vulnerability news
549 stories · page 1 of 12
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

Citrix NetScaler Hit by Third Actively Exploited Zero-Day
Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

Citrix NetScaler security snafus get even worse amid more 0-day reports
Citrix has confirmed a new zero-day vulnerability, CVE-2026-88779, affecting its NetScaler ADC and Gateway appliances, which is already being actively exploited in the wild. The flaw is a memory overflow bug that can lead to denial of service attacks.

Rejetto HFS servers now actively scanned for critical RCE flaw
Rejetto HFS servers are currently experiencing active scanning for a critical remote code execution (RCE) vulnerability, identified as CVE-2026-61500. This flaw, which allows for session forgery and account takeover, was first disclosed on July 13, 2026, and details of a proof-of-concept (PoC) exploit were publicly released on September 30, 2026.

Google halts open-source bug bounty program amid AI spam surge
Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

AI slop submissions force Google to freeze its open-source bug bounty
Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

Citrix NetScaler Flaw Exploited Before CVE Publication
The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

NetScaler CVE-2026-88779 Exploited Before Publication
NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

dompdf_project dompdf XSS flaw added to VulnCheck KEV
CVE-2022-28368, a cross-site scripting vulnerability in dompdf, was added to the VulnCheck Known Exploited Vulnerabilities catalogue. The flaw has a high EPSS score but is not listed by CISA or ENISA.

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water…

Zyxel GS1900 Switch Flaw Exploited, Now in EU Catalogue
A stack-based buffer overflow in Zyxel GS1900-48HPv2 switches is now listed in the EU's common vulnerabilities exploited catalogue, following its inclusion in the US federal list.

Zammad Session Fixation Vulnerability Exploited Same Day as Disclosure
CVE-2026-102489, a session fixation vulnerability in Zammad GmbH Zammad, was exploited on the same day it was published. The vulnerability is now listed in multiple exploitation catalogues.

Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-102490, an improper privilege management vulnerability in Zammad GmbH Zammad, was exploited on the same day it was published. It is now listed in multiple exploitation catalogues.

Linux Kernel Out-of-Bounds Write Exploited, Added to EUVD
A Linux kernel vulnerability, CVE-2026-53266, has been confirmed as exploited and added to the EUVD catalogue. This follows its inclusion in the CISA KEV list.

getarcane arcane SSRF Flaw Added to VulnCheck KEV
CVE-2026-40242, a Server-Side Request Forgery in getarcane arcane, was added to the VulnCheck KEV catalogue on September 17, 2026. It has been publicly exploited since April 10, 2026.

Kan Project Management Tool SSRF Flaw Exploited, Not on CISA KEV
A server-side request forgery vulnerability in the Kan project management tool has been confirmed as exploited. The flaw, CVE-2026-32255, has been listed on VulnCheck's Known Exploited Vulnerabilities catalog but not yet on CISA's.

Paytm Payment Gateway SSRF Flaw Added to VulnCheck KEV
CVE-2022-45362, a server-side request forgery vulnerability in Paytm's payment gateway, was added to the VulnCheck KEV catalog. It has been publicly exploited since at least December 2023.

CVE-2023-54405 Exploited Same Day as Publication
A vulnerability, CVE-2023-54405, was reported as exploited on the same day it was published. This flaw has an 'Unrestricted Upload of File with Dangerous Type' vulnerability.

CVE-2014-125130 Exploited Same Day as Publication
A path traversal vulnerability, CVE-2014-125130, was reported as exploited on the same day its CVE record was published. The vulnerability is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

CVE-2020-37278 SSRF Exploited Same Day as Publication
A server-side request forgery vulnerability, CVE-2020-37278, was reportedly exploited on the same day it was published. The flaw has a zero-day patch window.

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
A critical authentication bypass vulnerability, tracked as CVE-2026-61500, in Rejetto HTTP File Server (HFS) has been actively exploited in the wild, with initial activity originating from a China-hosted IP address. The flaw, which can lead to full administrative access and remote code execution, was discovered by researchers using Anthropic's AI bug-hunting model, Mythos.

YARA-X 1.21.0 Release, (Sat, Oct 3rd)
The YARA-X project has announced the release of version 1.21.0, which includes five new improvements and four bug fixes. The update was made available on Saturday, October 3rd.

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The…

Dutch Vulnerability Institute Breached Via Zammad 0-Days
The Dutch Institute for Vulnerability Disclosure (DIVD) has reportedly suffered a security breach, with attackers exploiting two zero-day vulnerabilities in the Zammad ticketing system. The incident led to remote code execution and ultimately granted the attackers root access to affected systems.

