LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

vulnerability news

549 stories · page 5 of 12
vulnerabilityhigh

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply patches for a critical vulnerability, CVE-2026-8452, affecting Citrix NetScaler appliances by Saturday, August 29. This directive, issued under Binding Operational Directive (BOD) 26-04, follows the addition of CVE-2026-8452 to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

vulnerabilitycritical

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the Avada theme for WordPress, tracked as CVE-2026-18431, could allow an unauthenticated attacker to achieve zero-click remote code execution (RCE) on affected websites. The exploit combines six distinct security issues, resulting in a critical severity score of 9.8.

vulnerability

Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released security updates to address three critical vulnerabilities that could allow unauthenticated remote attackers to compromise affected devices. The patches were issued on August 26, 2026, for flaws impacting the UniFi Protect Application, UniFi Talk Application, and UniFi OS.

vulnerability

Four in Five AI Tools Run with No IT Oversight, New Research Finds

A new report indicates that a significant majority of AI tools within enterprise environments operate without IT oversight, contributing to an increasingly risky AI agent ecosystem. The study, conducted by AI security vendor Reco, analyzed anonymized platform telemetry from large enterprises, publicly available Model Context Protocol (MCP) servers, and vulnerability disclosures from the…

CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint analysis by Tenable and SentinelOne reveals that edge infrastructure is a shared attack surface, with both state-sponsored actors and cybercriminals independently targeting the same vulnerabilities and vendors. This convergence challenges the perception that edge device exploitation is primarily a nation-state problem, demonstrating a broader threat landscape.

phishingcritical

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A new phishing-as-a-service (PhaaS) platform, dubbed AnonyMousKIT, is actively being used to automate the theft of Apple ID credentials, which are necessary to bypass the Activation Lock feature on stolen iPhones. The platform leverages advanced AI voice calls to impersonate Apple Support and trick victims into revealing their device passcodes and other sensitive information.

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

A critical vulnerability in Gitea, a self-hosted Git service, is now being actively exploited by attackers, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw, tracked as CVE-2026-60004, is a code injection vulnerability that allows an authenticated user with repository write access to execute arbitrary shell commands on affected servers.

vulnerability

Chrome 152 Patches Over 300 Vulnerabilities

Google has released Chrome 152, an update that addresses over 300 vulnerabilities within the browser. The majority of these security flaws were identified internally by Google, leveraging artificial intelligence (AI) tools for discovery. However, the update also includes patches for high-value vulnerabilities that continue to be found by external security researchers.

CVE-2026-60004

CISA Warns of Exploited Gitea Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding an actively exploited remote code execution (RCE) vulnerability in Gitea, an open-source Git service. The flaw, identified as CVE-2026-60004, was addressed by Gitea developers in late July with the release of version 1.27.1. CISA's alert indicates that the vulnerability is currently being leveraged in…

vulnerability

AI vulnerability discovery scores the highest impact of 20 emerging risks

A recent survey of risk managers, auditors, and senior executives across 316 companies has identified AI-driven cyber vulnerability discovery as the most impactful emerging risk. This finding represents a significant shift from a similar survey conducted three months prior, where this particular risk was not even among the top five.

vulnerability

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

A recently disclosed security vulnerability, dubbed "Nemo(Claw)," allows for the poisoning of large language models (LLMs) within NVIDIA's OpenClaw framework. The reported issue stems from a networking misconfiguration that grants unauthenticated access to the local model server via the Ollama API. This access could enable attackers to introduce malicious data into the models, leading to…

CVE-2024-28224high

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A recent report indicates a significant vulnerability within NVIDIA NemoClaw that could enable a malicious webpage to compromise a local AI agent. The core of the issue lies in the ability of an attacker to modify the AI model's chat template, effectively injecting hidden instructions that would then influence all subsequent interactions with the model. This form of "poisoning" could lead to…

CVE-2026-61979

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

Reports indicate that WordPress websites are currently being targeted through the exploitation of two authentication bypass vulnerabilities found in the MiniOrange SAML 2.0 SSO plugin. These vulnerabilities have been assigned the identifiers CVE-2026-61979 and CVE-2026-15981. The active targeting suggests that attackers are leveraging these flaws to gain unauthorized access to affected…

vulnerabilitycritical

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

The Australian Cyber Security Centre (ACSC) has issued a warning regarding the active exploitation of a critical vulnerability, CVE-2026-63077, affecting TeamCity On-Premises servers. This flaw allows unauthenticated attackers with HTTP(S) access to a TeamCity server to bypass authentication and execute arbitrary operating system commands. All versions of TeamCity On-Premises are impacted.

vulnerability

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day patching directive for a critical Oracle vulnerability, CVE-2026-21962, which has been actively exploited in the wild. This is CISA's most urgent deadline, requiring federal civilian executive branch (FCEB) agencies to apply patches by August 27.

