Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, a ... Read more
Published Date: Aug 29, 2026 (3 hours, 25 minutes ago)Vulnerabilities has been mentioned in this article.
CVE-2026-82222 CVE-2026-76581 CVE-2026-18431 CVE-2026-19632 CVE-2026-19598 CVE-2026-58231Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortio ... Read more
Published Date: Aug 28, 2026 (22 hours, 19 minutes ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2020-1472Threat actors are constantly developing new attack schemes — from OAuth token theft to attacks on AI agents — but the classics never quite leave their playbook. On any given day, an employee may recei ... Read more
Published Date: Aug 28, 2026 (1 day, 2 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2025-24993Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional ha ... Read more
Published Date: Aug 28, 2026 (1 day, 2 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-82078 CVE-2026-81578 CVE-2026-58231The Good | Authorities Launch New Operations Against Cybercrime Networks & Supply Chain Attackers Operation Jackal IV, coordinated by INTERPOL across 22 nations, has led to the arrest of 58 individual ... Read more
Published Date: Aug 28, 2026 (1 day, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-36425The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports th ... Read more
Published Date: Aug 28, 2026 (1 day, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-66384 CVE-2026-58231 CVE-2026-53362 CVE-2024-28000 CVE-2023-49105ServiceNow has patched four security vulnerabilities affecting its AI Platform and Now Platform. Three of them received the maximum CVSS v4.0 score of 10.0.The three most serious flaws are especially ... Read more
Published Date: Aug 28, 2026 (1 day, 4 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-74820 CVE-2026-6876 CVE-2026-18886 CVE-2026-18885Op internet zijn ruim achtduizend Gitea-servers te vinden, waaronder meer dan tweehonderd in Nederland, die een actief misbruikt beveiligingslek bevatten, zo laat The Shadowserver Foundation vandaag o ... Read more
Published Date: Aug 28, 2026 (1 day, 6 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-60004Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root ... Read more
Published Date: Aug 28, 2026 (1 day, 7 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-76640 CVE-2026-76639 CVE-2026-58231Het Nationaal Cyber Security Centrum (NCSC) waarschuwt organisaties dat er een grote kans is op misbruik van een kritieke kwetsbaarheid in Microsoft Exchange en dit tot grote schade kan leiden. Organi ... Read more
Published Date: Aug 28, 2026 (1 day, 7 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-62911Softwarebedrijf ServiceNow waarschuwt voor meerdere kritieke kwetsbaarheden in het eigen AI-platform waardoor ongeauthenticeerde aanvallers code op het platform kunnen uitvoeren en toegang tot data ku ... Read more
Published Date: Aug 28, 2026 (1 day, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-74820 CVE-2026-18886 CVE-2026-18885 CVE-2026-6875ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unaut ... Read more
Published Date: Aug 28, 2026 (1 day, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-74820 CVE-2026-6876 CVE-2026-18886 CVE-2026-18885 CVE-2026-58231 CVE-2026-6875This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international ... Read more
Published Date: Aug 28, 2026 (1 day, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the a ... Read more
Published Date: Aug 28, 2026 (1 day, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-74233 CVE-2026-74232 CVE-2026-58231 CVE-2026-66747Aanvallers hebben een Filipijns nucleair onderzoeksinstituut door middel van een bekende kritieke kwetsbaarheid in ownCloud weten te hacken, zo meldt cybersecuritybedrijf Hunt.io. Bij de aanval zou ne ... Read more
Published Date: Aug 28, 2026 (1 day, 10 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2023-49105cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vuln ... Read more
Published Date: Aug 28, 2026 (1 day, 10 hours ago)Vulnerabilities has been mentioned in this article.
