vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
vulnerability Vulnérabilité dans WordPress (13 août 2026) A remote code execution vulnerability has been identified in older versions of WordPress, allowing attackers to execute arbitrary code. This affects WordPress versions prior to 7.0.4, and requires immediate patching to p… CERT-FR · Aug 13, 2026 Critical CVE-2026-65640wordpressrcevulnerability
vulnerability Multiples vulnérabilités dans Progress MOVEit WAF (13 août 2026) Multiple vulnerabilities have been discovered in Progress MOVEit WAF, allowing attackers to execute arbitrary code remotely, escalate privileges, and bypass security policies. These vulnerabilities affect versions prior… CERT-FR · Aug 13, 2026 Critical CVE-2026-59686CVE-2026-59687CVE-2026-59688vulnerabilityprogressmoveit
threat-intel CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates rec… The Record · Aug 12, 2026 Critical CVE-2026-68820FRGEBRzero-daynorth koreaoperation dream job
vulnerability Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws Adobe has released critical security patches to address multiple vulnerabilities in ColdFusion, Commerce, and Campaign Classic. These flaws could lead to arbitrary code execution and privilege escalation, and while no ex… The Hacker News · Aug 12, 2026 Critical CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a critical security flaw in its Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability stems from insufficient autho… The Hacker News · Aug 12, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-34265securitypatcharbitrary code execution
vulnerability SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform SonicWall has released patches to address eight critical vulnerabilities in its discontinued GMS platform and Email Security products. These flaws, including remote code execution and command injection, could allow attac… SecurityWeek · Aug 12, 2026 Critical CVE-2026-66147CVE-2026-66145CVE-2026-66149vulnerabilitypatchrce
vulnerability Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS A critical vulnerability (CVE-2026-20349, CVSS: 8.6) in Cisco ASA and FTD software has been actively exploited in the wild. This flaw, triggered by a crafted HTTP request, can lead to a denial-of-service condition and is… The Hacker News · Aug 12, 2026 Critical CVE-2026-20349cveasaftd
threat-intel Microsoft Patch Tuesday August 2026, (Tue, Aug 11th) Microsoft released a substantial batch of security updates this month, including several critical vulnerabilities that are either being exploited in the wild or have been publicly disclosed as zero-days. Several of these… SANS Internet Storm Center · Aug 11, 2026 Critical CVE-2026-68820CVE-2026-62832CVE-2026-72971vulnerabilityremote code executionprivilege escalation
vulnerability Zoom Patches Zero-Click Code Execution Vulnerability Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction… SecurityWeek · Aug 11, 2026 Critical CVE-2026-53413CVE-2026-53414CVE-2026-53415vulnerabilityremote code executionzero-click
vulnerability SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities SAP released 28 security notes on August 2026 Patch Day to address a range of critical vulnerabilities across its products, including SAP Commerce Cloud, NetWeaver Application Server ABAP, and ABAP Platform. These flaws… SecurityWeek · Aug 11, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-44758vulnerabilitypatchcode injection
threat-intel Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants The Head Mare APT group is exploiting multiple vulnerabilities in TrueConf servers to deliver the PhantomCore and PhantomGraph backdoors. Attackers connect to TrueConf servers without authorization, call a server functio… Securelist · Aug 11, 2026 Critical aptmalwarebackdoor
vulnerability Pulsetto Vagus Nerve Stimulator A critical vulnerability (CVE-2026-18844) exists in Pulsetto Vagus Nerve Stimulator devices, allowing attackers to bypass security measures and manipulate device settings via Bluetooth Low Energy (BLE). The vulnerability… CISA Advisories · Aug 11, 2026 Critical CVE-2026-18844LIbluetoothcvecontrol systems
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
vulnerability ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code remotely. This exploit could lead to widespread data breaches and… SANS Internet Storm Center · Aug 10, 2026 Critical log4jrcevulnerability
vulnerability Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and… SecurityWeek · Aug 8, 2026 Critical aiprompt injectiondata exfiltration
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach