vulnerability Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code Two unpatched vulnerabilities in Kaltura's HTML5 video player library (mwEmbed) allow remote attackers to read arbitrary files and execute code on a server, without requiring authentication. These flaws stem from unsafe… The Hacker News · 4d ago High CVE-2026-19913CVE-2026-19912unpatcheddeserializationremote code execution
vulnerability Chrome 152 Patches Over 300 Vulnerabilities Google released Chrome 152, addressing over 300 vulnerabilities, a significant portion of which were identified using internal AI. This update represents a substantial increase in patching activity for Chrome this year,… SecurityWeek · 4d ago High CVE-2026-79282chromevulnerabilitypatch
vulnerability Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively being exploited to deploy cryptocurrency miners. The vulnerability, stemming from default open registration, allows attackers to gain r… The Hacker News · 4d ago Critical CVE-2026-60004remote code executioncryptojackinggit hook
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
vulnerability Multiples vulnérabilités dans OpenSSL (26 août 2026) Multiple vulnerabilities have been discovered in OpenSSL, allowing for denial of service attacks and policy bypasses. These vulnerabilities affect various OpenSSL versions and could be exploited by attackers. Users are a… CERT-FR · 4d ago Medium CVE-2026-14457CVE-2026-18798CVE-2026-54874vulnerabilityopensslsecurity
vulnerability Multiples vulnérabilités dans les produits Veeam (26 août 2026) Multiple vulnerabilities have been discovered in Veeam products, allowing an attacker to compromise data confidentiality and bypass security policies. Veeam has released security bulletins with patches to address these i… CERT-FR · 4d ago Medium CVE-2026-58070CVE-2026-65641vulnerabilitypatchsecurity
vulnerability Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw A vulnerability in NVIDIA's NemoClaw tool, used for deploying AI agents with OpenClaw, allows unauthenticated attackers to poison a large language model's chat template and corrupt the AI agents using it. The issue stems… Dark Reading · 5d ago High aiagentdns rebinding
vulnerability You could've applied all 1,449 Oracle patches and still been hit by this attack A zero-day vulnerability in on-prem SharePoint, stemming from improperly applied patches, is being exploited by attackers. Despite applying 1,449 Oracle patches, attackers successfully leveraged this flaw to gain unautho… The Register · 5d ago High UNzero-dayvulnerabilitysharepoint
vulnerability A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw A vulnerability in NVIDIA NemoClaw allows an attacker to poison an AI model by serving a malicious webpage that can inject hidden instructions into every conversation. The vulnerability stems from a misconfigured Ollama… The Hacker News · 5d ago High CVE-2024-28224aimodel poisoningdns rebinding
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
vulnerability Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability (CVE-2026-75149) in Marimo notebook software allows an attacker to execute arbitrary commands by crafting a malicious notebook file. The vulnerability is addressed in version 0.23.15 and req… The Hacker News · 5d ago High CVE-2026-75149CVE-2026-67618CVE-2026-39987code injectionnotebookmcp
vulnerability Ebyte NE2-D11 A CISA advisory highlights critical vulnerabilities in Ebyte NE2-D11 devices, primarily due to a lack of consistent authentication enforcement and cleartext transmission of sensitive information. The vendor, Ebyte, has n… CISA Advisories · 5d ago High CVE-2026-73125CVE-2026-73809CVE-2026-73839CHvulnerabilityauthenticationencryption
vulnerability FURUNO FA-50 Class B AIS Transponder A vulnerability in FURUNO FA-50 Class B AIS Transponders allows an attacker with credentials to alter device settings. Production of this product has ended, and software updates are no longer provided. Mitigation involve… CISA Advisories · 5d ago Medium CVE-2026-59769CVE-2026-67578vulnerabilityaiscontrol systems
vulnerability PayRange API A critical vulnerability in the PayRange API allows unauthorized access to sensitive device information and potential denial-of-service attacks. The vulnerability stems from a lack of proper authorization on management e… CISA Advisories · 5d ago Critical CVE-2026-18965USCAvulnerabilityicscontrol systems
vulnerability Rently Smart Home Rently Smart Home versions 20.1.0 and earlier are vulnerable to an insufficient credentials issue, potentially allowing an attacker to access sensitive information and override user permissions. Rently has released a pat… CISA Advisories · 5d ago Medium CVE-2026-75960USINvulnerabilitycwe-522industrial control systems
vulnerability Bendix EC80 Brake ECU A critical vulnerability exists in Bendix EC80 Brake ECU firmware, potentially allowing an attacker to disable ABS, steering assist, speedometer, and shifting capabilities, or inject malicious CAN bus traffic. Multiple f… CISA Advisories · 5d ago Critical CVE-2026-67560CVE-2026-68967CVE-2026-71396UNCAfirmwarebuffer overflowcan bus
vulnerability Siemens SIMATIC IoT2050 Advanced A vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed allows unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying ser… CISA Advisories · 5d ago Critical CVE-2026-58115vulnerabilityindustrial control systemsnode-red
vulnerability Zoneminder A critical Remote Code Execution (RCE) vulnerability exists in Zoneminder versions 1.37.48 and 1.38.3, allowing authenticated users to execute arbitrary operating system commands. The vulnerability stems from an Improper… CISA Advisories · 5d ago Critical CVE-2026-76060vulnerabilityrceos command injection
vulnerability CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw CISA has issued a critical three-day patch deadline for a vulnerability in the Perfect 10 plugin for Joomla, which is being actively exploited by attackers. This plugin flaw allows attackers to gain unauthorized access t… The Register · 5d ago Critical CVE-2026-21962joomlavulnerabilityplugin
vulnerability Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Attackers are exploiting two unauthenticated vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain administrator access to vulnerable sites. The vulnerabilities stem from f… The Hacker News · 5d ago High CVE-2026-61979CVE-2026-15981wordpresssamlauthentication