vulnerability Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Multiple critical vulnerabilities have been discovered in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could lead to complete site takeover, allowing attackers to gain administrator access and execute arbitrary code, highlighting a significant… The Hacker News · 1d ago Critical CVE-2026-76581CVE-2026-18431CVE-2026-19632wordpressvulnerabilityplugin
vulnerability Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable A critical balance-handling flaw in the Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026. The vulnerability, initially missed due to a misunderstanding of how the system… The Hacker News · 1d ago High vulnerabilityblockchaincryptocurrency
vulnerability Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Attackers are chaining two PaperCut vulnerabilities – one related to dynamic class loading and another to improper access control – to execute arbitrary code on susceptible instances without authentication. The vulnerabi… The Hacker News · 2d ago High CVE-2026-82078CVE-2026-81578vulnerabilityremote code executionpatch
vulnerability Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth A security researcher discovered two separate root remote code execution (RCE) vulnerabilities in Unitree's G1 and G1 EDU humanoid robots. One vulnerability, accessible via Bluetooth, allows attackers to gain root access… The Hacker News · 2d ago High CVE-2026-76639CVE-2026-76640roboticsrcebluetooth
vulnerability Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL ServiceNow has released security patches for four critical vulnerabilities in its AI Platform, including three rated at 10.0 CVSS, that could allow unauthenticated attackers to execute code, create or modify instance dat… The Hacker News · 2d ago Critical CVE-2026-18885CVE-2026-18886CVE-2026-74820cvssvulnerabilitycode injection
vulnerability Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server A critical security vulnerability in cPanel and WebHost Manager (WHM) allows an authenticated user adding parked or addon domains to execute code as the root user, potentially leading to full server control. While the vu… The Hacker News · 2d ago Critical CVE-2026-65643CVE-2026-58048CVE-2026-58047cpanelvulnerabilityroot
vulnerability PaperCut Releases Emergency Patch for Exploited Zero-Day PaperCut has released an emergency patch for a zero-day vulnerability being actively exploited in its print management solutions. The vulnerability, currently unassigned a CVE, is linked to malware delivery and log delet… SecurityWeek · 2d ago High USCAEUzero-dayvulnerabilitypatch
vulnerability PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions PaperCut has confirmed a zero-day vulnerability is being actively exploited in its print management software, impacting all versions of NG and MF. The company released a patch and urges users to restrict internet access… The Hacker News · 2d ago Critical CVE-2023-27350RUzero-dayprint managementvulnerability
vulnerability Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Next.js has released security patches to address two critical vulnerabilities. The first, a Windows path traversal flaw, allows unauthenticated remote code execution when processing specially crafted AVIF images. The sec… The Hacker News · 3d ago High CVE-2026-75604avifrcelibheif
vulnerability Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers A vulnerability in Amazon Kiro, an AI-powered IDE, allows attackers to steal sensitive data by injecting malicious prompts and leveraging Kiro Powers. This flaw, currently unpatched, could lead to significant data breach… The Hacker News · 3d ago Medium prompt-injectionaiide
vulnerability Xiiaozet LK100W The CISA has issued an advisory regarding critical vulnerabilities in the Xiiaozet LK100W device. Exploitation could allow an attacker to gain full control over the device by leveraging authentication bypass and command… CISA Advisories · 3d ago Critical CVE-2026-78037CVE-2026-78239CVE-2026-76943vulnerabilitycommand injectionauthentication bypass
vulnerability Rockwell Automation OTTO Fleet Manager Rockwell Automation’s OTTO Fleet Manager is vulnerable to a brute-force attack due to a weak password hashing implementation. This allows attackers to potentially compromise stored password hashes, especially if they gai… CISA Advisories · 3d ago High CVE-2026-75112passwordbrute-forcecve
vulnerability Applied Systems Engineering ASE2000 V2 Communications Test Set Applied Systems Engineering’s ASE2000 V2 Communications Test Set versions 2.25 through 2.37 are vulnerable to two separate attacks. The first stems from an improper XML External Entity Reference (CWE-611) due to a Log4Ne… CISA Advisories · 3d ago High CVE-2018-1285CVE-2026-18717log4netxml external entitycertificate validation
vulnerability Mitsubishi Electric Multiple FA Products (Update D) A denial-of-service vulnerability exists in multiple Mitsubishi Electric FA products due to improper validation of input, allowing a remote attacker to cause a DoS condition by sending a specially crafted UDP packet. Thi… CISA Advisories · 3d ago Medium CVE-2025-3511
vulnerability Ebyte NA111-M A series of vulnerabilities have been identified in Ebyte NA111-M devices, primarily related to authentication and configuration management. These flaws allow unauthenticated attackers to access sensitive information, mo… CISA Advisories · 3d ago High CVE-2026-73125CVE-2026-76179CVE-2026-75814CHauthenticationconfigurationvulnerability
vulnerability Mitsubishi Electric CNC Series (Update A) A vulnerability (CWE-1285) exists in Mitsubishi Electric CNC Series (Update A) products, allowing a remote attacker to cause a denial-of-service by sending crafted packets to TCP port 683. This affects a wide range of CN… CISA Advisories · 3d ago Critical CVE-2025-2399cwe-1285cncindustrial control systems
vulnerability Recent Citrix NetScaler Vulnerability Exploited in the Wild A critical Citrix NetScaler vulnerability (CVE-2026-8452) is currently being actively exploited in the wild, prompting CISA to urge immediate action from government agencies. The vulnerability allows for unauthenticated… SecurityWeek · 3d ago High CVE-2026-8452CVE-2026-8451vulnerabilityremote code executionunpatched
vulnerability 'HTTP Terminator' Hunts for Novel Desync Attacks A new open-source tool, dubbed 'HTTP Terminator,' developed by PortSwigger, utilizes AI to automatically discover novel HTTP request smuggling vulnerabilities. The tool identifies previously unknown attack vectors by ana… Dark Reading · 4d ago Medium httpvulnerabilityweb application
vulnerability Adobe and Nvidia Patch Dozens of Vulnerabilities Adobe and Nvidia released patches addressing dozens of security vulnerabilities across their products, including critical flaws that could lead to code execution and data breaches. Nvidia released four advisories focusin… SecurityWeek · 4d ago High vulnerabilitysecurityai
vulnerability CISA Vulnerability Review The CISA Vulnerability Review highlights that many cyberattacks exploit readily available, unpatched software vulnerabilities, emphasizing a need for proactive security improvements rather than reactive patching. The rev… CISA Advisories · 4d ago Info vulnerabilitysecure by designcybersecurity