vulnerability New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android A newly discovered Linux kernel vulnerability, dubbed "Bad Epoll" (CVE-2026-46242), allows unprivileged users to gain root access on systems, including Android devices. The flaw, a "use-after-free" bug, was identified by… The Hacker News · Jul 3, 2026 High CVE-2026-46242CVE-2026-43074CVE-2026-31431USUKlinuxkernelepoll
vulnerability Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution The DuneSlide vulnerabilities enable zero-click prompt injection attacks that escape Cursor's sandbox and execute arbitrary code on the underlying operating system. The post Critical Cursor AI Code Editor Flaws Could Lea… SecurityWeek · Jul 3, 2026 High CVE-2026-50548CVE-2026-50549
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
vulnerability CubeSpace CW0057 Reaction Wheel This CISA advisory details a vulnerability in CubeSpace CW0057 Reaction Wheels, specifically prior to version 5.0.20, which allows an attacker with physical access to upload malicious firmware. The vulnerability stems fr… CISA Advisories · Jul 2, 2026 Low CVE-2026-13743ZXfirmwarecryptographysecure boot
vulnerability ST Engineering iDirect iQ-Series Terminals ST Engineering iDirect has issued a security advisory regarding vulnerabilities in its iQ-Series Terminals, specifically versions through 4.5.2.1. These vulnerabilities allow unauthorized access to device information, in… CISA Advisories · Jul 2, 2026 High CVE-2026-38059CVE-2026-38057USapiauthenticationcsrf
vulnerability Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability A PoC exploit has been available since public disclosure, and the first exploitation attempts were observed last week. The post Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability appeared first on Securi… SecurityWeek · Jul 2, 2026 Medium CVE-2026-20230
vulnerability CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659). The post CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability appeared first on Se… SecurityWeek · Jul 2, 2026 Critical CVE-2026-45659
vulnerability Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? This article discusses a security vulnerability discovered in Fortinet’s FortiBleed, a tool designed to securely dispose of sensitive data. A researcher identified a flaw allowing unauthorized access to sensitive data, h… Graham Cluley · Jul 1, 2026 High vulnerabilityfortinetsecurity
vulnerability Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic Adobe has released critical security patches for vulnerabilities in both ColdFusion and Adobe Campaign Classic, addressing flaws with CVSS scores of up to 10.0. These vulnerabilities could allow for remote code execution… The Hacker News · Jul 1, 2026 Critical CVE-2026-48276CVE-2026-48283CVE-2026-48277adobevulnerabilitycode execution
vulnerability Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts A critical remote code execution (RCE) vulnerability, CVE-2026-8037, in Progress Kemp LoadMaster is currently being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary commands on vulnerabl… The Hacker News · Jul 1, 2026 Critical CVE-2026-8037CVE-2024-1212rcecommand injectionload balancer
vulnerability Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution. The post Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities appeared first on SecurityWee… SecurityWeek · Jul 1, 2026 CVE-2026-48286CVE-2026-48276CVE-2026-48277
vulnerability Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack Citrix urges customers to patch NetScaler after fixing six vulnerabilities, including the HTTP/2 Bomb flaw and a high-severity CitrixBleed-style information disclosure bug. The post Citrix Patches NetScaler Vulnerabiliti… SecurityWeek · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655
vulnerability Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and S… SecurityWeek · Jul 1, 2026
vulnerability Google Patches 382 Chrome Vulnerabilities Fifteen of the newly patched flaws have been rated ‘critical’ and 67 have been rated ‘high severity’. The post Google Patches 382 Chrome Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jul 1, 2026 High
vulnerability Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service This article details six newly discovered vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway software, potentially allowing for denial-of-service attacks and arbitrary file reads. The vulnerabilities, ranging… The Hacker News · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655samlhttp2memory
vulnerability Schneider Electric EcoStruxure IT Data Center Expert This report details a vulnerability discovered in Schneider Electric’s EcoStruxure IT Data Center Expert software, specifically versions up to 9.1.1. The vulnerability, classified as CWE-611, is an Improper Restriction o… CISA Advisories · Jun 30, 2026 Medium CVE-2026-8045FRxmlcwe-611data center
vulnerability StoneFly Storage Concentrator This report details a critical vulnerability affecting StoneFly Storage Concentrator versions prior to 8.0.4.29, exposing the system to significant risks including unauthorized access, command execution, and data theft.… CISA Advisories · Jun 30, 2026 Critical CVE-2026-56415CVE-2026-55721CVE-2026-50040UScredentialcommand injectionsql injection
vulnerability XZ Utils vulnerability impacting B&R Products This advisory details a critical vulnerability (CVE-2025-31115) affecting versions of XZ Utils used in B&R Industrial Automation products, specifically the PPC3100, C50, C80, FT50, MT50, T30, T80, and T50. The vulnerabil… CISA Advisories · Jun 30, 2026 Critical CVE-2025-31115CHxzmemory corruptionheap
vulnerability Delta Electronics DVP12SE PLC This advisory details a critical vulnerability in Delta Electronics’ DVP12SE PLC, exposing it to unauthorized remote access and control. The PLC’s Modbus TCP service lacks authentication, allowing attackers to potentiall… CISA Advisories · Jun 30, 2026 Critical CVE-2026-12819CVE-2026-12818TWplcmodbusiot
vulnerability Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M This advisory details a vulnerability (CVE-2025-53816, CVE-2025-53817, CVE-2025-55188, CVE-2025-11001) within the Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M software. The vulnerability, a heap-based buffer o… CISA Advisories · Jun 30, 2026 High CVE-2025-53816CVE-2025-53817CVE-2025-55188JPbuffer overflowheapdenial of service