vulnerability news
549 stories · page 2 of 12
Yonyou U8 CRM Path Traversal Flaw Exploited Same Day as Disclosure
CVE-2023-54403, a path traversal vulnerability in Yonyou U8 CRM, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

Inspur Haiyue HCM Cloud Path Traversal Flaw Exploited Same Day
CVE-2024-58387, a path traversal vulnerability in Inspur Haiyue HCM Cloud, was reported as exploited on the same day it was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

Fortinet FortiMail Path Traversal Flaw Exploited Same Day as Disclosure
A path traversal vulnerability in Fortinet FortiMail was exploited on the same day it was disclosed, leaving no patch window for affected organizations.

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws…

Legit Security extends automated fixes to vulnerable open-source dependencies
Legit Security has announced an expansion of its Agentic Remediation capability to automatically address vulnerabilities found in open-source dependencies. This update allows development teams to move directly from vulnerability detection to a verified fix without requiring manual triage, a process previously limited to first-party code.

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget has confirmed that a recent theft of $387.5 million was facilitated by the exploitation of a zero-day vulnerability in third-party security products. The confirmation, based on ongoing investigation findings from blockchain security firm SlowMist, indicates that malicious activity involved these external security solutions. Investigators reportedly recovered a…

The vulnerabilities AI finds are the ones attackers want
Threat actors are rapidly exploiting vulnerabilities discovered by artificial intelligence research agents, often within days of public disclosure, according to new research from Google Threat Intelligence Group (GTIG). The group's analysis, covering January 2025 to August 2026, indicates a significant increase in overall vulnerability exploitation, particularly for "n-day" flaws.

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Recent analysis by LevelBlue's Threat Hunt Operations & Research (THOR) team indicates that threat actors are exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway products. The observed post-exploitation payloads are designed to establish persistence by creating superuser accounts and mapping web shells to URLs that mimic…

Apple Products Vulnerability Exploited Same Day as Disclosure
A critical out-of-bounds write vulnerability in multiple Apple products was exploited on the same day it was disclosed. Both US and EU government catalogues now list it as actively exploited.

Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Google's Threat Intelligence Group (GTIG) has reported a significant surge in vulnerability disclosures, with monthly totals more than doubling from January to August of this year. The number of disclosures climbed from 5,045 in January to over 10,000 in both July and August, peaking at 10,740 last month. This increase is attributed by GTIG researchers to the growing influence of artificial…

16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
A 16-year-old security researcher, known as Faav, discovered an authentication flaw in Microsoft's internal analytics service, Titan, which granted him administrator access and the ability to execute unauthorized SQL queries. This vulnerability potentially exposed analytics databases containing an estimated 17.3 trillion rows of data. Microsoft has since addressed the issue and awarded Faav a…

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors are actively exploiting a previously disclosed vulnerability in Zimbra Collaboration Suite (ZCS) to gain unauthorized access and exfiltrate sensitive information, as reported by the Microsoft Security Research team. The attacks involve the deployment of web shells and subsequent harvesting of authentication secrets, indicating a sophisticated post-exploitation strategy aimed at…

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical pre-authentication remote code execution (RCE) vulnerability affecting MikroTik RouterOS. The flaw, identified as CVE-2026-84411, is an integer underflow within the web-management HTTP request handling component of RouterOS.

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has released a series of patches addressing multiple vulnerabilities within its Fireware OS. The update targets a total of fifteen distinct security flaws, encompassing critical code injection vulnerabilities, denial-of-service issues, authorization bypasses, and path traversal bugs. This comprehensive patch aims to fortify the security posture of devices running the Fireware…

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Reports indicate that government and finance organizations have been targeted in weeks-long attacks exploiting zero-day vulnerabilities in NetScaler products. The attacks leverage two specific vulnerabilities, identified as CVE-2026-88771 and CVE-2026-88772, with multiple security firms confirming observed exploitation.

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
Suspected state-sponsored threat actors have been exploiting a zero-day vulnerability in NetScaler Application Delivery Controllers (ADCs) and Gateways, identified as CVE-2026-88772, since at least early September 2026. This flaw, along with a related vulnerability, CVE-2026-88771, allows for remote code execution on affected appliances. Citrix confirmed the active exploitation of both…

Most open critical and high flaws are over 90 days old
A recent analysis of internet-facing systems across 1,293 organizations in the US, UK, and Nordics revealed that the vast majority of critical and high-severity vulnerabilities remain unaddressed for over 90 days. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than three months at the time of the study.

