vulnerability RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries Using an AI model called BinNet, RevEng hunts vulnerabilities and backdoors in released software binaries. The post RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries appeared first on Secu… SecurityWeek · May 27, 2026
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
vulnerability CISA gives feds 4 days to patch actively exploited cPanel plugin flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is active… BleepingComputer · May 27, 2026 Critical CVE-2026-48172
vulnerability CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privileg… SecurityWeek · May 27, 2026 Critical CVE-2026-48172UScpanelzero-dayprivilege escalation
vulnerability Anthropic Releases New Claude Sandbox, Security Guidance Plugin The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. The post Anthropic Releases New Claude Sandbox, Security Guidance Plugin appeared fi… SecurityWeek · May 27, 2026
vulnerability KnowledgeDeliver flaw exploited as a zero-day to install web shells Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. BleepingComputer · May 26, 2026 Critical CVE-2026-5426
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day
vulnerability ABB Terra AC This report details a vulnerability in ABB Terra AC wallbox chargers, specifically versions up to 1.8.34. An attacker could exploit unencrypted communication to the Charging Station Management System (CSMS) by sending sp… CISA Advisories · May 26, 2026 Critical CVE-2025-5517WOocppheap overflowfirmware
vulnerability ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) This advisory details a denial-of-service (DoS) vulnerability in ABB B&R Automation Runtime versions prior to 6.3 and Q4.93, specifically within the System Diagnostics Manager (SDM) component. An unauthenticated network… CISA Advisories · May 26, 2026 High CVE-2025-3450WOdosdenial of serviceresource locking
vulnerability ABB LVS MConfig ABB has identified and announced a vulnerability in its MConfig product versions (<=1.4.9.21) that allows attackers with local network access to potentially extract sensitive information, including passwords, from memory… CISA Advisories · May 26, 2026 High CVE-2025-9970WOmemory_dumppassword_leaklocal_access
vulnerability Eppendorf BioFlo 320 This CISA advisory details a critical vulnerability in Eppendorf BioFlo 320 bioreactors due to a hard-coded VNC password, allowing unauthorized remote access and control. The vulnerability affects all versions of the Bio… CISA Advisories · May 26, 2026 Critical CVE-2026-7251WOvncpasswordremote access
vulnerability ABB AbilityTM Zenon Remote Transport Vulnerability This advisory from CISA details a vulnerability in ABB AbilityTM Zenon Remote Transport, specifically versions 7.50 through 14. The flaw allows unauthorized access and remote system reboots without authentication, posing… CISA Advisories · May 26, 2026 High CVE-2025-8754WOauthenticationremote rebootcwe-306
vulnerability ABB Ability Camera Connect This CISA advisory details a vulnerability in ABB Ability Camera Connect, specifically related to the VLC media player component (version 2.2.4 and earlier). The vulnerability, a heap-based buffer overflow due to an inte… CISA Advisories · May 26, 2026 Medium CVE-2024-46461CVE-2023-47360CVE-2023-47359WOheap_overflowinteger_underflowvulnerability
vulnerability Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerabilit… The Hacker News · May 26, 2026 High CVE-2026-45659CVE-2026-32201
vulnerability Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first… SecurityWeek · May 26, 2026 Critical CVE-2026-5426
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
vulnerability Ghost CMS Vulnerability Exploited to Hack Over 700 Websites A previously disclosed SQL injection vulnerability (CVE-2026-26980) in the Ghost CMS has been actively exploited by multiple threat actors, leading to the compromise of over 700 websites. The attackers leveraged this vul… SecurityWeek · May 25, 2026 High CVE-2026-26980USGBsql injectionghost cmsvulnerability
vulnerability Wireshark 4.6.6 Released, (Sun, May 24th) Wireshark, a popular network protocol analyzer, released version 4.6.6, addressing several issues within the software. This update includes fixes for a single vulnerability and eleven bugs, alongside an update to the Npc… SANS Internet Storm Center · May 24, 2026 Medium wiresharknetwork analysissecurity update
vulnerability ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connection… SecurityWeek · May 23, 2026 Medium
vulnerability LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incor… The Hacker News · May 23, 2026 Medium CVE-2026-48172CVE-2026-41940