vulnerability news
549 stories · page 11 of 12
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
Attackers are reportedly bypassing Microsoft Entra ID sign-in logs by spoofing OAuth client IDs during account enumeration against Microsoft cloud tenants. This technique involves manipulating the `client_id` parameter in authentication requests, which Entra ID records as the application ID. The way the system handles unfamiliar identifiers creates a blind spot that threat actors are…

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
Public exploits are now available for a pair of critical vulnerabilities in WordPress Core, which, when chained, allow attackers to achieve pre-authentication remote code execution on affected installations. The flaws, collectively dubbed "wp2shell," impact WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip has released version 26.02 of its popular archiving utility to address a remote code execution (RCE) vulnerability. The flaw, which could allow attackers to execute malicious code, is triggered when users open specially crafted compressed files.

WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Publicly available exploits have emerged for a pair of critical remote code execution (RCE) vulnerabilities in WordPress Core, collectively dubbed "wp2shell." These flaws, identified as CVE-2026-63030 and CVE-2026-60137, can be chained together to allow pre-authentication RCE on affected WordPress installations. Administrators are strongly advised to update their sites immediately.

Two High-Severity WordPress Vulnerabilities Require Immediate Patching
WordPress has released emergency security updates to address two high-severity vulnerabilities, including a critical SQL injection flaw that could lead to remote code execution. Users are urged to patch their installations immediately.

Gemini AI Flaw Lets Strangers Message From Locked Android Phones
A newly identified vulnerability in Google's Gemini AI assistant allows unauthorized individuals with physical access to a locked Android 16 smartphone to send messages via SMS and WhatsApp without needing to enter the device's security PIN. Google has confirmed awareness of the issue and stated that a fix is scheduled for release this week.

Critical RCE Vulnerability in WordPress Core Affects Millions of Sites
A critical unauthenticated remote code execution vulnerability, identified as CVE-2026-63030, has been discovered in WordPress Core, affecting millions of websites globally. The vulnerability allows an attacker to execute arbitrary code without authentication through the WordPress REST API batch endpoint, potentially leading to a complete compromise of the affected website and its data.

Cloudflare WAF Shields WordPress From Critical RCE and SQL Injection Flaws
Cloudflare has confirmed that its Web Application Firewall (WAF) successfully mitigated attacks targeting two critical vulnerabilities in WordPress and its plugins. The vulnerabilities, identified as CVE-2023-50387 and CVE-2024-21724, could lead to remote code execution (RCE) and SQL injection, respectively.

WordPress Core Flaw Allows Unauthenticated Code Execution
A critical vulnerability has been reported in the core of WordPress, enabling unauthenticated attackers to achieve arbitrary code execution on affected websites. The flaw, identified by Adam Kues of Searchlight Cyber, was present in WordPress versions 6.9 and 7.0. WordPress has subsequently released patches and initiated forced updates to mitigate the risk across its user base.

OpenSSL Flaw Allows Denial-of-Service via Small TLS Requests
A denial-of-service vulnerability has been identified in OpenSSL, allowing attackers to disrupt service by sending small TLS requests. The flaw, internally dubbed "HollowByte," can be triggered with an 11-byte TLS request, leading to significant memory allocation issues on vulnerable servers.

Inc Ransomware Exploits SonicWall SMA Zero-Days
Reports indicate that the Inc ransomware group is currently leveraging two previously undisclosed zero-day vulnerabilities within SonicWall's Secure Mobile Access (SMA) appliances. This active exploitation has been observed to grant attackers root-level control over the compromised devices, which can then be used as a pivot point for broader malicious operations within a targeted network.

HollowByte DDoS flaw bloats OpenSSL server memory
A denial-of-service vulnerability, dubbed HollowByte, has been identified in OpenSSL, allowing unauthenticated attackers to deplete server memory with minimal data transmission. The OpenSSL team has addressed the flaw in recent updates, though no CVE identifier has been assigned. Organizations are strongly advised to update their OpenSSL installations to a patched version.

Iran Tracks US Military Phones, macOS Malware, Data Breaches
Recent reports indicate a multi-faceted threat landscape, with Iran reportedly engaging in tracking the mobile phones of U.S. military personnel. This intelligence surfaces alongside the emergence of a new macOS malware variant named CrashStealer. Further incidents include identified vulnerabilities in OpenClaw AI agents, a ransomware attack targeting the naval defense firm TKMS, and a data…

AI Coding Tools Vulnerable to Decades-Old Hacking Technique
AI-powered coding assistants are susceptible to a security flaw that could allow attackers to execute malicious code on a developer's machine. Researchers have dubbed this attack method "GhostApproval." The vulnerability exploits a well-established hacking technique, demonstrating a potential risk as AI tools become more integrated into software development processes.

