CVE Tools

Security news, decoded.

73 stories in the last 7 days, naming 202 CVEs; 57 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 2 of 36 · newest first · times in UTC

Wednesday, Sep 238 stories

  1. The Hacker News
    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    Chinese-linked actor UTA0565 used fake websites to exploit a zero-day chain affecting Google Chrome and Microsoft Windows: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The flaws enabled a browser sandbox escape and remote code execution, delivering the CLEANGULP malware, which can run commands, manage files, inspect processes, and execute BOF payloads.

    Reported exploitedChrome
  2. SecurityWeek
    Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

    F5 has confirmed active zero-day exploitation of CVE-2026-94127, a CVSS 9.8 vulnerability in BIG-IP Access Policy Manager. Unauthenticated attackers can execute code remotely when a vulnerable BIG-IP APM deployment is configured as an OAuth Authorization Server with an access policy and OAuth profile on a virtual server. Affected releases are BIG-IP APM 21.1.0, 17.5.0 to 17.5.1, and 17.1.0 to 17.1.3; F5 has issued hotfixes. CISA has also added the flaw to its Known Exploited Vulnerabilities catalog, making prompt remediation important.

    Reported exploitedBIG-IP Access Policy Manager
  3. BleepingComputer
    F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

    F5 released fixes for CVE-2026-94127, an actively exploited remote code execution zero-day in BIG-IP Access Policy Manager. The issue affects BIG-IP APM virtual servers configured with both an access policy and OAuth profile when operating as an OAuth Authorization Server; OAuth Client or Resource Server-only deployments are not affected. CISA added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog. Organizations should install F5's updates, investigate OAuth authentication failures, suspicious commands, and subsequent TMM SIGABRT events, or apply F5's iRule mitigation where patching is delayed.

    Reported exploitedBIG-IP Access Policy Manager
  4. SecurityWeek
    ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

    ShinyHunters claims it breached FBI systems, defaced a subdomain of fbijobs.gov, and obtained personal data allegedly belonging to thousands of FBI employees. The group says it used a zero-day flaw in Oracle PeopleSoft to access FBI systems and steal 2-3 TB of information, though the FBI is still investigating and the data's source has not been confirmed. ShinyHunters has previously been linked to in-the-wild exploitation of the Oracle PeopleSoft vulnerability tracked as CVE-2026-35273, but it is unclear whether that flaw was used in the alleged FBI incident.

    Reported exploitedPeopleSoft
  5. The Hacker News
    Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

    Vercel has patched CVE-2026-94545, a critical Next.js vulnerability that can allow server-side code execution when Node.js ImageResponse processes attacker-controlled values in generated SVG content. The issue affects Next.js 16.2.0 through 16.3.5; Next.js 15 and the Edge implementation of ImageResponse are not affected. Organizations should upgrade to Next.js 16.3.6, while developers using Satori directly should update to version 0.33.5.

    PatchNext.js
  6. SecurityWeek
    Check Point Patches Exploited Management Server Zero-Day

    Check Point has issued urgent fixes for CVE-2026-93616, a CVSS 9.8 directory traversal and file upload flaw exploited in attacks against Management Server. The issue affects Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent, allowing unauthenticated attackers to upload and run arbitrary scripts. The company also reports exploitation attempts targeting Spark Firewall customers through CVE-2026-85102, which can bypass VPN authentication and enable code execution on Security Gateway and Spark Firewall; organizations should apply the available updates and restrict Management Server access to trusted IP addresses.

    Reported exploitedManagement Server
  7. The Hacker News
    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    ShinyHunters claims it breached the FBI and obtained data on current and former employees, as well as FBI job applicants. The group says it used an undisclosed Oracle PeopleSoft pre-authenticated RCE flaw to compromise FBIjobs.gov, while CVE-2026-35273 was previously exploited by the group against enterprise networks; the FBI is investigating the claims.

    Reported exploitedPeopleSoft
  8. Help Net Security
    NetBSD 10.2 security fixes close a remote kernel bug in ipfilter

    The NetBSD Project released NetBSD 10.2 with a fix for a remotely triggerable null pointer dereference in ipfilter that could crash the kernel, plus a TCP timestamp issue that exposes 4 bytes of kernel stack data. The update also addresses unspecified security issues in NFS and telnet, updates OpenSSL to 3.0.21, Xorg to 21.1.24, and xkbcomp to 1.5.0, and includes fixes for libXpm CVE-2026-4367 and unbound CVE-2025-11411. Administrators should upgrade NetBSD 10 systems, updating the kernel and modules before userspace when using a manual upgrade path.

    PatchNetBSD 10.2

Tuesday, Sep 2218 stories

  1. Patchstack
    CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch

    Patchstack observed active probing for CVE-2026-87902 less than five hours after WordPress 7.1.2 was released. The unauthenticated path traversal flaw affects WordPress Core 4.7.0 to 7.1.1 and can lead to local file inclusion and, under certain server conditions, RCE; administrators should update to 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the applicable backport through 4.7.37.

