Joomla iCagenda, Balbooa Forms Flaws Exploited as Zero-Days
CISA adds CVE-2026-48939 and CVE-2026-56291 to KEV after attackers weaponized iCagenda and Balbooa Forms file upload bugs before patches existed. Federal deadline is July 13.
368 articles
CISA adds CVE-2026-48939 and CVE-2026-56291 to KEV after attackers weaponized iCagenda and Balbooa Forms file upload bugs before patches existed. Federal deadline is July 13.
OpenSSH 10.4 fixes eight security vulnerabilities including sftp/scp file redirection bugs and client-side use-after-free. Experimental ML-DSA post-quantum signatures debut.
University researchers found critical security flaws in 281 popular Google Play VPN apps with 2.4 billion installs. 29 apps leak DNS queries, 61 transmit data in cleartext.
Zimbra urges immediate patching for a stored XSS flaw in Classic Web Client that executes malicious code when users open crafted emails. Google TAG reported the vulnerability.
Progress Software tells ShareFile customers to immediately shut down Storage Zone Controllers due to a credible security threat. The company disabled affected accounts while investigating.
Binarly uncovers six vulnerabilities in U-Boot's FIT signature verification present since 2013, affecting millions of BMCs, routers, and IoT devices. Patches exist but downstream adoption lags.
Palo Alto Networks addresses 13 PAN-OS vulnerabilities including CVE-2026-0288 (CVSS 9.2) buffer overflow and CVE-2026-0257 auth bypass under active exploitation by unknown threat actors.
Wiz researchers discover six major AI coding assistants vulnerable to symlink attacks. Malicious repos can trick Claude Code, Cursor, and Amazon Q into writing files outside designated workspaces.
Januscape vulnerability CVE-2026-53359 allows guest VM root users to corrupt host kernel memory and escape to host. First KVM exploit affecting both Intel and AMD architectures simultaneously.
Critical Gitea Docker vulnerability allows full admin access via single X-WEBAUTH-USER header injection. 6,200 exposed instances at risk as attackers begin active scanning.
CISA adds four actively exploited vulnerabilities to KEV catalog including two max-severity Joomla plugin flaws and Adobe ColdFusion CVE-2026-48282. Federal deadline is July 10.
CVE-2026-40138 and CVE-2026-40139 (CVSS 9.2) enable pre-auth bypass in BeyondTrust Remote Support and PRA. Flaws found using Claude AI during internal audit.
Ubiquiti warns of CVE-2026-50746 (CVSS 10.0) and six other critical vulnerabilities affecting UniFi OS devices. 100,000 instances exposed online require immediate patching.
CERT/CC warns of CVE-2026-11405, an undocumented authentication backdoor in Tenda router firmware. The vendor remains unreachable with no fix in sight.
CVE-2026-10134 enables unauthenticated RCE in Langflow OSS through public flows. Attackers can run arbitrary Python on servers via the build endpoint.
JetBrains fixes CVSS 9.8 account takeover bug in Hub and multiple RCE vulnerabilities across IntelliJ, GoLand, and other IDEs. Update immediately.
CVE-2026-20191 in Cisco Catalyst Center allows unauthenticated attackers to read arbitrary files through path traversal. Affects version 3.1+ across hardware appliances and cloud deployments.
Critical authentication bypass in Oracle Payments (CVE-2026-46817) is being actively exploited. Over 900 vulnerable instances exposed online, with attackers achieving system takeover via unauthenticated HTTP requests.
Google releases Chrome 151 fixing 382 vulnerabilities including 15 critical use-after-free and type confusion bugs enabling remote code execution across Windows, macOS, and Linux.
CVE-2026-8451 and five other NetScaler vulnerabilities disclosed this week, with attackers already targeting SAML-configured appliances. Patch now.
CISA confirms ransomware groups are exploiting CVE-2026-33825, a Microsoft Defender privilege escalation flaw leaked in April. Patch urgently if you haven't already.
CVE-2026-46242 exploits a use-after-free race in Linux epoll, giving unprivileged users root access with 99% reliability. Servers and Android devices at risk.
CVE-2026-8037 lets unauthenticated attackers execute root-level commands on Progress Kemp LoadMaster appliances. Exploitation attempts started June 29, same day as PoC publication.
