vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
vulnerability Critical UniFi OS bug lets hackers gain root without authentication A critical vulnerability in UniFi OS Server versions 5.0.6 and earlier allows attackers to gain root access without authentication by chaining three previously identified flaws. This vulnerability, detailed by Bishop Fox… BleepingComputer · Jun 8, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910remote code executionroot accessauthentication bypass
vulnerability Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups Check Point has identified and warned of a critical vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products, allowing unauthenticated attackers to bypass password authentication when using the… The Hacker News · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752GLikev1vpncertificate
vulnerability Check Point links VPN zero-day attacks to Qilin ransomware gang Check Point identified a zero-day vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access deployments, exploited by the Qilin ransomware gang. The flaw allowed unauthenticated attackers to bypass authen… BleepingComputer · Jun 8, 2026 High CVE-2026-50751CVE-2026-50752ISJAAUzero-dayvpnauthentication
vulnerability Everest Forms Vulnerability Exploited to Hack WordPress Sites The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek . SecurityWeek · Jun 8, 2026 Critical CVE-2026-3300
vulnerability Anthropic’s Project Glasswing Update In April, Anthropic initated Project Glasswing . The idea was to let companies use their new model to find and fix vulnerabilities in their own software. It was a fantastic PR move, and so many press outlets have uncriti… Schneier on Security · Jun 8, 2026
vulnerability SolarWinds Serv-U Vulnerability Exploited in the Wild Unauthenticated attackers can exploit the flaw via specially crafted POST requests that crash the Serv-U service. The post SolarWinds Serv-U Vulnerability Exploited in the Wild appeared first on SecurityWeek . SecurityWeek · Jun 8, 2026 Critical CVE-2026-28318
vulnerability Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation Emphere’s solution delivers AI-driven remediation to software companies to speed up releases. The post Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation appeared first on SecurityWeek . SecurityWeek · Jun 7, 2026 Medium
vulnerability Critical Everest Forms Pro flaw exploited to take over WordPress sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution,… BleepingComputer · Jun 6, 2026 Critical CVE-2026-3300wordpresspluginvulnerability
vulnerability CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalo… The Hacker News · Jun 6, 2026 Critical CVE-2026-28318
vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execu… The Hacker News · Jun 6, 2026 Critical CVE-2026-20245CVE-2026-20182CVE-2026-20127sd-wancvezero-day
vulnerability CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers CISA has issued a warning about hackers actively exploiting a recently patched vulnerability in SolarWinds Serv-U, a file transfer software, to crash servers. This vulnerability, CVE-2026-28318, stems from uncontrolled r… BleepingComputer · Jun 5, 2026 High CVE-2026-28318CVE-2021-35211CVE-2024-28995UNdenial-of-servicepatchingfile transfer
vulnerability Chrome 149 Patches 429 Vulnerabilities Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 5, 2026 High CVE-2026-10881CVE-2026-10882CVE-2026-10883
vulnerability Cisco warns of unpatched SD-WAN zero-day exploited in attacks Cisco has issued a warning about a previously unknown zero-day vulnerability (CVE-2026-20245) in its Cisco Catalyst SD-WAN Manager software, which is being actively exploited to gain root privileges. The flaw, stemming f… BleepingComputer · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daysd-wanroot privilege
vulnerability Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used b… SecurityWeek · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daycommand injectionsd-wan
vulnerability Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept… The Hacker News · Jun 4, 2026 CVE-2026-20230CVE-2025-20309CVE-2026-20045
vulnerability CISA directive for AI executive order to be released this week, Andersen says The binding operational directive will focus in part on “vulnerability alleviation and vulnerability management,” Andersen said in remarks delivered at the TechNet Cyber conference in Baltimore. The Record · Jun 4, 2026 Medium
vulnerability Mirasvit Vulnerability Exploited to Execute Code on Magento Servers A flaw in the Full Page Cache Warmer extension can be exploited without authentication via serialized PHP object payloads. The post Mirasvit Vulnerability Exploited to Execute Code on Magento Servers appeared first on Se… SecurityWeek · Jun 4, 2026 Medium CVE-2026-45247
vulnerability Hitachi Energy MACH HiDraw A buffer overflow vulnerability has been identified in Hitachi Energy’s MACH HiDraw product versions up to 9.22. Exploitation of this flaw could lead to denial-of-service attacks and potential arbitrary code execution, i… CISA Advisories · Jun 4, 2026 High CVE-2026-7310USbuffer overflowxml parserindustrial control systems
vulnerability Hitachi Energy RTU500 This advisory details vulnerabilities within Hitachi Energy’s RTU500 product, specifically CMU Firmware versions 12.7.1 through 13.8.1. These vulnerabilities, primarily CWE-476 (NULL Pointer Dereference) and CWE-190 (Int… CISA Advisories · Jun 4, 2026 Medium CVE-2025-69421CVE-2026-24515CVE-2026-25210WOcwe-476cwe-190denial-of-service