Tag: vulnerability management
549 articles

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens
A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks
Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

Cosmos EVM Flaw Exploited to Drain Funds from Six Blockchains
Cosmos Labs revealed a critical flaw in the Cosmos EVM system was exploited to drain funds from six blockchains, after initially downplaying the bug's impact. The vulnerability was eventually patched on August 19, 2026, with a state-breaking update requiring coordinated network upgrades.

PaperCut Issues Second Patch as Hackers Exploit Flaws
PaperCut has released an updated emergency patch to tackle vulnerabilities that hackers are actively exploiting, working closely with security researchers to stay one step ahead. This new patch includes extra security measures to protect PaperCut NG and MF installations from attacks.

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery
The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

Gitea Servers Exposed to Ongoing Code Execution Attacks
Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

ZBT Routers Expose Critical Flaw with Factory-Installed Implants
Millions of ZBT routers are at risk due to a critical flaw caused by factory-installed implants that grant hackers root access to every device connected to them. This severe vulnerability, rated 9.3 out of 10, allows attackers to take full control with just a network connection.

CISA Warns of Persisting Vulnerabilities
Threat actors are still finding success by exploiting simple, preventable software weaknesses that have been known for years - and it's a problem that CISA says could have been designed out of products from the start. The agency's review reveals that decades-old bugs, like improper input validation, continue to plague the industry.

ServiceNow Patches Maximum-Severity Vulnerabilities
ServiceNow has released urgent security updates to fix three critical vulnerabilities in its AI Platform, and experts warn customers to act fast to secure their self-hosted instances. Apply the patches now to protect against potential malicious attacks.

cPanel Flaw Enables Root Code Execution via Domain Functionality
A critical cPanel security flaw, tracked as CVE-2026-65643, allows attackers to execute code as the root user, giving them full control of the server, by exploiting domain parking and addon domain functionality. This vulnerability impacts all supported versions of cPanel & WHM and can be triggered by an authenticated account holder.

Hackers Actively Exploit PaperCut Flaw in Zero-Day Attacks
Hackers are on the attack, exploiting a vulnerability in PaperCut's print management software, with confirmed incidents reported by the company. PaperCut has sprung into action, releasing emergency patches to protect its customers from these zero-day attacks.

Federal Agencies Face Shrinking Window to Defend Against Cyber Threats
The threat landscape has drastically changed: cyber attackers can now exploit vulnerabilities in as little as two days, leaving federal agencies with a shrinking window to defend against threats. To stay ahead, they must shift their focus from reacting to attacks to anticipating and preparing for what's next.

Security Teams Face New Urgency in AI-Enhanced Threat Landscape
The AI-enhanced threat landscape is shrinking the window of time security teams have to act, as advanced models empower attackers to discover vulnerabilities, generate exploit code, and exploit weaknesses faster than ever before. This new urgency demands a fresh approach to threat detection and response.

CISA Flags Six Exploited Flaws in Microsoft, Linux, Citrix Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has just sounded the alarm, adding six new vulnerabilities to its Known Exploited Vulnerabilities catalog in a single day - a stark reminder that threat actors are relentlessly targeting both old and newly discovered software weaknesses. This urgent move underscores the need for immediate action to patch these flaws and prevent exploitation.

CISA Mandates Patching of Exploited Citrix NetScaler Flaw
Don't wait until it's too late: CISA has issued a directive requiring all Federal agencies to patch the exploited Citrix NetScaler flaw, CVE-2026-8452, by August 29 to avoid potential security breaches. This critical vulnerability is already being exploited in the wild, making swift action essential.

CISA Catalog Adds Six Exploited Flaws
Active exploitation is underway for six newly cataloged vulnerabilities, including a high-severity Citrix NetScaler flaw that's seen 36 exploitation attempts in just 12 days. The US Cybersecurity and Infrastructure Security Agency has added these flaws to its Known Exploited Vulnerabilities catalog, signaling urgent attention is needed.

Ubiquiti Patches Three Maximum-Severity Flaws in UniFi Line
Ubiquiti has patched three critical vulnerabilities in its UniFi line, with a severity score of 10 out of 10, that could allow hackers to gain control of affected devices. These flaws, along with 19 others, were disclosed in a security bulletin, highlighting the need for immediate updates.

AI-Driven Vulnerability Discovery Surges, Threatens Software Security
The AI-driven vulnerability discovery surge is alarming, with OpenClaw, a popular AI project, ranking 12th in Q2 for most vulnerabilities discovered and published, with over 200 CVEs registered. This sharp increase in registered vulnerabilities is largely driven by AI adoption in both application development and vulnerability discovery.

Unpatched Kaltura Flaws Expose Servers to Remote Code Execution
A pair of unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library could put servers at risk of remote code execution, allowing attackers to read sensitive files and run malicious code - and affecting not just individual customers, but also every tenant on shared hosting infrastructure. This critical security gap, tracked as CVE-2026-19913 and CVE-2026-19912, remains unpatched, leaving countless systems exposed.

Ubiquiti Disrupts Three Max-Severity Flaws in UniFi Systems
Ubiquiti has just dropped a critical security update to fix three massive vulnerabilities in its UniFi systems that hackers can exploit remotely without needing any special access. If you're using UniFi, now's the time to patch up and keep your network safe!

Vulnerability Management Faces AI-Driven Overhaul
The AI revolution is here, and it's forcing security teams to ask themselves: are their vulnerability programs ready to keep up with the lightning-fast pace of Frontier AI models that can identify zero-day flaws and adapt in real time? For many organisations, the answer is a worrying "no".

Australian Cyber Agency Warns of Widespread TeamCity Server Exploit
A critical TeamCity server flaw, tracked as CVE 2026-63077, is being actively exploited, allowing unauthenticated attackers to bypass security checks and execute malicious commands, posing significant risks to organizations. This vulnerability, with a near-perfect CVSS score of 9.8, is a high-priority threat that demands immediate attention.

CISA Mandates Swift Patching for Oracle Flaw
Don't wait - patch now! A critical Oracle flaw, scored 10.0, requires immediate attention to prevent low-complexity attacks that could give hackers complete access to your critical data.

CISA Warns of Actively Exploited Oracle WebLogic Flaw
A critical Oracle WebLogic flaw, CVE-2026-21962, is being actively exploited, allowing hackers to wreak havoc on your system by creating, deleting, or modifying sensitive data. This severe vulnerability has a CVSS score of 10.0, making it a high-priority threat that demands immediate attention.