CVE-2026-73570

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra Collaboration Suite (ZCS) instances have been compromised through exploitation of CVE-2026-73570, a code injection vulnerability. The Shadowserver Foundation, a nonprofit security organization, reported the rising number of compromises after initially identifying 155 affected instances on August 20.

CVE-2026-21962

CISA Warns of Exploited Oracle WebLogic Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding an actively exploited vulnerability in Oracle WebLogic Server. The flaw, identified as CVE-2026-21962, is reportedly being widely leveraged by various threat actors targeting WebLogic installations.

CVE-2026-21962critical

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw affecting Oracle WebLogic Server and Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) catalog. The agency cited evidence of active exploitation for this maximum-severity vulnerability.

CVE-2026-69414

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

A zero-day elevation-of-privilege vulnerability, tracked as CVE-2026-69414 and dubbed "ShieldBreak," has been discovered in the Microsoft Malware Protection Engine, which is integral to Microsoft Defender. This flaw allows a local attacker with low privileges to escalate to SYSTEM-level access on affected Windows systems.

CVE-2026-73570

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

A recently exploited vulnerability in Zimbra, identified as CVE-2026-73570, has prompted a directive from the Cybersecurity and Infrastructure Security Agency (CISA) for federal agencies to apply patches within a three-day window. The flaw is reported to enable a complete takeover of a user's communications, underscoring the critical nature of the exploit and the urgency of mitigation.

vulnerability

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers, also marketed as the GigaSpire 7u10txg, allows remote, unauthenticated attackers to create port-forwarding rules that expose internal network devices to the public internet. The flaw, tracked as CVE-2026-75501, is a missing authentication issue affecting devices running EXOS/6.6.47 firmware.

vulnerabilitycritical

Hackers target WordPress sites in miniOrange auth bypass attacks

Threat actors are actively attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to forge SAML responses and gain administrative access to affected WordPress sites.

vulnerabilityhigh

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The deadline for Federal Civilian Executive Branch (FCEB) agencies to secure their systems was set for August 24.

vulnerability

Rethinking Application Security for the AI Era

Recent analysis suggests that the advent of artificial intelligence (AI) is significantly accelerating the window between the public disclosure of a software vulnerability and its active exploitation by malicious actors. This compressed timeline necessitates a fundamental shift in how enterprises approach application security, moving beyond traditional reactive patching strategies to more…

vulnerability

Slovakia Warns of Cyber Risks in Road Speed Cameras

Slovakia's National Security Authority (NBÚ) has issued a warning regarding significant cybersecurity risks associated with several types of road speed cameras, identifying them as potential threats to public networks and sensitive vehicle data. The alert, prompted by a request from the Interior Ministry, focuses on connected devices that collect vehicle information, communicate with other…

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

A significantly upgraded version of the ToxicPanda Android malware, dubbed ToxicPanda 2.0, has expanded its targeting to 349 financial applications across 16 countries, a substantial increase from the 16 applications it previously targeted. Researchers at Zimperium's zLabs team documented the new variant, noting its command set has grown to 167 remote instructions.

nasacritical

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical vulnerability has been identified in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit. The flaw, rated with a CVSS score of 9.4 and tracked as GHSA-p9r8-2q67-fp86, allowed unauthenticated execution of commands on spacecraft instruments. The issue has been addressed in AIT-GUI version 2.5.2.

CVE-2026-73570critical

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Zimbra Collaboration Suite (ZCS), identified as CVE-2026-73570, to its Known Exploited Vulnerabilities (KEV) catalog. This move mandates that all U.S. federal civilian executive branch (FCEB) agencies address the flaw by August 24, 2026, to protect their networks, and private organizations…

vulnerability

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch two actively exploited vulnerabilities in TrueConf Server, a video conferencing platform developed in Russia. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, were added to CISA's Known Exploited Vulnerabilities catalog on Thursday, indicating their use in real-world attacks.…

vulnerability

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that leverages a legitimate Microsoft Defender driver, BTR.sys (Boot Time Removal Tool), to delete security software at boot time. The technique reportedly does not exploit a software flaw but rather weaponizes the driver's intended functionality. This method is said to affect Windows systems from Windows 7 up to Windows 11 25H2.

vulnerability

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

A recent report highlighted several security incidents and developments, including a "Zombie Card" attack, a distributed denial-of-service (DDoS) attack against Threema, and the emergence of the Evooo1Bot Linux botnet. Additionally, T-Mobile reportedly severed a cable in an attempt to thwart attackers, while GitHub denied that artificial intelligence was responsible for a specific bug.…

vulnerabilitycritical

Six Maximum-Severity Flaws Found in Cisco Products

Cisco has released a series of security patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, with six of these flaws receiving the maximum CVSS score of 10.0. The vulnerabilities were discovered during an internal security review conducted by Cisco's engineering team, which included the use of advanced AI models. As of the announcement on August…

vulnerabilitycritical

Critical Isolated-vm Vulnerability Leads to RCE on Host

A critical vulnerability has been reported in the `isolated-vm` library, a Node.js module designed for running untrusted code in a sandboxed environment. The flaw, described as a type confusion bug, could allow an attacker to achieve remote code execution (RCE) on the host system by escaping the V8 sandbox and hijacking the control flow of the host process.

