Skip to main content

Tag: vulnerability management

549 articles

JFrog Artifactory server setup with laptop in a bright, daylight-filled room.

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens

A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

Analyst 207
Dimly lit server room with rows of racks, one foreground rack with a warning sign.

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks

Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

Analyst 207
Rows of computer servers in a secure data center with a single laptop screen displaying code in the foreground.

Cosmos EVM Flaw Exploited to Drain Funds from Six Blockchains

Cosmos Labs revealed a critical flaw in the Cosmos EVM system was exploited to drain funds from six blockchains, after initially downplaying the bug's impact. The vulnerability was eventually patched on August 19, 2026, with a state-breaking update requiring coordinated network upgrades.

Analyst 207
Office printer room with loose network cable on floor, hinting at security vulnerability.

PaperCut Issues Second Patch as Hackers Exploit Flaws

PaperCut has released an updated emergency patch to tackle vulnerabilities that hackers are actively exploiting, working closely with security researchers to stay one step ahead. This new patch includes extra security measures to protect PaperCut NG and MF installations from attacks.

Analyst 207
Cybersecurity team works in a busy operations center with multiple screens and computer equipment.

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery

The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

Analyst 207
Gitea server setup in a data center with a single server prominently displayed on a rack.

Gitea Servers Exposed to Ongoing Code Execution Attacks

Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Analyst 207
Router on a table with visible lights and ports, surrounded by blurred furniture.

ZBT Routers Expose Critical Flaw with Factory-Installed Implants

Millions of ZBT routers are at risk due to a critical flaw caused by factory-installed implants that grant hackers root access to every device connected to them. This severe vulnerability, rated 9.3 out of 10, allows attackers to take full control with just a network connection.

Analyst 207
Cluttered software development workspace with laptop, monitor, and papers, overlooking a cityscape.

CISA Warns of Persisting Vulnerabilities

Threat actors are still finding success by exploiting simple, preventable software weaknesses that have been known for years - and it's a problem that CISA says could have been designed out of products from the start. The agency's review reveals that decades-old bugs, like improper input validation, continue to plague the industry.

Analyst 207
Modern tech company's server room with rows of equipment and a single laptop workstation.

ServiceNow Patches Maximum-Severity Vulnerabilities

ServiceNow has released urgent security updates to fix three critical vulnerabilities in its AI Platform, and experts warn customers to act fast to secure their self-hosted instances. Apply the patches now to protect against potential malicious attacks.

Analyst 207
Rows of computer servers and storage units in a shared web hosting server room.

cPanel Flaw Enables Root Code Execution via Domain Functionality

A critical cPanel security flaw, tracked as CVE-2026-65643, allows attackers to execute code as the root user, giving them full control of the server, by exploiting domain parking and addon domain functionality. This vulnerability impacts all supported versions of cPanel & WHM and can be triggered by an authenticated account holder.

Analyst 207
Office workspace with printer, computer, and paper supplies, under ordinary indoor lighting.

Hackers Actively Exploit PaperCut Flaw in Zero-Day Attacks

Hackers are on the attack, exploiting a vulnerability in PaperCut's print management software, with confirmed incidents reported by the company. PaperCut has sprung into action, releasing emergency patches to protect its customers from these zero-day attacks.

Analyst 207
Network operations center with analysts monitoring internet traffic and network visualizations on multiple screens.

Federal Agencies Face Shrinking Window to Defend Against Cyber Threats

The threat landscape has drastically changed: cyber attackers can now exploit vulnerabilities in as little as two days, leaving federal agencies with a shrinking window to defend against threats. To stay ahead, they must shift their focus from reacting to attacks to anticipating and preparing for what's next.

Analyst 207
Security analysts work urgently in a dimly lit operations center surrounded by multiple screens displaying threat maps and…

Security Teams Face New Urgency in AI-Enhanced Threat Landscape

The AI-enhanced threat landscape is shrinking the window of time security teams have to act, as advanced models empower attackers to discover vulnerabilities, generate exploit code, and exploit weaknesses faster than ever before. This new urgency demands a fresh approach to threat detection and response.

Analyst 207
Empty computer workstation on a neutral-colored desk in a generic office setting with a laptop and peripherals.