AI Coding Agents Can Be Tricked Into Executing Malicious Code
A new vulnerability has been reported concerning AI coding agents, specifically those designed to assist with code development and security analysis. Researchers have demonstrated that these agents, including Anthropic's Claude Code and OpenAI's Codex, can be manipulated into executing malicious code rather than performing their intended function of identifying security vulnerabilities. This…

Tenda Firmware Vulnerability Allows Unauthenticated Admin Access
A critical vulnerability has been identified in the firmware of Tenda devices, allowing attackers to gain administrative access without authentication. The flaw, tracked as CVE-2026-11405, affects the web management interface of the affected devices.

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Langflow AI framework to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-55255, has been observed being actively exploited in the wild by threat actors.

Bug in top AI coding agents shows that Unix-era security headaches never really die
Security researchers have identified a significant vulnerability, termed "GhostApproval," affecting multiple widely-used AI coding assistants. This flaw allows malicious actors to trick these agents into accessing and modifying files beyond their intended sandbox environment, leading to potential remote code execution on a developer's machine. The vulnerability was discovered by Google-owned…

CISA orders feds to prioritize patching Langflow auth bypass flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies prioritize patching a critical authentication bypass vulnerability affecting the Langflow visual framework. The directive, issued as Binding Operational Directive (BOD) 26-04, requires agencies to secure their systems by Friday.

Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has issued security updates to address seven critical vulnerabilities affecting its UniFi OS, including a maximum-severity flaw that could allow for command injection attacks. The most severe issue, tracked as CVE-2026-50746, impacts the UniFi Connect Application, specifically versions 3.4.16 and earlier.

CISA orders feds to patch max severity ColdFusion flaw by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch a critical vulnerability in Adobe ColdFusion by Friday. This directive, issued under Binding Operational Directive 26-04, targets a flaw designated CVE-2026-48282, which is actively being exploited by malicious actors.

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
A Linux kernel vulnerability, present for 15 years and now publicly disclosed as CVE-2026-43499, has been identified by Nebula Security. This flaw, dubbed GhostLock, allows any authenticated user on an unpatched system to escalate their privileges to root and to break out of containerized environments.

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its catalog of Known Exploited Vulnerabilities (KEV). These newly identified weaknesses, which affect products from Adobe, Joomla, and Langflow, are reportedly being actively exploited in the wild.

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
Attackers are actively exploiting a critical vulnerability in Gitea's official Docker images, enabling them to bypass authentication and gain access to sensitive repositories and secrets. The flaw, identified as CVE-2026-20896, carries a high severity score of 9.8.

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft
Security researchers at Varonis have disclosed a vulnerability in Google's Dialogflow CX platform that could have allowed attackers to steal sensitive data from AI-powered chatbots. The flaw, which Varonis has named the "Rogue Agent" flaw, has since been addressed by Google with a deployed fix.

Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese threat actors, identified as UAT-7810, are actively developing and deploying new malware to enhance their Operational Relay Box (ORB) network. This network, previously documented as a secure relay infrastructure for other China-aligned advanced persistent threat groups, is being expanded by compromising internet-facing networking devices, with a particular focus on unpatched Ruckus…

Hidden backdoor in Tenda router firmware grants admin access
A security vulnerability has been discovered in the firmware of several Tenda router models, creating a hidden backdoor that could allow unauthorized administrative access. The issue, tracked as CVE-2026-11405, stems from an undocumented authentication mechanism within the device's web server.

Critical Gitea Flaw Under Active Exploitation, Researchers Warn
A critical security vulnerability in the popular open-source Git service Gitea is currently being actively exploited by attackers, according to security researchers. The flaw, identified as CVE-2026-20896, allows unauthorized individuals to bypass authentication mechanisms and gain access to sensitive data, including private repositories and secrets.

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A security vulnerability in Google's Dialogflow CX platform, which has since been addressed, presented a risk of chatbot hijacking. The flaw could have enabled an attacker with edit permissions for a specific "Code Block" agent to gain control over other agents within the same Google Cloud project.

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
A suspected China-aligned threat group, tracked by researchers as UNK_MassTraction, has been actively exploiting vulnerabilities in Roundcube webmail servers to gain access to academic institutions in the United States and Canada. The primary targets appear to be physics and engineering departments, with potential connections to national security interests.

'GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows
A newly identified vulnerability, named GitLost, has been discovered that allows for the exfiltration of private data from GitHub's Agentic Workflows. The flaw enables an unauthenticated attacker to exploit a public GitHub Issue to silently steal information from private repositories.

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
Researchers at Noma Security have uncovered a vulnerability in GitHub's Agentic Workflows that could allow malicious actors to exfiltrate private repository data. The exploit leverages a public GitHub Issue to trick the workflow system into disclosing sensitive information from private repositories.

