cve news
12 stories
Citrix NetScaler Hit by Third Actively Exploited Zero-Day
Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

Critical GitLab Vulnerability Exploited in Internet-Wide Probes
GitLab has released emergency patches for two high-severity vulnerabilities in its software development platform, one of which carries the maximum possible severity score and is already being actively probed by attackers across the internet. The company urged operators of self-managed installations to upgrade immediately, while confirming its own hosted service and single-tenant Dedicated…

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
A remote code execution (RCE) vulnerability, identified as CVE-2026-63520, has been disclosed in Microsoft SharePoint, allowing an authenticated attacker to execute arbitrary code on a vulnerable server. When chained with an authentication bypass vulnerability, CVE-2026-55040, the exploit becomes unauthenticated.

GitLab Code Injection Vulnerability Actively Exploited
A critical code injection vulnerability in GitLab, tracked as CVE-2026-19478, is reportedly being actively exploited in the wild. The flaw was publicly disclosed recently, and exploitation attempts have been observed shortly thereafter. This vulnerability allows unauthenticated attackers to manipulate or remove public projects and their associated data, though specific conditions must be met…

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
A newly identified vulnerability, dubbed ShieldBreak (CVE-2026-69414), has been disclosed as a bypass for a previous patch issued by Microsoft for its Defender antivirus product. This elevation of privilege (EoP) flaw in the Microsoft Malware Protection Engine reportedly circumvents the fix for an earlier vulnerability, RoguePlanet, which Microsoft addressed in July.

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
A critical authentication bypass vulnerability, identified as CVE-2026-15826, has been discovered in the User Profile Builder plugin for WordPress, potentially exposing over 40,000 websites to administrative takeover. The flaw, which carries a CVSS rating of 9.8, affects plugin versions up to and including 3.16.4.

Critical Adobe Commerce Flaw Exploited After Disclosure
Attackers have begun exploiting a critical vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that could allow unauthenticated account takeovers and access to sensitive customer data. The flaw, identified as CVE-2026-71362, carries a CVSS score of 9.1 and was publicly disclosed by Adobe in its APSB26-92 security bulletin.

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
A critical command injection vulnerability affecting Progress Kemp LoadMaster has been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog. The flaw, identified as CVE-2026-8037, reportedly enables unauthenticated attackers to achieve arbitrary code execution on vulnerable devices. This inclusion by CISA follows reports of…

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
On July 27, 2026, JetBrains issued a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting its TeamCity product. This flaw allows an unauthenticated attacker to achieve remote code execution by exploiting the agent polling protocol. An attacker capable of reaching a TeamCity server via HTTP or HTTPS can execute operating system commands with the…

Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild
Microsoft has confirmed active exploitation of a critical remote code execution (RCE) vulnerability, CVE-2026-58644, affecting on-premises deployments of its SharePoint Server. The vulnerability, which stems from the deserialization of untrusted data (CWE-502), allows an unauthenticated attacker to execute arbitrary code with a CVSS v3.1 score of 9.8 (Critical).

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI
Elastic's InfoSec Product Security Team has developed a generative AI agent to automate the drafting of security advisories, significantly reducing the time required to process vulnerability reports. This new system leverages Retrieval-Augmented Generation (RAG) against MITRE's Common Weakness Enumeration (CWE) and Common Attack Pattern Enumeration and Classification (CAPEC) catalogs, which…

Oracle Releases June Patch Update Addressing 243 Vulnerabilities
Oracle has issued its June Critical Security Patch Update, resolving 243 unique CVEs with 245 security patches. A significant portion, 122 patches, are rated as critical severity. The Oracle Fusion Middleware product family received the largest number of fixes, with 106 patches.