vulnerabilityhigh

CISA orders feds to patch actively exploited TrueConf Server flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to immediately patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform, which are reportedly being actively exploited in the wild. The directive, issued on Thursday, August 21, 2026, requires all U.S. Federal Civilian Executive Branch (FCEB) agencies to secure…

CVE-2026-69836critical

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has issued a patch for a critical remote code execution vulnerability, identified as CVE-2026-69836, within its Entra ID cloud identity service. The company confirmed that the vulnerability has been actively exploited in the wild. Entra ID, previously known as Azure Active Directory, is a core Microsoft service responsible for authenticating user logins and managing access to…

vulnerability

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has confirmed it has patched a critical vulnerability in its Entra ID identity and access management (IAM) platform, previously known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, has a maximum severity rating and has been exploited in active attacks.

breach

SickKids data breach exposes employee and job applicant info

The Hospital for Sick Children (SickKids) has disclosed a cybersecurity incident that exposed the personal information of some current and former employees, as well as job applicants. The Toronto-based pediatric hospital confirmed that the breach originated from a vulnerability in a third-party software application used by SickKids and other organizations.

CVE-2026-19478critical

GitLab Critical GraphQL Flaw Actively Exploited

GitLab has confirmed that a critical vulnerability in its GraphQL API, identified as CVE-2026-19478, is being actively exploited in the wild. The flaw, which carries a CVSS score of 9.4, allows unauthenticated attackers to remotely modify or delete public projects and associated user data on self-managed GitLab instances.

CVE-2026-73570critical

Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

CERT Polska has confirmed active exploitation of a critical unauthenticated remote code execution vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. The flaw, which allows attackers to execute arbitrary shell commands with the privileges of the `zimbra` user, was patched by Zimbra on July 20, 2026, in version 10.1.20. Active exploitation was confirmed less than a month…

vulnerability

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in TrueConf Server, an on-premises video conferencing and unified communications platform, to its Known Exploited Vulnerabilities (KEV) catalog. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, both carry high CVSS scores, indicating their severity.

vulnerability

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft has released 22 new security patches, addressing a range of vulnerabilities across its product line. The majority of these fixes target issues related to remote code execution, privilege escalation, and information disclosure. This regular update cycle is a standard practice for major software vendors to maintain the security posture of their offerings.

CVE-2026-19490critical

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has issued an urgent advisory for customers to patch two critical vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including a severe authentication bypass flaw identified as CVE-2026-19490. The company, through its parent Cloud Software Group, strongly recommends that users review the official security bulletin and upgrade affected appliances immediately.

cisahigh

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive urging organizations to immediately patch critical vulnerabilities found in TrueConf software. This advisory comes as the Head Mare hacktivist group is reportedly actively exploiting these flaws to facilitate the distribution of PhantomCore malware. The directive underscores the urgency for all entities…

CVE-2026-12569critical

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

The Cl0p ransomware group claims to have compromised over 40 organizations by exploiting a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) software. This vulnerability, identified as CVE-2026-12569, is a remote code execution (RCE) flaw with a CVSS score of 9.3, stemming from the deserialization of untrusted data. It affects all CPS versions and…

CVE-2026-19478critical

GitLab Code Injection Vulnerability Actively Exploited

A critical code injection vulnerability in GitLab, tracked as CVE-2026-19478, is reportedly being actively exploited in the wild. The flaw was publicly disclosed recently, and exploitation attempts have been observed shortly thereafter. This vulnerability allows unauthenticated attackers to manipulate or remove public projects and their associated data, though specific conditions must be met…

CVE-2026-69836high

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft has issued a warning regarding a critical security flaw in its Entra ID cloud-based identity and access management service, which has reportedly been exploited in the wild. The vulnerability, identified as CVE-2026-69836, carries a maximum CVSS score of 10.0, indicating its severe potential impact. Despite the active exploitation, Microsoft has stated that no immediate customer…

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Cisco has issued an advisory regarding five vulnerabilities discovered in its Secure Workload Software, a micro-segmentation tool previously known as Tetration. These flaws, identified during an internal security review that included the use of advanced AI models, range in severity from critical to high. Cisco confirmed that it has not observed any malicious exploitation of these…

supply chain attackhigh

Hackers poison arrayref Rust crate to push infostealer malware

A widely used Rust library, arrayref, was compromised through its maintainer account to distribute infostealer malware during compilation, affecting developers' systems. The attack, which occurred on August 20, also impacted two other crates, append-only-vec and internment, within a 23-minute window.