Most organizations need six months or longer to roll out new security controls
A recent survey of 8,000 security professionals across 30 markets indicates that most organizations face significant internal friction and delays in implementing new security controls, with only a small fraction demonstrating high effectiveness against modern threats. The survey, conducted by Cisco, found that only 8% of organizations fall into the top tier of preparedness for AI-era threats.

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Apple has reported that a zero-day vulnerability, identified as CVE-2026-86950, is actively being exploited in targeted attacks. The company described the exploitation as highly sophisticated, indicating a significant level of attacker capability. This out-of-bounds write flaw affects Apple products, though specific affected versions or devices were not detailed in the announcement.

Acronis Backup Flaw Exploited Before CVE Publication
The Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) was exploited two days before its official CVE publication date. A second major catalogue now lists it as exploited.

CVE-2024-24112 SQL Injection in exrick xmall Exploited
CVE-2024-24112, an SQL injection vulnerability in exrick xmall, was listed as exploited in the VulnCheck KEV catalogue on September 14, 2026. It remains absent from CISA and EUVD catalogues.

Car Rental System SQL Injection Flaw Added to VulnCheck KEV
CVE-2022-32025, an SQL injection vulnerability in the Car Rental Management System Project, was added to the VulnCheck Known Exploited Vulnerabilities catalogue. This follows public exploitation reports from September 14, 2026.

CVE-2015-20122 Exploited Same Day as Publication
A SQL injection vulnerability, CVE-2015-20122, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

SQL Injection Flaw Exploited Same Day CVE Was Published
CVE-2023-54400, an SQL injection vulnerability, was reported as exploited on the same day its CVE record was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA KEV or EUVD.

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Attackers have been exploiting two zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to gain root access, deploy web shells, and infiltrate internal networks. Citrix confirmed the active exploitation of both flaws and released security updates to address them.

Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services
Attackers have exploited two critical zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances, designated CVE-2026-88771 and CVE-2026-88772, to compromise government agencies, financial services firms, educational institutions, and legal and professional services organizations across North America and Europe. The exploitation campaign began in early September, weeks…

CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three distinct vulnerabilities within the Linux kernel, one of which is rated critical. These security issues were added to CISA's catalog last week, with severity ratings ranging from medium to critical. Federal agencies have been mandated to apply available security…

Intent injection attacks are a new worry for AI-native 6G networks
Researchers from the University of Ottawa and Nokia Bell Labs have identified a new class of threat, termed adversarial intent injection, targeting AI-native 6G networks that utilize intent-based networking (IBN). This attack vector exploits the abstraction inherent in IBN systems, where operators define desired outcomes and software translates these into network policies. The researchers…

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal civilian executive branch (FCEB) agencies address these flaws by September 21, 2026. This directive, issued under Binding Operational Directive (BOD) 22-01, aims to mitigate significant risks posed by actively…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
CenterPoint Energy, a Texas-based utility provider, has confirmed a data breach following claims by an unnamed hacker of having stolen 7.49 million customer records. The company acknowledged the incident but did not immediately provide details on the scope or nature of the compromised data.

WordPress Amelia Plugin Flaw Exploited Before CVE Publication
A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.

Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEV
A Linux kernel vulnerability, CVE-2026-46331, has been confirmed as exploited, but remains absent from the US federal CISA Known Exploited Vulnerabilities (KEV) catalogue.
CVE-2026-84434 Exploited Before Publication, No Patch Window
A critical vulnerability, CVE-2026-84434, was reported as exploited on September 18, 2026, one day before its official publication. This flaw has no patch window and is listed in the VulnCheck KEV but not in CISA KEV or EUVD.

CVE-2017-20284 Exploited Same Day as Publication
A path traversal vulnerability, CVE-2017-20284, was reported as exploited on the same day it was published. The flaw is listed in the VulnCheck KEV catalogue but not in CISA or EUVD catalogues.

