exploitation

GitLab Critical GraphQL Flaw Actively Exploited
GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

GitLab Code Injection Vulnerability Actively Exploited
A critical code injection vulnerability in GitLab, identified as CVE-2026-19478, is being actively exploited shortly after its public disclosure. The flaw enables unauthenticated attackers to alter or delete public projects and their data under specific circumstances.

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Attackers are actively exploiting a critical vulnerability in Zimbra Collaboration (ZCS) that allows for unauthenticated remote code execution. The flaw, identified as CVE-2026-73570 with a CVSS score of 8.9, stems from improper input sanitization in the SNMP notification processing. Exploitation can lead to the execution of arbitrary operating system commands as the Zimbra user. Zimbra has released version 10.1.20 to patch this vulnerability, and CERT Polska is urging users to check their logs for signs of compromise.

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are actively exploiting a critical vulnerability in macOS's Screen Sharing feature to gain root access and deploy Monero cryptocurrency miners. The flaw, which allows attackers to bypass authentication without valid credentials, is being exploited on Macs with port 5900 exposed to the internet. Apple has released patches for this issue, but exploitation was observed shortly after the fix was deployed.

Critical Adobe Commerce Flaw Exploited After Disclosure
Attackers are actively exploiting a critical vulnerability in Adobe Commerce, identified as CVE-2026-71362, shortly after its public disclosure. This flaw allows unauthenticated attackers to hijack customer accounts and access sensitive data by switching user sessions. Adobe has released an isolated patch to address this and other vulnerabilities.

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit
Attackers are actively exploiting a critical SharePoint vulnerability, CVE-2026-55040, following the public release of a proof-of-concept exploit. This flaw allows unauthenticated attackers to impersonate any user, including administrators, by forging JWT tokens. While Microsoft patched the vulnerability in July, organizations that have not yet applied the update remain at risk of unauthorized access and data manipulation.

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC) exploit. This security feature bypass allows unauthenticated attackers to impersonate users and potentially modify data by exploiting weaknesses in JWT token validation. Microsoft had previously patched this flaw in its July 2026 updates.

Ransomware Gangs Exploit SonicWall SMA1000 Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting two vulnerabilities in SonicWall's SMA1000 series appliances. These flaws, which have already been patched, include a critical server-side request forgery (SSRF) vulnerability. The exploitation is linked to ransomware attacks.

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released Hotfix 2 for its N-central platform to address an actively exploited zero-day vulnerability. Attackers leveraged this flaw to gain administrative access, persist on managed systems using Cloudflare Tunnel, and maintain access even after the initial exploit was mitigated. The company confirmed a limited number of customers were affected and is providing additional indicators of compromise and tools for detection.

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A sophisticated threat actor, tracked as UTA0533, has been exploiting two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. These exploits, CVE-2026-15409 and CVE-2026-15410, were chained together to achieve arbitrary command execution and gain root access. The actor leveraged these vulnerabilities to deploy custom malware, establish persistence, and potentially exfiltrate sensitive data.

Metasploit Adds Linux Fetch Multi Payload for Architecture Agnostic Exploits
The Metasploit Framework has introduced a new Linux Fetch Multi payload family. This enhancement allows for on-the-fly identification of the target host's architecture, enabling a single payload and handler to serve multiple Linux targets without manual architecture selection. This feature is available for HTTP and HTTPS-based fetch payloads.

Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild
Microsoft has released a security advisory for CVE-2026-58644, a critical vulnerability in on-premises SharePoint Server versions that allows unauthenticated remote code execution. The flaw, stemming from untrusted data deserialization, has been actively exploited and added to CISA's Known Exploited Vulnerabilities catalog. Organizations are urged to apply security updates immediately and monitor for exploitation attempts.

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
A critical vulnerability in Gitea's Docker images, identified as CVE-2026-20896, allows attackers to bypass authentication using a single HTTP header. This flaw, stemming from insecure default configurations that trust any IP address for reverse proxy authentication, enables unauthorized access to repositories and sensitive data. Researchers have observed active exploitation of this vulnerability shortly after its disclosure.

Critical Gitea Flaw Under Active Exploitation, Researchers Warn
A critical vulnerability in Gitea, tracked as CVE-2026-20896, is being actively exploited. The flaw lets attackers bypass authentication with a single HTTP header to access repositories and secrets.

Critical Adobe ColdFusion Vulnerability Exploited in Attacks
A critical Adobe ColdFusion vulnerability, CVE-2026-48282 with a maximum CVSS score of 10, is being actively exploited in attacks. The flaw poses a severe risk to affected systems.

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Researchers have identified a new cyberattack campaign targeting academic institutions in North America. The attackers, believed to be linked to China, are exploiting vulnerabilities within the Roundcube webmail system used by physics and engineering departments.

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
A critical vulnerability affecting Cisco Unified CM and Unified CM SME deployments, which allows for server-side request forgery (SSRF) and root privilege escalation, was rapidly exploited by attackers. Threat actors weaponized the flaw within 24 hours of its public disclosure.