vulnerability Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Multiple critical vulnerabilities have been discovered in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could lead to complete site takeover, allowing attackers to gain administrator access and execute arbitrary code, highlighting a significant… The Hacker News · 1d ago Critical CVE-2026-76581CVE-2026-18431CVE-2026-19632wordpressvulnerabilityplugin
threat-intel PaperCut warns of hackers using printer management software flaw in attacks PaperCut, a popular printer management software provider, has warned customers of a serious vulnerability being actively exploited by cybercriminals. The vulnerability, affecting their PaperCut NG and MF software, has le… The Record · 2d ago Critical CVE-2026-82078CVE-2026-81578IRvulnerabilityprintercybersecurity
vulnerability Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL ServiceNow has released security patches for four critical vulnerabilities in its AI Platform, including three rated at 10.0 CVSS, that could allow unauthenticated attackers to execute code, create or modify instance dat… The Hacker News · 2d ago Critical CVE-2026-18885CVE-2026-18886CVE-2026-74820cvssvulnerabilitycode injection
vulnerability Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server A critical security vulnerability in cPanel and WebHost Manager (WHM) allows an authenticated user adding parked or addon domains to execute code as the root user, potentially leading to full server control. While the vu… The Hacker News · 2d ago Critical CVE-2026-65643CVE-2026-58048CVE-2026-58047cpanelvulnerabilityroot
vulnerability PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions PaperCut has confirmed a zero-day vulnerability is being actively exploited in its print management software, impacting all versions of NG and MF. The company released a patch and urges users to restrict internet access… The Hacker News · 2d ago Critical CVE-2023-27350RUzero-dayprint managementvulnerability
vulnerability Xiiaozet LK100W The CISA has issued an advisory regarding critical vulnerabilities in the Xiiaozet LK100W device. Exploitation could allow an attacker to gain full control over the device by leveraging authentication bypass and command… CISA Advisories · 3d ago Critical CVE-2026-78037CVE-2026-78239CVE-2026-76943vulnerabilitycommand injectionauthentication bypass
vulnerability Mitsubishi Electric CNC Series (Update A) A vulnerability (CWE-1285) exists in Mitsubishi Electric CNC Series (Update A) products, allowing a remote attacker to cause a denial-of-service by sending crafted packets to TCP port 683. This affects a wide range of CN… CISA Advisories · 3d ago Critical CVE-2025-2399cwe-1285cncindustrial control systems
vulnerability Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload A critical remote code execution vulnerability (CVE-2026-60004) in Gitea is actively being exploited to deploy cryptocurrency miners. The vulnerability, stemming from default open registration, allows attackers to gain r… The Hacker News · 4d ago Critical CVE-2026-60004remote code executioncryptojackinggit hook
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
threat-intel Employee benefits platform Paylogix says hackers stole financial and health data Paylogix, a benefits administration platform, suffered a cyberattack that exposed sensitive data for tens of thousands of users, including Social Security numbers, health insurance details, and passport information. The… The Record · 5d ago Critical USransomwaredata breachcyberattack
vulnerability PayRange API A critical vulnerability in the PayRange API allows unauthorized access to sensitive device information and potential denial-of-service attacks. The vulnerability stems from a lack of proper authorization on management e… CISA Advisories · 5d ago Critical CVE-2026-18965USCAvulnerabilityicscontrol systems
vulnerability Zoneminder A critical Remote Code Execution (RCE) vulnerability exists in Zoneminder versions 1.37.48 and 1.38.3, allowing authenticated users to execute arbitrary operating system commands. The vulnerability stems from an Improper… CISA Advisories · 5d ago Critical CVE-2026-76060vulnerabilityrceos command injection
vulnerability Siemens SIMATIC IoT2050 Advanced A vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed allows unauthenticated remote attackers to create malicious flows and execute arbitrary code on the underlying ser… CISA Advisories · 5d ago Critical CVE-2026-58115vulnerabilityindustrial control systemsnode-red
vulnerability Bendix EC80 Brake ECU A critical vulnerability exists in Bendix EC80 Brake ECU firmware, potentially allowing an attacker to disable ABS, steering assist, speedometer, and shifting capabilities, or inject malicious CAN bus traffic. Multiple f… CISA Advisories · 5d ago Critical CVE-2026-67560CVE-2026-68967CVE-2026-71396UNCAfirmwarebuffer overflowcan bus
vulnerability CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw CISA has issued a critical three-day patch deadline for a vulnerability in the Perfect 10 plugin for Joomla, which is being actively exploited by attackers. This plugin flaw allows attackers to gain unauthorized access t… The Register · 5d ago Critical CVE-2026-21962joomlavulnerabilityplugin
vulnerability CISA Warns of Exploited Oracle WebLogic Vulnerability The CISA has issued a critical warning to federal agencies about a widely exploited vulnerability in Oracle WebLogic servers (CVE-2026-21962). This flaw allows attackers to execute code remotely without authentication, a… SecurityWeek · 5d ago Critical CVE-2026-21962CNoracleweblogicvulnerability
vulnerability Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data A critical, actively exploited vulnerability in Oracle WebLogic Server allows unauthenticated attackers to access sensitive data. Despite patches being released in January, threat actors are still leveraging this flaw, p… The Hacker News · 5d ago Critical CVE-2026-21962CVE-2020-14882CVE-2020-2551rceweblogiccve-2026-21962
vulnerability ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This exploit could lead t… SANS Internet Storm Center · 6d ago Critical log4jlog4shellremote code execution
vulnerability Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patch… The Hacker News · 6d ago Critical CVE-2026-18963CVE-2026-15571password-resetauthenticationkeycloak
vulnerability ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability is act… SANS Internet Storm Center · Aug 24, 2026 Critical log4jremote code executionapache