    Reported exploitedWordPress Core
  2. BleepingComputer
    Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

    A Chinese-speaking threat actor linked to Red Heron exploited WordPress Core wp2shell flaws CVE-2026-63030 and CVE-2026-60137 to breach organizations, including government targets, and steal database records containing passwords and PII. The campaign also exploited ZyXEL GS1900 Smart Managed Switches flaw CVE-2026-7273 and targeted PAN-OS GlobalProtect, FlowiseAI CVE-2026-56271, Ubiquiti UniFi OS CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, Linux CVE-2022-0847, Gitea CVE-2026-60004, Nuclio CVE-2026-79756, SENAITE LIMS CVE-2026-54569, and Proxmox VE CVE-2023-54391. Organizations should review GreyNoise IoCs and patch exposed systems, as the activity resulted in stolen credentials, device configurations, and sensitive records.

    Reported exploitedWordPress
  3. The Hacker News
    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Check Point says CVE-2026-93616 was used in targeted attacks against its Security Management Server on July 23. The path traversal vulnerability can let an unauthenticated attacker upload and execute scripts through the server's web service, so administrators should apply the fixes in sk1000171 and investigate for prior compromise. The company also reported exploitation attempts against CVE-2026-85102 on Check Point Spark Firewalls, a VPN certificate-validation flaw fixed on September 9.

    Reported exploitedCheck Point Security Management Server
  4. The Hacker News
    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    WordPress has released fixes for CVE-2026-87902, a CVSS 9.2 core vulnerability affecting versions 4.7.0 through 7.1.1. An unauthenticated attacker could cause WordPress to load PHP files outside theme directories, which could lead to attacker-controlled code execution on certain server and theme configurations. Site owners should update to WordPress 7.1.2 or the applicable supported-branch release; no workaround is available.

    PatchWordPress
  5. The Hacker News
    Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

    JFrog researchers released proof-of-concept details for CVE-2026-90898, a CVSS 9.8 flaw in Bifrost AI Gateway that lets unauthenticated attackers launch commands through MCP client registration when management authentication is disabled. All Bifrost HTTP transport versions before 2.1.0 are affected; operators should update to transports/v2.1.0 and rotate provider credentials if an exposed instance ran without authentication. The research also covers CVE-2026-86242, fixed in transports/v2.0.0, which can enable code execution on dynamically linked builds or SSRF on statically linked builds.

    PoC publicBifrost AI Gateway
  6. BleepingComputer
    Check Point warns of Management Server zero-day exploited in attacks

    Check Point has released R82.20 Security Hotfix for CVE-2026-93616, an actively exploited path traversal vulnerability affecting Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Unauthenticated attackers can upload and run arbitrary scripts, so organizations should apply the hotfix, review indicators of compromise, and restrict management access to trusted IP addresses where immediate patching is not possible.

    Reported exploitedCheck Point Security Management Server
  7. The Hacker News
    Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

    A public proof of concept named BigDiskBuster can prevent Microsoft Defender from downloading platform and signature updates by exhausting free space on the C:\ drive. The tool has no assigned CVE and no Microsoft patch or advisory; it may leave Defender running with outdated detection content, although its claimed behavior has not been independently verified. It differs from the previously patched UnDefend issue, CVE-2026-45498, which Microsoft addressed in Antimalware Platform version 4.18.26040.7.

    PoC publicMicrosoft Defender
  8. Patchstack
    WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE

    WordPress 7.1.2 addresses CVE-2026-87902, an unauthenticated local file inclusion flaw in page template resolution affecting WordPress Core from 4.7.0 through 7.1.1. The issue can allow remote code execution under certain server configurations, so administrators should apply the available fixed release as soon as possible.

    ResearchWordPress
  9. BleepingComputer
    D-Link warns of max severity zero-day bug in DIR-822A routers

    D-Link has disclosed two unpatched vulnerabilities with public PoC code affecting legacy DIR-822A dual-band Wi-Fi routers: CVE-2026-86296 and CVE-2026-86510. CVE-2026-86296 is an unauthenticated DHCP server stack buffer overflow that could let an attacker on the local network crash the service or execute code, while CVE-2026-86510 can cause memory corruption on devices using L2TP or L2TPv6 WAN connectivity. D-Link is investigating and developing fixes; customers should keep these routers off the internet, limit remote management, and restrict administrative access to trusted systems.