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
A critical security vulnerability in the enterprise generative AI platform Writer has been patched, addressing a flaw that could have allowed agent previews to leak session tokens and potentially lead to cross-tenant compromise. The issue, identified as a session isolation flaw, posed a significant risk to organizations utilizing the platform for their AI-driven operations.

Critical Adobe ColdFusion Vulnerability Exploited in Attacks
Adobe ColdFusion is facing active exploitation due to a critical vulnerability, identified as CVE-2026-48282. This security flaw carries the highest possible CVSS score of 10, indicating a severe risk to systems running the affected software.

New Januscape Linux flaw allows VM escape on Intel, AMD devices
A newly disclosed vulnerability in the Linux kernel, named Januscape, allows an attacker to escape a virtual machine and execute code on the host system. The flaw, present for approximately 16 years before being patched in June 2026, stems from a use-after-free weakness within the shadow MMU emulation of KVM/x86, the virtualization technology for Intel and AMD processors.

Claude Code’s hidden tracker was an “experiment,” says Anthropic
An independent developer discovered a hidden tracking mechanism within Anthropic's Claude Code client, which the company has since removed, stating it was an experimental feature. The developer, known online as "Thereallo," found the code while reverse-engineering the local installation of Claude Code version 2.1.196. This feature, buried within the minified JavaScript, appeared to encode the…

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems
A critical vulnerability, present in the Linux kernel's KVM (Kernel-based Virtual Machine) hypervisor for 16 years, has been disclosed, potentially allowing attackers to escape virtual machine environments and execute code on the host system. The flaw, named Januscape, impacts systems utilizing processors from both Intel and AMD.

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
China-aligned attackers have targeted U.S. and Canadian universities, exploiting a chain of vulnerabilities in the Roundcube webmail client to gain unauthorized access to sensitive data and establish persistent footholds within academic networks. The campaign, observed by Proofpoint researchers since May, appears to be ongoing and has primarily focused on physics and engineering departments,…

BeyondTrust warns of critical flaws in remote access software
BeyondTrust has issued a warning to its customers regarding two critical security vulnerabilities discovered in its Remote Support (RS) and Privileged Remote Access (PRA) software. These flaws could potentially allow attackers to bypass authentication mechanisms and gain unauthorized access to affected systems.

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released security updates to address critical vulnerabilities in its Remote Support and Privileged Remote Access software. The flaws, if exploited, could allow attackers who have not authenticated to gain unauthorized access and control over vulnerable systems.

CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Threat actors have begun actively exploiting a recently disclosed memory disclosure vulnerability in Citrix NetScaler appliances. This exploitation began shortly after security researchers released a proof-of-concept (PoC) exploit for the flaw.

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A critical vulnerability discovered in the Linux Kernel-based Virtual Machine (KVM) hypervisor could allow a malicious actor within a guest virtual machine to escape to the host system. The flaw, identified as CVE-2026-53359 and nicknamed "Januscape," affects the shadow memory management unit (MMU) component of KVM.

JadePuffer: The First Complete LLM-Driven Ransomware Attack
A novel ransomware attack, dubbed JadePuffer, has been observed leveraging large language models (LLMs) to automate significant portions of its operation, marking a potential shift in the threat landscape. This marks the first documented instance of a complete ransomware attack driven by an agentic threat actor utilizing LLMs.

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Security researchers have detected malicious actors actively probing for a critical vulnerability in Gitea Docker images, just thirteen days after the issue was publicly disclosed and patched. The vulnerability, designated CVE-2026-20896, carries a severe CVSS score of 9.8, indicating a high level of risk.

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages
A security vulnerability discovered in the Opera GX browser could allow malicious websites to silently install add-ons and exfiltrate data from visited pages. The flaw, demonstrated by researchers, specifically targets the gaming-oriented version of the Opera browser.

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
A cybersecurity firm has revealed seven security weaknesses in FatFs, a widely deployed filesystem library. FatFs is used by millions of embedded devices to read and write data on FAT and exFAT formatted storage media, such as USB drives and SD cards. The vulnerabilities were disclosed by the security firm runZero.

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A critical vulnerability, dubbed "Bad Epoll" and identified as CVE-2026-46242, has been discovered in the Linux kernel. This flaw allows an unprivileged user to gain complete root-level control over a compromised system. The vulnerability impacts a wide range of Linux-based systems, including desktop and server distributions, as well as the Android mobile operating system. Fortunately, a patch…

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Threat actors are increasingly leveraging a combination of sophisticated techniques, including the exploitation of a critical Citrix vulnerability, Bring Your Own Vulnerable Driver (BYOVD) attacks, and the misuse of compromised supply chain credentials, to gain initial access for ransomware operations.