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The comp ... Read more
Published Date: Aug 28, 2026 (1 day, 11 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2023-27350Een beveiligingslek in een IPv6-subsysteem van de Linux-kernel wordt misbruikt bij aanvallen, zo waarschuwt het Amerikaanse cyberagentschap CISA. Via de kwetsbaarheid (CVE-2026-53362) kan een aanvalle ... Read more
Published Date: Aug 28, 2026 (1 day, 12 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-53362Acknowledgements: Special thanks to Tanner Filip, Jai Minton, Max Rogers, Ben Nahorney, Lindsey Welch, Aaron Deal, Dray Agha, Lindon Wass, Michael Elford, and Craig Sweeney for their contributions to ... Read more
Published Date: Aug 28, 2026 (1 day, 16 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2024-55956 CVE-2023-39143Next.js has released security updates for two critical vulnerabilities that can lead to unauthenticated remote code execution.The two vulnerabilities are separate and affect different deployment scena ... Read more
Published Date: Aug 28, 2026 (1 day, 17 hours ago)Vulnerabilities has been mentioned in this article.
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior ... Read more
Published Date: Aug 27, 2026 (2 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2026-53362Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable ... Read more
Published Date: Aug 27, 2026 (2 days, 4 hours ago)Vulnerabilities has been mentioned in this article.
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.The rest of the week gets stranger: botnets borrowi ... Read more
Published Date: Aug 27, 2026 (2 days, 4 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-63520 CVE-2026-58231 CVE-2026-55040Vulnerabilities in dool software CVE ID CVE-2026-56651 Publication date 27 August 2026 Vendor scottchiefbaker Product dool Vulnerable versions All through 1.3.8 Vulnerability type (CWE) Improper Link ... Read more
Published Date: Aug 27, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate dat ... Read more
Published Date: Aug 27, 2026 (1 day, 12 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-65105 CVE-2026-58231 CVE-2026-10591 CVE-2026-41613 CVE-2026-35603 CVE-2026-25725Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes ... Read more
Published Date: Aug 27, 2026 (1 day, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2026-36425donderdag 27 augustus 2026, 10:27 door Redactie, 2 reactiesLaatst bijgewerkt: Vandaag, 10:31 Een belangrijke kwetsbaarheid in Microsoft SharePoint die remote code execution (RCE) mogelijk maakt, en wa ... Read more
Published Date: Aug 27, 2026 (1 day, 11 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-63520 CVE-2026-55040The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability imp ... Read more
Published Date: Aug 27, 2026 (1 day, 12 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2026-8452 CVE-2022-0995 CVE-2021-23758 CVE-2019-1068 CVE-2015-5287 CVE-2015-3246On August 26, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitat ... Read more
Published Date: Aug 27, 2026 (1 day, 14 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-8452 CVE-2022-0995 CVE-2021-23758 CVE-2019-1068 CVE-2015-5287 CVE-2015-3246A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. It is the sha ... Read more
Published Date: Aug 26, 2026 (2 days, 4 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-15409 CVE-2026-1340 CVE-2026-1281 CVE-2026-24858 CVE-2025-59718 CVE-2024-47575 CVE-2024-8963 CVE-2024-8190 CVE-2024-24919 CVE-2024-3400 CVE-2023-42793 CVE-2023-34133 CVE-2023-34132 CVE-2023-34124The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a ... Read more
Published Date: Aug 26, 2026 (2 days, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19913 CVE-2026-19912 CVE-2026-58231Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in self-hosted Git service Gitea, zo waarschuwt het Amerikaanse cyberagentschap CISA. Gitea, gebruikt voor de ontwikkeling van software, ... Read more
Published Date: Aug 26, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
woensdag 26 augustus 2026, 10:12 door Redactie, 1 reactiesLaatst bijgewerkt: Vandaag, 11:29 Een groot aantal WordPress-sites is via een kritieke kwetsbaarheid in vertaalplug-in TranslatePress door ong ... Read more
Published Date: Aug 26, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19632The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability ... Read more
Published Date: Aug 26, 2026 (2 days, 7 hours ago)Vulnerabilities has been mentioned in this article.
