vulnerability Chrome 148 Update Patches 151 Vulnerabilities The browser update resolves critical-severity security defects that could potentially lead to remote code execution. The post Chrome 148 Update Patches 151 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · May 29, 2026 High CVE-2026-9872CVE-2026-9873CVE-2026-9874
vulnerability Multiples vulnérabilités dans les produits Mattermost (29 mai 2026) Multiple vulnerabilities have been discovered in Mattermost Server, allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities, detailed in Mattermost security bulletins, re… CERT-FR · May 29, 2026 Medium CVE-2026-3472CVE-2026-4339vulnerabilitymattermostsecurity
vulnerability Hackers exploit FortiClient EMS flaw to push infostealer malware Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. BleepingComputer · May 28, 2026 Medium CVE-2026-35616
vulnerability Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical remote code execution (RCE) vulnerability has been identified in Gogs, a popular self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw, detailed by Jonah Burgess, stems from… The Hacker News · May 28, 2026 Critical rcegitrebase
vulnerability Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoi… The Hacker News · May 28, 2026 Medium CVE-2026-35616
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
vulnerability Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fres… SecurityWeek · May 28, 2026 Critical CVE-2026-35616
vulnerability IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under “Project Lightwell” appeared first… SecurityWeek · May 28, 2026 High
vulnerability ABB EIBPORT View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions… CISA Advisories · May 28, 2026 Medium CVE-2021-22291
vulnerability KMW CCTV Security Cameras This advisory details a critical vulnerability in KMW CCTV Security Cameras, specifically versions KM-IP521 (V4.04.91.230307) and KM-IP421 (V4.04.53.210416), allowing unauthorized access to camera feeds and settings via… CISA Advisories · May 28, 2026 Critical CVE-2026-5386WOcctvpasswordunauthenticated
vulnerability Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative cr… CISA Advisories · May 28, 2026 Critical CVE-2026-7786CNfirmwarecredentialsiot
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
vulnerability ABB Busch-Welcome 2 Wire Door Opener Actuator A vulnerability has been identified in ABB Busch-Welcome 2 Wire Door Opener Actuators, specifically due to a default compatibility mode that allows for authentication bypass. This could enable an attacker to gain unautho… CISA Advisories · May 28, 2026 High CVE-2025-7705WOdoor lockphysical accessauthentication
vulnerability Fourth Frontier Frontier X Mobile Application, Frontier X2 A vulnerability has been identified in the Fourth Frontier Frontier X Mobile Application and Frontier X2 devices, allowing unauthorized access and control. Attackers could potentially read and modify patient data, trigge… CISA Advisories · May 28, 2026 High CVE-2026-5768USbleauthenticationdevice control
vulnerability Gitea Vulnerability Exposed 30,000 Deployments to Attacks The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure. The post Gitea Vulnerability Exposed 30,000 Deployments to Attacks appeared first on SecurityWe… SecurityWeek · May 28, 2026 High CVE-2026-27771
vulnerability DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format. Cisco Talos · May 28, 2026 Medium
vulnerability Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx. The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared… SecurityWeek · May 27, 2026 High CVE-2026-41241
vulnerability MediaArea heap-based buffer overflow vulnerabilities Cisco Talos’ Vulnerability Discovery & Research team recently disclosed four vulnerabilities in MediaArea MediaInfoLib library. The vulnerabilities mentioned in this blog post have been patched by their respective vendor… Cisco Talos · May 27, 2026 High CVE-2026-25104CVE-2026-25713CVE-2026-28764
vulnerability CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-453… CISA Advisories · May 27, 2026 Medium CVE-2026-8398CVE-2026-45321CVE-2026-48027