    PoC publicDIR-822A
  10. The Hacker News
    New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

    Arista Networks says attackers are actively exploiting CVE-2026-93952, a CVSS 10.0 vulnerability in on-premises VeloCloud Orchestrator deployments using certificate-based Edge authentication. A remote unauthenticated attacker with network access to the VCO web interface and an Edge certificate's public portion could access privileged internal functions, compromise the orchestrator, and potentially reach managed Edge devices. Fixed releases are available for 5.2 and 6.4, while fixes for affected 6.1 and 7.0 releases are pending; organizations should restrict VCO web access and monitor for signs of compromise.

    Reported exploitedVeloCloud Orchestrator
  11. SecurityWeek
    Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

    Chinese threat actor Red Heron has exploited CVE-2026-7273, a CVSS 8.8 unauthenticated stack-based buffer overflow in ZyXEL GS1900-series switches. GreyNoise observed attacks in 48 countries that used crafted HTTP requests to run commands and steal hashed root credentials, device configurations, and network data from 996 systems. ZyXEL released updates for ten affected models in June, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog after the campaign exposed many devices still using factory-default credentials.

    Reported exploitedGS1900-series switches
  12. The Hacker News
    New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    CVE-2026-89775 in Linux Kernel ARM64 KVM can let a guest virtual machine retain read-write access to freed host kernel memory when nested virtualization is enabled, potentially enabling a guest-to-host escape. The issue is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1; no exploitation or public exploit code has been reported, and ARM64 nested virtualization is disabled by default.

    PatchLinux Kernel
  13. The Hacker News
    SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

    Technical details and a public proof of concept show that CVE-2026-65660 in Microsoft SharePoint Server can enable authenticated remote code execution, despite initially being described as a spoofing issue. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition, where crafted web-part markup can bypass SafeControls checks and load arbitrary .NET classes. Microsoft patched the issue in its August 11 security updates; no in-the-wild exploitation has been reported.

    PoC publicSharePoint Server
  14. Help Net Security
    Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

    A Chinese-speaking threat actor exploited CVE-2026-7273 in unpatched ZyXEL GS1900 Smart Managed Switches, compromising 996 devices in 48 countries and stealing configurations, network details, and hashed root credentials. The stack-based buffer overflow affects firmware 2.90(XXXX.1)C0 and earlier and enables unauthenticated command execution over LAN; CISA has listed it as exploited, while CVE-2026-32996 in Veeam Agent for Windows is also under active attack and should be remediated by upgrading Veeam Backup & Replication to 13.0.2.29 or later.

    Reported exploitedZyXEL GS1900
  15. BleepingComputer
    New Windows Defender zero-day blocks Microsoft antivirus updates

    Researcher Abdelhamid Naceri released BigDiskBuster, a proof of concept that can prevent Windows Defender from receiving platform and signature updates on supported Windows versions while it runs in the background. The update-blocking issue has no CVE ID or vendor patch yet; it follows other Defender flaws, including ShieldBreak, tracked as CVE-2026-69414.

    PoC publicWindows Defender
  16. BleepingComputer
    CISA orders feds to patch Zyxel flaw exploited for data theft

    CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in ZyXEL GS1900 switches, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply fixes by Thursday. Crafted HTTP requests can allow an unauthenticated attacker on the LAN to execute operating-system commands, creating a path to device compromise and data theft. GreyNoise reports that a suspected Chinese-speaking actor exploited the flaw to steal data from 996 ZyXEL switches across 48 countries; organizations using affected GS1900 models should update to Zyxel's patched firmware releases.

    Reported exploitedZyXEL GS1900
  17. The Hacker News
    WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

    WordPress has fixed CVE-2026-93485, known as Comment2Shell, an issue that could let an anonymous commenter inject script into a page. If a logged-in administrator viewed the affected comment, the script could abuse that session to upload a malicious plugin and execute code on the server. The flaw affects WordPress 4.7 through 7.1; update to WordPress 7.1.1 or the fixed release for the supported branch. No exploitation has been reported.

    PatchWordPress
  18. The Hacker News
    Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

    CISA has added CVE-2026-7273, an actively exploited stack-based buffer overflow in Zyxel GS1900 series switch firmware, to its KEV catalog. The flaw affects specified GS1900 models through their listed 2.90 firmware releases and can let an unauthenticated LAN attacker run operating-system commands through a crafted HTTP request; federal agencies must apply fixes by September 24, 2026. Arctic Wolf also reported active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows, where a local attacker can reuse exposed elevated session identifiers to execute commands with SYSTEM privileges.

    Reported exploitedZyxel GS1900 series switches

Monday, Sep 217 stories

  1. Check Point Research
    21st September – Threat Intelligence Report

    Check Point's weekly report says Cisco is aware of active exploitation of CVE-2026-76460 in Cisco Identity Services Engine, which can give unauthenticated remote attackers access to the management interface; Cisco also fixed CVE-2026-76461 in Secure Email Gateway. Check Point patched CVE-2026-91843 in Security Management and Log Servers, Oracle addressed more than 800 flaws including in Oracle E-Business Suite, and ISC updated BIND 9 for 14 issues, including CVE-2026-77692; the roundup also covers breaches affecting Japan Digital Agency Government Solution Service, Brevo, and Gyazo, plus the WaterPlum campaign.

