vulnerability Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active… The Hacker News · May 23, 2026 Critical CVE-2026-9082
vulnerability Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Dis… SecurityWeek · May 22, 2026 Medium CVE-2026-9082
vulnerability Trend Micro warns of Apex One zero-day exploited in the wild Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. BleepingComputer · May 22, 2026 Critical CVE-2026-34926CVE-2025-54948CVE-2022-40139
vulnerability Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. BleepingComputer · May 22, 2026 Medium CVE-2026-9082
vulnerability Ubiquiti patches three max severity UniFi OS vulnerabilities Ubiquiti Networks has released security patches for three critical vulnerabilities within its UniFi OS operating system, addressing potential remote exploitation risks. These flaws include improper access control, path t… BleepingComputer · May 22, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910UScommand injectionaccess controlpath traversal
vulnerability TrendAI Patches Apex One Zero-Day Exploited in the Wild CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek . SecurityWeek · May 22, 2026 Critical CVE-2026-34926
vulnerability CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of a… The Hacker News · May 22, 2026 Medium CVE-2025-34291CVE-2026-34926
vulnerability Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the… The Hacker News · May 22, 2026 Medium CVE-2026-20223CVE-2026-20182
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
vulnerability Google accidentally exposed details of unfixed Chromium flaw Google inadvertently exposed details of a persistent vulnerability in Chromium, allowing for remote code execution on devices. The flaw, initially reported in December 2022, remained unfixed for over two years, leading t… BleepingComputer · May 21, 2026 High remote-code-executionbrowservulnerability
vulnerability macOS Kernel Memory Corruption Exploit A group used Anthropic’s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple’s M5. News article . Schneier on Security · May 21, 2026 Medium
vulnerability Max severity Cisco Secure Workload flaw gives Site Admin privileges Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges. BleepingComputer · May 21, 2026 Medium CVE-2026-20223CVE-2026-20182
vulnerability Cisco Patches Critical Vulnerability in Secure Workload Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. The post Cisco Patches Critical Vulnerability in Secure Workload appeared first on Securi… SecurityWeek · May 21, 2026 Critical CVE-2026-20223
vulnerability Hitachi Energy GMS600 View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability c… CISA Advisories · May 21, 2026 Medium CVE-2022-4304
vulnerability ABB B&R Automation Studio ABB has issued a security advisory regarding vulnerabilities in its B&R Automation Studio software. The issues, stemming from SQLite versions, could lead to memory corruption and heap buffer overflows, potentially allowi… CISA Advisories · May 21, 2026 High CVE-2025-6965CVE-2025-3277CVE-2023-7104CHsqliteheap-overflowmemory-corruption
vulnerability CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-34926 Trend M… CISA Advisories · May 21, 2026 Medium CVE-2025-34291CVE-2026-34926
vulnerability ABB B&R Automation Runtime This CISA advisory details vulnerabilities within ABB B&R Automation Runtime versions prior to 6.4. Specifically, the System Diagnostic Manager (SDM) component is susceptible to reflected cross-site scripting (XSS) and i… CISA Advisories · May 21, 2026 High CVE-2025-3449CVE-2025-3448CVE-2025-11498CHxsscsvsdm
vulnerability ABB B&R PCs This CISA advisory details a vulnerability (CVE-2023-45229 through CVE-2023-45237) affecting ABB B&R PCs, specifically versions of the EDK2 Network Package. The vulnerability, a critical out-of-bounds read, allows for re… CISA Advisories · May 21, 2026 Critical CVE-2023-45229CVE-2023-45230CVE-2023-45231uefidhcpv6remote code execution
vulnerability ABB Terra AC Wallbox ABB has identified and addressed vulnerabilities in its Terra AC Wallbox product versions (<=1.8.33). These vulnerabilities, specifically related to heap and stack memory pollution due to improper handling of communicati… CISA Advisories · May 21, 2026 Medium CVE-2025-10504CVE-2025-12142CVE-2025-12143GLbluetoothfirmwarebuffer overflow
vulnerability Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution. The post Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking appear… SecurityWeek · May 21, 2026 Critical CVE-2026-9082