Fortra Patches Critical Vulnerabilities in BoKS
Fortra has released patches addressing critical vulnerabilities within its BoKS product line. The reported flaws collectively present a significant security risk, potentially enabling attackers to bypass authentication mechanisms, execute arbitrary shell commands, and trigger memory corruption issues. These vulnerabilities underscore the ongoing challenges in securing privileged access…

CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed
GitLab has released patches for a critical vulnerability in its AI Gateway, identified as CVE-2026-90970, which could enable an authenticated user to execute arbitrary commands on self-hosted gateway instances. The flaw, which carries a CVSS score of 9.9, was publicly disclosed by GitLab on October 2, 2026.

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in Zammad GmbH's Zammad helpdesk software to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address them by October 5, 2026. These flaws, identified as CVE-2026-102489 and CVE-2026-102490, have been actively exploited in the wild, including in a recent breach of…

Frontline Education breach exposes school district employee data
Frontline Education, a provider of administration and workforce management software for school districts, has confirmed a data breach that exposed employee information, including Social Security numbers, after attackers exploited a vulnerability in a third-party software product. The company began notifying affected school districts of the incident in early October 2026.

Warlock ransomware breach SharePoint in water, telecom operator attacks
The Warlock ransomware group, identified by Symantec as Longlegs, has been observed targeting a range of organizations, including a water utility, a telecommunications provider, a regional government body, and a university. These attacks, which have primarily focused on Portuguese and Spanish-speaking countries in Europe, Africa, and Latin America over the past two months, leverage…

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab has issued a patch for a critical vulnerability in its AI Gateway, which could allow a logged-in user to execute arbitrary commands on self-hosted gateway instances. The flaw, rated 9.9 on the CVSS scale, specifically affects organizations that host their own AI Gateway and have configured it to use Duo Agent Platform access.

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has issued security updates to address several critical vulnerabilities within its Container Storage Modules (CSM) that could be leveraged by malicious actors to compromise affected systems. Among the disclosed flaws is CVE-2026-63688, which has been assigned a CVSS score of 10.0. This particular vulnerability is described as a missing authentication for critical function flaw residing in…

SWIFT Banking & Government Middleware Enables RCE
A recent report indicates that critical vulnerabilities have been identified in SWIFT banking and government middleware, potentially enabling remote code execution (RCE). The findings highlight a significant risk, particularly in environments that rely on hardware-based multi-factor authentication (MFA), suggesting that these systems could be exploited if the underlying middleware remains…

GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab has issued an urgent warning to customers regarding a critical remote code execution (RCE) vulnerability, identified as CVE-2026-90970, affecting its AI Gateway service. The flaw could allow attackers to execute arbitrary commands on vulnerable self-hosted instances.

CuppaCMS Flaw Listed in VulnCheck KEV, Not CISA KEV
CVE-2022-25497, a vulnerability in CuppaCMS, was added to the VulnCheck Known Exploited Vulnerabilities catalogue on September 17, 2026, but remains absent from the US federal CISA KEV catalogue and the European Union's EUVD catalogue.

CVE-2026-86538 Path Traversal Flaw Exploited
A path traversal vulnerability in knowns-dev knowns, CVE-2026-86538, was reported exploited on September 17, 2026. The vulnerability was published on September 7, 2026.

Dolibarr ERP/CRM Flaw Added to VulnCheck Exploited List
A vulnerability in Dolibarr ERP/CRM was added to the VulnCheck Known Exploited Vulnerabilities catalogue on September 17, 2026. The flaw was publicly reported as exploited on the same date.

Gravity Forms Unrestricted Upload Flaw Exploited Before CVE Publication
A critical vulnerability in Gravity Forms, an unrestricted file upload flaw, was exploited before its official CVE publication. It is listed on VulnCheck's Known Exploited Vulnerabilities catalogue but not on CISA's or the EUVD.

Caucho Resin Path Traversal Flaw Exploited Same Day as Disclosure
CVE-2017-20284, a path traversal vulnerability in Caucho Technology's Resin, was reported as exploited on the same day it was published. VulnCheck lists it as exploited, but CISA and EUVD do not.

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of…

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiMail vulnerability, identified as CVE-2026-104286, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, which carries a CVSS score of 9.8, is a path traversal vulnerability that attackers are reportedly exploiting in the wild.

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.

AI agents hacked the hackers, stealing email addresses from security research org
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit cybersecurity research organization, has confirmed it was compromised through two zero-day vulnerabilities in its Zammad support platform. The attack, which occurred on September 21, involved session hijacking, remote code execution, and privilege escalation to root access, leading to the theft of email addresses and…

Werkzeug Path Traversal Flaw Linked to Ransomware Use
CVE-2024-49766, a path traversal vulnerability in Werkzeug, is now linked to ransomware campaigns. The flaw was publicly known for over two years before this connection was made.