deadline for Exploited Vulnerabilities
CERT-In is urging organizations to act fast - patch, mitigate, or remove exposure to exploited vulnerabilities within 12 hours for internet-facing and high-priority systems. This strict deadline aims to minimize risk and protect critical assets from potential attacks.

Cisco Exposes New Zero-Auth Vulnerability in Secure Workload Platform
Cisco has uncovered a critical zero-auth vulnerability in its Secure Workload platform, allowing attackers to access sensitive information and make configuration changes with alarming ease and admin-level privileges. This severe flaw, scoring a perfect 10.0 on the CVSS scale, demands immediate attention to prevent exploitation.

Microsoft Patches 138 Vulnerabilities, Including Critical DNS and Netlogon Flaws
Microsoft just patched a critical DNS flaw that could let hackers execute code on your network, along with 137 other vulnerabilities - so make sure to update ASAP! The update also includes a mandatory rollout of updated Secure Boot certificates to keep your system secure.

Microsoft Patch Tuesday Exposes 137 Vulnerabilities, Including 30 Critical Flaws
Microsoft just dropped a massive Patch Tuesday update, fixing 137 vulnerabilities - including 30 critical flaws and 14 high-severity bugs scoring 9.0 or higher on the CVSS scale. This surge in patches, partly driven by AI-powered bug detection, is expected to continue, making it crucial to stay on top of updates.

Cline Kanban Flaw Exposes AI Coding Agents to Website Hijacking
A critical vulnerability in Cline Kanban's WebSocket endpoints lets hackers hijack websites visited by developers, silently interacting with local AI agents - and it's a flaw that requires zero phishing, malware, or social engineering. This severe flaw, scoring 9.7 on the CVSS scale, puts AI coding agents at risk of website hijacking.

Google Fixes Critical Gemini CLI Flaw Enabling Remote Code Execution
Google patched a critical flaw in Gemini CLI that allowed hackers to inject malicious code and take control of host systems, thanks to a report from Novee Security. The vulnerability, scoring a perfect 10.0 on the CVSS scale, has been fixed in recent updates to the @google/gemini-cli and google-github-actions/run-gemini-cli packages.

Cursor Flaw Exposes Developer API Keys to Unrestricted Access
A single design flaw in the AI-powered development tool Cursor has been found to expose developer API keys to unrestricted access, earning a high-severity CVSS score of 8.2. This vulnerability stems from Cursor's weak storage design, which stores sensitive authentication data in a locally accessible SQLite database without proper protection.

nginx-ui Flaw Enables Full Server Takeover via Active Exploits
A single flaw in nginx-ui, a popular open-source management tool for Nginx, has been actively exploited, allowing attackers to seize control of your server with ease. This critical authentication bypass vulnerability, tracked as CVE-2026-33032, has been rated extremely severe with a CVSS score of 9.8.