Two CVSS 9.8 vulnerabilities in the popular AI code editor allow zero-click attacks where malicious instructions in external data sources execute arbitrary commands on developer machines.
CVE-2026-45659 lets authenticated attackers with basic Site Member permissions execute arbitrary code on SharePoint servers. CISA added it to KEV after confirming active exploitation.
Seven CVSS 10.0 vulnerabilities in Adobe ColdFusion and Campaign Classic enable unauthenticated RCE. Adobe shifts to twice-monthly security bulletins citing AI-accelerated discovery.
Curl 8.21.0 addresses a record 18 CVEs, including CVE-2026-8932—an mTLS authentication bypass introduced in March 2001. AI tools discovered several of the vulnerabilities.
CVE-2026-20182 allows unauthenticated attackers to inject rogue peers into Cisco SD-WAN fabrics. Active exploitation since May; no workaround available—patch immediately.
CVE-2026-13028, a critical use-after-free in Chrome's WebGL component, scores CVSS 9.6 and allows remote code execution with sandbox escape on Android. Update immediately.
CVE-2026-48558 lets attackers bypass OIDC auth and register as technicians. CISA added it to KEV June 29 after TaskWeaver and Djinn Stealer deployments.
A critical memory corruption flaw in libssh2 lets malicious SSH servers execute code on connecting clients—no credentials needed. PoC dropped June 29.
CVE-2026-50160 in self-hosted Hoppscotch lets attackers overwrite JWT secrets with one HTTP request—no credentials needed. Patch immediately.
CVE-2026-12957 and CVE-2026-12958 enabled code execution and AWS credential theft when developers opened malicious repositories. Patch auto-applied for most users.
CVE-2026-12569 (CVSS 9.3) in PTC Windchill PLM software is being exploited to deploy web shells. First PTC product ever added to CISA KEV catalog.
CVE-2026-46331 in Linux's tc subsystem lets local users poison cached binaries and gain root. Public exploit available within a day of CVE assignment.
CVE-2026-43503 lets attackers corrupt cached binaries through network packet cloning, achieving root without leaving disk traces. Patch immediately.
Island researchers discover Adblock for YouTube extension contains remote-controlled script injection capability that could steal passwords with a single server-side change.
CVE-2026-9862 (CVSS 9.8) in Fortra Core Privileged Access Manager (BoKS) enables unauthenticated command injection via the autoregistration service. Restrict port 6507 access immediately.
CVE-2026-20253 in Splunk Enterprise lets unauthenticated attackers execute code via an unprotected PostgreSQL sidecar. Over 1,400 instances exposed. Patch or disable the service now.
CISA confirms active exploitation of CVE-2025-67038 (CVSS 9.8) in Lantronix EDS5000 serial-to-IP devices. The command injection flaw grants root access. Federal deadline is June 26.
A new class of CI/CD vulnerability affects repositories at Microsoft, Google, Apache, and Cloudflare. A free GitHub account is all attackers need to forge approvals and steal credentials.
Attackers exploit CVE-2026-20230 in Cisco Unified Communications Manager to deploy webshells via Tor-routed automated attacks. Patching alone won't remove existing compromises.
CISA adds three maximum-severity Ubiquiti UniFi OS vulnerabilities to KEV catalog after confirming active exploitation. Federal agencies have until June 26 to patch under BOD 26-04.
CVE-2026-50751 allows unauthenticated VPN access via IKEv1 certificate validation flaw. CISA gave federal agencies three days to patch after linking attacks to ransomware affiliate.
A publicly released exploit targets CVE-2026-50656 in Microsoft Defender's quarantine pipeline. Microsoft confirms the flaw but has no patch timeline yet.
CVE-2026-42824 chained prompt injection, a timing race, and CSP bypass to exfiltrate Outlook emails, OneDrive files, and MFA codes via Microsoft 365 Copilot. Now patched.
CVE-2026-8461 is a heap overflow in FFmpeg's MagicYUV decoder that enables remote code execution via malicious video files. Jellyfin, Kodi, and Nextcloud affected.
CVE-2026-47729 exposes a heap over-read in Squid's FTP parser that leaks HTTP authorization headers and cookies. The bug dates to 1997.