vulnerability Anthropic Expanding Mythos Access to 150 New Organizations Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products. The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first o… SecurityWeek · Jun 2, 2026
vulnerability CISA flags two-year-old Oracle flaw as actively exploited in attacks CISA has identified a two-year-old Oracle WebLogic Server vulnerability (CVE-2024-21182) as actively being exploited in attacks, prompting a directive for federal agencies to immediately patch their systems. The vulnerab… BleepingComputer · Jun 2, 2026 High CVE-2024-21182CVE-2025-61884CVE-2026-21992oracleweblogicvulnerability
vulnerability Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches A critical vulnerability (CVE-2026-0826) has been identified in HP Poly Voice VoIP phone models, allowing for remote code execution with root privileges. The flaw, triggered by a stack-based buffer overflow when processi… SecurityWeek · Jun 2, 2026 Critical CVE-2026-0826USvoipbuffer overflowremote code execution
vulnerability Oracle WebLogic Vulnerability Exploited in the Wild The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. The post Oracle WebLogic Vulnerability Exploited in the Wild appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 Critical CVE-2024-21182
vulnerability Google fixes one actively exploited Android zero-day, 124 flaws Google has released a significant security update addressing 124 vulnerabilities in Android, including a previously exploited zero-day vulnerability (CVE-2025-48595). This update focuses on mitigating targeted attacks an… BleepingComputer · Jun 2, 2026 High CVE-2025-48595CVE-2025-48633CVE-2025-48572zero-dayandroidvulnerability
vulnerability Microsoft Threatening Security Researcher A security researcher known as "Nightmare Eclipse" has been publicly disclosing a series of critical vulnerabilities within Microsoft Windows, including a breach of BitLocker encryption. In response, Microsoft has issued… Schneier on Security · Jun 2, 2026 High securityexploitbitlocker
vulnerability Oracle’s First Monthly Patches Resolve 77 Vulnerabilities Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 2, 2026 Medium
vulnerability WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared fir… SecurityWeek · Jun 1, 2026 Medium CVE-2026-8732
vulnerability Vulnerability Disclosure in the Age of AI New article: “ Responsible Disclosure in the Age of AI: A Call for Urgent Action ,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remedi… Schneier on Security · Jun 1, 2026 Medium
vulnerability Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation. The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on S… SecurityWeek · Jun 1, 2026 Medium CVE-2026-41089
vulnerability Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain… Dark Reading · Jun 1, 2026 Critical CVE-2026-0257CVE-2025-0108USvpnauthenticationcookie
vulnerability 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Sys… SecurityWeek · Jun 1, 2026 Medium
vulnerability Recent Palo Alto Networks Vulnerability Exploited for Weeks Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on Sec… SecurityWeek · Jun 1, 2026 Medium CVE-2026-0257
vulnerability Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts A critical security flaw (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been actively exploited to create administrator accounts on vulnerable websites. The vulnerability stems from a flaw in the plugin's tempor… The Hacker News · Jun 1, 2026 Critical CVE-2026-8732wordpresspluginvulnerability
vulnerability WP Maps Pro bug exploited to create admin accounts on WordPress sites A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin has been exploited by threat actors to create administrator accounts on affected websites. The flaw stems from an insecure AJAX endpoint that a… BleepingComputer · May 31, 2026 Critical CVE-2026-8732wordpresswp maps provulnerability
vulnerability Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks Palo Alto Networks is warning of an actively exploited vulnerability (CVE-2026-0257) in its GlobalProtect VPN software, allowing attackers to bypass authentication and establish unauthorized VPN connections. The flaw, in… BleepingComputer · May 30, 2026 High CVE-2026-0257USvpnauthenticationcookie
vulnerability Exploit Code Published for Critical Flowise RCE Vulnerability A critical remote code execution (RCE) vulnerability, CVE-2026-40933, has been discovered in Flowise, a popular open-source AI agent platform. The flaw, stemming from a command injection issue within the Anthropic MCP pr… SecurityWeek · May 30, 2026 Critical CVE-2026-40933rcecommand injectionai
vulnerability New CIFSwitch Linux flaw gives root on multiple distributions A newly discovered vulnerability, dubbed 'CIFSwitch,' in the Linux kernel allows attackers to escalate privileges to root by forging CIFS authentication key descriptions. The flaw, present since 2007, affects multiple Li… BleepingComputer · May 30, 2026 High CVE-2026-46243linuxkernelprivilege escalation
vulnerability PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS s… The Hacker News · May 30, 2026 Medium CVE-2026-0257CVE-2026-35616
vulnerability Gogs Zero-Day Exposes Servers to Remote Code Execution A critical zero-day vulnerability has been discovered in the open-source self-hosted Git service, Gogs, allowing for remote code execution (RCE) on affected servers. The flaw, identified by Rapid7, stems from an argument… SecurityWeek · May 29, 2026 Critical CVE-2025-8110zero-dayremote code executiongit