CISA Flags Six Exploited Flaws in Microsoft, Linux, Citrix Products

The US Cybersecurity and Infrastructure Security Agency (CISA) has just sounded the alarm, adding six new vulnerabilities to its Known Exploited Vulnerabilities catalog in a single day - a stark reminder that threat actors are relentlessly targeting both old and newly discovered software weaknesses. This urgent move underscores the need for immediate action to patch these flaws and prevent exploitation.

Analyst 207
Technicians walk through a server room with rows of equipment racks and computer servers.

CISA Mandates Patching of Exploited Citrix NetScaler Flaw

Don't wait until it's too late: CISA has issued a directive requiring all Federal agencies to patch the exploited Citrix NetScaler flaw, CVE-2026-8452, by August 29 to avoid potential security breaches. This critical vulnerability is already being exploited in the wild, making swift action essential.

Analyst 207
Security operations center with large screen displaying system monitoring dashboard.

CISA Catalog Adds Six Exploited Flaws

Active exploitation is underway for six newly cataloged vulnerabilities, including a high-severity Citrix NetScaler flaw that's seen 36 exploitation attempts in just 12 days. The US Cybersecurity and Infrastructure Security Agency has added these flaws to its Known Exploited Vulnerabilities catalog, signaling urgent attention is needed.

Analyst 207
Network equipment rack with modern devices and cables, one device showing an open panel.

Ubiquiti Patches Three Maximum-Severity Flaws in UniFi Line

Ubiquiti has patched three critical vulnerabilities in its UniFi line, with a severity score of 10 out of 10, that could allow hackers to gain control of affected devices. These flaws, along with 19 others, were disclosed in a security bulletin, highlighting the need for immediate updates.

Analyst 207
Cybersecurity team workspace with computers and equipment, featuring a large blank screen.

AI-Driven Vulnerability Discovery Surges, Threatens Software Security

The AI-driven vulnerability discovery surge is alarming, with OpenClaw, a popular AI project, ranking 12th in Q2 for most vulnerabilities discovered and published, with over 200 CVEs registered. This sharp increase in registered vulnerabilities is largely driven by AI adoption in both application development and vulnerability discovery.

Analyst 207
Rows of server racks and networking equipment in a shared data center with technicians in the background.

Unpatched Kaltura Flaws Expose Servers to Remote Code Execution

A pair of unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library could put servers at risk of remote code execution, allowing attackers to read sensitive files and run malicious code - and affecting not just individual customers, but also every tenant on shared hosting infrastructure. This critical security gap, tracked as CVE-2026-19913 and CVE-2026-19912, remains unpatched, leaving countless systems exposed.

Analyst 207
Network operations room with computer workstations and equipment.

Ubiquiti Disrupts Three Max-Severity Flaws in UniFi Systems

Ubiquiti has just dropped a critical security update to fix three massive vulnerabilities in its UniFi systems that hackers can exploit remotely without needing any special access. If you're using UniFi, now's the time to patch up and keep your network safe!

Analyst 207
Security professional examines technology equipment on a tablet or laptop.

Vulnerability Management Faces AI-Driven Overhaul

The AI revolution is here, and it's forcing security teams to ask themselves: are their vulnerability programs ready to keep up with the lightning-fast pace of Frontier AI models that can identify zero-day flaws and adapt in real time? For many organisations, the answer is a worrying "no".

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room with technicians in the background.

Australian Cyber Agency Warns of Widespread TeamCity Server Exploit

A critical TeamCity server flaw, tracked as CVE 2026-63077, is being actively exploited, allowing unauthenticated attackers to bypass security checks and execute malicious commands, posing significant risks to organizations. This vulnerability, with a near-perfect CVSS score of 9.8, is a high-priority threat that demands immediate attention.

Analyst 207
Windows virtual machine terminal in a data center with servers and cables, screen slightly out of focus showing generic…

CISA Mandates Swift Patching for Oracle Flaw

Don't wait - patch now! A critical Oracle flaw, scored 10.0, requires immediate attention to prevent low-complexity attacks that could give hackers complete access to your critical data.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit, empty server room.

CISA Warns of Actively Exploited Oracle WebLogic Flaw

A critical Oracle WebLogic flaw, CVE-2026-21962, is being actively exploited, allowing hackers to wreak havoc on your system by creating, deleting, or modifying sensitive data. This severe vulnerability has a CVSS score of 10.0, making it a high-priority threat that demands immediate attention.

Analyst 207