Acronis Backup Flaw Exploited Before CVE Publication
The Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) was reported as exploited two days before its official CVE publication date, leaving no patch window for affected organizations.

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Cisco has confirmed that attackers are actively exploiting a zero-day SQL injection vulnerability, tracked as CVE-2026-76461, in its Secure Email Gateway appliances. The company's Product Security Incident Response Team became aware of the exploitation in September 2025 and has since provided indicators of compromise for organizations to check for potential breaches.

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Security researchers have reportedly leveraged Anthropic's Claude Opus 5 to assist in chaining two distinct vulnerabilities, leading to the compromise of OpenAI staff accounts for ChatGPT and Codex, and subsequently gaining access to an internal OpenAI code repository. The incident was described as a security research effort conducted by three researchers at the firm Hacktron.

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing
A new attack technique, dubbed "BragJack" by its discoverer, security researcher Gal Weizman of Forever Security, can hijack AI assistants embedded in popular browsers using a single malicious browser extension. The proof-of-concept demonstrated the technique against five Chromium-based browsers or browser assistants: Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon,…

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
Three researchers from Hacktron successfully exploited a vulnerability in the Discourse forum used by OpenAI, gaining unauthorized access to staff accounts for ChatGPT and Codex. The attack, which took less than 72 hours from initial discovery to accessing an internal OpenAI code repository, highlighted risks associated with shared single sign-on (SSO) systems.

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
The cybersecurity landscape is experiencing a significant surge in reported software vulnerabilities, a phenomenon that experts attribute to the increasing use of artificial intelligence in bug discovery. This "vulnerability explosion" is already underway, driven by broadly available AI tools, even as discussions continue about a potential slowdown in AI development.

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released a patch for a critical vulnerability in its Access Rights Manager (ARM) software. The flaw, designated CVE-2026-28299, enables unauthenticated remote code execution. This issue stems from the presence of a hard-coded static key within the software. All versions of ARM preceding 2026.2.1 are affected by this vulnerability.

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical pre-authentication remote code execution (RCE) vulnerability in the Orkes Conductor workflow orchestration platform is reportedly being actively exploited in the wild. The flaw, identified as CVE-2026-58138, carries a CVSS v3.1 score of 9.8 and a CVSS v4 score of 9.3, indicating its severe impact and ease of exploitation. Security researchers at Fortinet are credited with reporting…

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that these flaws are being actively exploited in the wild. This advisory highlights the immediate threat posed by these specific kernel issues to systems running the Linux operating system.

Cisco Zero-Day Highlights API Endpoint Authentication Issues
A critical authentication bypass vulnerability, designated CVE-2026-76460, has been reported in Cisco's Identity Services Engine (ISE). The flaw has been assigned a maximum CVSS score of 10.0, indicating its severe potential impact. This zero-day issue reportedly allows for an authentication bypass, highlighting significant concerns regarding API endpoint security within the affected product.

Researchers use AI to find widespread software decoder flaw
Cybersecurity researchers have identified a widespread vulnerability in popular software decoders that could lead to remote code execution and data theft across major internet platforms, enterprise services, and web frameworks. The flaw, dubbed "HEIF Heist," exploits memory corruption errors when processing specially crafted image files, potentially allowing attackers to bypass application…

Gyazo Data Breach Exposes 23 Million User Records
Helpfeel, the Japanese software company behind the Gyazo image-sharing service, has confirmed a data breach that exposed approximately 23.62 million user records. The unauthorized access occurred on September 11, 2026, when an attacker exploited a vulnerability in Gyazo's image upload server, allowing them to execute malicious commands.

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress has released patches addressing a new set of vulnerabilities within its core software. One of these flaws, dubbed "Click2Shell" by the reporting security firm pwn.ai, could enable a logged-in administrator to inadvertently install a theme from the official WordPress.org directory simply by opening a specially crafted web link, without requiring explicit user interaction to confirm…

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Recent reports highlight several significant developments in the cybersecurity landscape, including the sentencing of a ransomware developer, a novel AI-driven attack dubbed "Plugin4Shell," and a critical vulnerability affecting SAP systems. These incidents underscore the diverse and evolving threats faced by organizations and individuals alike, ranging from traditional criminal enterprises to…