vulnerability Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Attackers are chaining two PaperCut vulnerabilities – one related to dynamic class loading and another to improper access control – to execute arbitrary code on susceptible instances without authentication. The vulnerability allows for remote code execution, and threat actors have been observed exploiting these flaws t… The Hacker News · 2d ago High CVE-2026-82078CVE-2026-81578vulnerabilityremote code executionpatch
vulnerability Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server A critical security vulnerability in cPanel and WebHost Manager (WHM) allows an authenticated user adding parked or addon domains to execute code as the root user, potentially leading to full server control. While the vu… The Hacker News · 2d ago Critical CVE-2026-65643CVE-2026-58048CVE-2026-58047cpanelvulnerabilityroot
vulnerability PaperCut Releases Emergency Patch for Exploited Zero-Day PaperCut has released an emergency patch for a zero-day vulnerability being actively exploited in its print management solutions. The vulnerability, currently unassigned a CVE, is linked to malware delivery and log delet… SecurityWeek · 2d ago High USCAEUzero-dayvulnerabilitypatch
vulnerability PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions PaperCut has confirmed a zero-day vulnerability is being actively exploited in its print management software, impacting all versions of NG and MF. The company released a patch and urges users to restrict internet access… The Hacker News · 2d ago Critical CVE-2023-27350RUzero-dayprint managementvulnerability
vulnerability Ebyte NA111-M A series of vulnerabilities have been identified in Ebyte NA111-M devices, primarily related to authentication and configuration management. These flaws allow unauthenticated attackers to access sensitive information, mo… CISA Advisories · 3d ago High CVE-2026-73125CVE-2026-76179CVE-2026-75814CHauthenticationconfigurationvulnerability
vulnerability Adobe and Nvidia Patch Dozens of Vulnerabilities Adobe and Nvidia released patches addressing dozens of security vulnerabilities across their products, including critical flaws that could lead to code execution and data breaches. Nvidia released four advisories focusin… SecurityWeek · 4d ago High vulnerabilitysecurityai
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
vulnerability Chrome 152 Patches Over 300 Vulnerabilities Google released Chrome 152, addressing over 300 vulnerabilities, a significant portion of which were identified using internal AI. This update represents a substantial increase in patching activity for Chrome this year,… SecurityWeek · 4d ago High CVE-2026-79282chromevulnerabilitypatch
vulnerability CISA Warns of Exploited Gitea Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a publicly exploited Gitea vulnerability (CVE-2026-60004) that allows remote code execution. Organizations are urged to patch this fl… SecurityWeek · 4d ago Critical CVE-2026-60004CVE-2026-20896vulnerabilitygitcisa
vulnerability Multiples vulnérabilités dans OpenSSL (26 août 2026) Multiple vulnerabilities have been discovered in OpenSSL, allowing for denial of service attacks and policy bypasses. These vulnerabilities affect various OpenSSL versions and could be exploited by attackers. Users are a… CERT-FR · 4d ago Medium CVE-2026-14457CVE-2026-18798CVE-2026-54874vulnerabilityopensslsecurity
vulnerability Multiples vulnérabilités dans les produits Veeam (26 août 2026) Multiple vulnerabilities have been discovered in Veeam products, allowing an attacker to compromise data confidentiality and bypass security policies. Veeam has released security bulletins with patches to address these i… CERT-FR · 4d ago Medium CVE-2026-58070CVE-2026-65641vulnerabilitypatchsecurity
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
vulnerability Ebyte NE2-D11 A CISA advisory highlights critical vulnerabilities in Ebyte NE2-D11 devices, primarily due to a lack of consistent authentication enforcement and cleartext transmission of sensitive information. The vendor, Ebyte, has n… CISA Advisories · 5d ago High CVE-2026-73125CVE-2026-73809CVE-2026-73839CHvulnerabilityauthenticationencryption
vulnerability Rently Smart Home Rently Smart Home versions 20.1.0 and earlier are vulnerable to an insufficient credentials issue, potentially allowing an attacker to access sensitive information and override user permissions. Rently has released a pat… CISA Advisories · 5d ago Medium CVE-2026-75960USINvulnerabilitycwe-522industrial control systems
vulnerability CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw CISA has issued a critical three-day patch deadline for a vulnerability in the Perfect 10 plugin for Joomla, which is being actively exploited by attackers. This plugin flaw allows attackers to gain unauthorized access t… The Register · 5d ago Critical CVE-2026-21962joomlavulnerabilityplugin
vulnerability CISA Warns of Exploited Oracle WebLogic Vulnerability The CISA has issued a critical warning to federal agencies about a widely exploited vulnerability in Oracle WebLogic servers (CVE-2026-21962). This flaw allows attackers to execute code remotely without authentication, a… SecurityWeek · 5d ago Critical CVE-2026-21962CNoracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Cisco IOS XE (25 août 2026) Cisco has announced multiple vulnerabilities in its IOS XE software, allowing attackers to bypass security policies and potentially cause unspecified security issues. These vulnerabilities affect several versions of the… CERT-FR · 5d ago High CVE-2026-20267CVE-2026-20268CVE-2026-20269ciscoios xevulnerability
vulnerability 91 Vulnerabilities Patched in Spring Application Framework Broadcom released a massive update addressing 91 vulnerabilities within the Spring application framework. Many of these flaws, including a critical Remote Code Execution (RCE) vulnerability, could be exploited for variou… SecurityWeek · 6d ago High CVE-2026-59270CVE-2026-59285CVE-2026-59318springvulnerabilityrce
vulnerability Multiples vulnérabilités dans LibreNMS (24 août 2026) Multiple vulnerabilities have been discovered in LibreNMS, allowing an attacker to compromise data confidentiality and bypass security policies. Users of LibreNMS versions prior to 26.8.0 are strongly advised to apply th… CERT-FR · 6d ago Medium librenmsvulnerabilitynetwork monitoring
threat-intel Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it US Homeland Security cybersecurity officials are warning users of TrueConf, a video conferencing tool developed in Russia, to urgently patch the software due to a critical vulnerability that could allow attackers to remo… The Register · Aug 21, 2026 Critical CVE-2026-72529CVE-2026-72530RUUSvulnerabilitycybersecurityrussia