Vulnerability in GNU wget software CVE ID CVE-2026-16599 Publication date 25 August 2026 Vendor GNU Product wget Vulnerable versions All through 1.25.0 Vulnerability type (CWE) Unchecked input for loo ... Read more
Published Date: Aug 25, 2026 (2 days, 20 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-16599August 25, 2026CISA has added multiple vulnerabilities affecting TrueConf Server, Zimbra Collaboration Suite and Oracle HTTP Server/WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities ... Read more
Published Date: Aug 25, 2026 (2 days, 20 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836 CVE-2026-72530 CVE-2026-72529 CVE-2026-73570 CVE-2026-21962Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden ... Read more
Published Date: Aug 25, 2026 (2 days, 21 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2024-28224Gameontwikkelaar Konami heeft een kritieke kwetsbaarheid in het spel Metal Gear Online 3 gepatcht waardoor aanvallers code op het systeem van spelers konden uitvoeren als die in een lobby van de aanva ... Read more
Published Date: Aug 25, 2026 (2 days, 22 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19874Netwerkfabrikant DrayTek heeft meerdere kwetsbaarheden in switches en access points verholpen, waaronder een aantal die aanvallers commando's als root laten uitvoeren en remote code execution mogelijk ... Read more
Published Date: Aug 25, 2026 (2 days, 22 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-71933 CVE-2026-71921 CVE-2026-71914Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted noteboo ... Read more
Published Date: Aug 25, 2026 (2 days, 22 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-75149 CVE-2026-58231 CVE-2026-67618 CVE-2026-39987Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of A ... Read more
Published Date: Aug 25, 2026 (3 days ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836 CVE-2026-11405Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as an ... Read more
Published Date: Aug 25, 2026 (3 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2026-61979 CVE-2026-58231 CVE-2026-15981Aanvallers maken misbruik van een kritieke kwetsbaarheid in Oracle HTTP Server en de Oracle Weblogic Server Proxy-plug-in waardoor systemen op afstand zijn over te nemen. De CVSS-impactscore van het b ... Read more
Published Date: Aug 25, 2026 (2 days, 21 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-21962The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnera ... Read more
Published Date: Aug 25, 2026 (2 days, 17 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2026-21962 CVE-2020-14882 CVE-2020-2551 CVE-2017-10271A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh a ... Read more
Published Date: Aug 24, 2026 (3 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
Aanvallers hebben de afgelopen weken honderden Zimbra-mailservers gehackt, waarbij gebruikt werd gemaakt van een kwetsbaarheid waarvoor sinds 20 juli een beveiligingsupdate beschikbaar is. Dat meldt T ... Read more
Published Date: Aug 24, 2026 (3 days, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-73570Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker ... Read more
Published Date: Aug 24, 2026 (3 days, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-15571 CVE-2026-18963 CVE-2026-58231 CVE-2026-17059Vulnerabilities in KAON PG5298A/PG5298B routers CVE ID CVE-2025-63080 Publication date 24 August 2026 Vendor KAON Product PG5298APG5298B Vulnerable versions PG5298A: All before 3.0.82PG5298B: All befo ... Read more
Published Date: Aug 24, 2026 (3 days, 4 hours ago)Vulnerabilities has been mentioned in this article.
August 24, 2026Microsoft has disclosed CVE-2026-69836, a critical remote-code-execution vulnerability affecting Microsoft Entra ID.The vulnerability is classified as CWE-502 — Deserialization of Untru ... Read more
Published Date: Aug 24, 2026 (3 days, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836TeamCity-servers die zich in Australië bevinden zijn het doelwit van aanvallen, zo meldt de Australische inlichtingendienst ASD. De aanvallers maken misbruik van een kritieke kwetsbaarheid aangeduid a ... Read more
Published Date: Aug 24, 2026 (3 Tage, 1 Stunde ago)Vulnerabilities has been mentioned in this article.
CVE-2026-63077