    Reported exploitedJapan Digital Agency Government Solution Service
  2. BleepingComputer
    CISA alerts of active exploitation of three Linux kernel flaws

    CISA has added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux Kernel to its Known Exploited Vulnerabilities catalog after confirming their use in attacks. The flaws involve AFALG cryptographic sockets, ebtables SNAT, and the kTLS receive path, with potential consequences including memory corruption, system crashes, altered cryptographic behavior, and privilege escalation. Federal agencies must apply available mitigations and updates and perform forensic triage on affected assets.

    Reported exploitedLinux Kernel
  3. Dark Reading
    ShinyHunters Hacked Clop. Now What About Clop's Victims?

    ShinyHunters claims it compromised rival ransomware group Clop's leak-site server by abusing an unauthenticated file-upload flaw in Grav CMS, though the alleged theft of server data has not been independently confirmed. The group has threatened to disclose information about organizations that paid Clop, including companies targeted in the Oracle E-Business Suite campaign tied to CVE-2025-61882. If victim records were obtained, affected organizations could face further data exposure or renewed extortion even after dealing with Clop.

    IncidentGrav CMS
  4. The Hacker News
    ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

    Cisco disclosed active exploitation of CVE-2026-76460, a CVSS 10.0 authentication-bypass flaw in Identity Services Engine (ISE) that can give remote unauthenticated attackers access to affected devices. The weekly roundup also covers Plugin4Shell, a SHA-pinning bypass enabling zero-click RCE in Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI, alongside CVE-2026-32882 in Discourse community forum, fixed upstream in libheif 1.22.0. Other incidents include ClickFix campaigns, Brevo's supply-chain compromise, and KREMLIN malware targeting Google Chrome and Microsoft Edge credentials.

    Reported exploitedCisco Identity Services Engine
  5. SecurityWeek
    Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

    CISA has added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its Known Exploited Vulnerabilities catalog, confirming exploitation of three Linux kernel flaws. The issues can enable denial of service, memory disclosure or corruption, unpredictable cryptographic results, and unauthorized memory modification through affected TLS, AFALG socket, and bridge Netfilter ebtables SNAT code. Federal agencies have been directed to remediate all three vulnerabilities within three days.

    Reported exploitedLinux Kernel
  6. ESET WeLiveSecurity
    The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

    ESET says SMBs adopting AI agents face new risks from excessive permissions, malicious skills, supply-chain changes, and prompt injection. The report highlights Microsoft 365 Copilot and CVE-2025-32711, where indirect prompt injection could expose data, while warning that AI is also accelerating phishing, vulnerability exploitation, and ransomware activity.

    Reported exploitedAI Agents
  7. Google Project Zero
    Windows Exploitation Techniques: Dangling COM Object Registrations

    Microsoft has fixed CVE-2026-66804, a Windows privilege-escalation flaw involving a dangling registration for the CrossDevice COM object. The issue, an incomplete remediation for CVE-2026-50343, could let a local user place a DLL in a writable ProgramData path and have it loaded by a privileged COM service. Google Project Zero shows how custom COM marshaling and the Shell Create Object Handler could be used to reach SYSTEM-level code execution.

    ResearchWindows COM

Sunday, Sep 201 story

  1. Help Net Security
    Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

    This week’s security news includes Cisco patches for actively exploited flaws in Cisco Secure Email Gateway (CVE-2026-76461) and Cisco Identity Services Engine (ISE) (CVE-2026-76460), as well as targeted exploitation of an Acronis backup plugin issue (CVE-2026-87886). Researchers also disclosed that Parallels Desktop flaw CVE-2026-90894 can let a local Mac user obtain root access, while Revolut confirmed a breach involving customer records obtained through government-agency impersonation.

    Reported exploitedRevolut

Saturday, Sep 196 stories

  1. BleepingComputer
    BragJack attacks hijack AI browser agents through malicious extensions

    Researcher Gal Weizman demonstrated BragJack, a proof-of-concept technique in which an already-installed malicious extension can take over AI browser assistants in Google Chrome's Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic's Claude in Chrome. The flaws can enable access to sensitive browser data and cause agents to perform actions for victims; Google fixed CVE-2026-0628 and Microsoft fixed CVE-2026-55945. Users should update their browsers and review extensions with broad site-data permissions.

    PoC publicGoogle Chrome
  2. BleepingComputer
    ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

    ShinyHunters breached and defaced the Clop (Cl0p) ransomware group's Tor leak site after claiming to exploit an unauthenticated file upload flaw in Grav CMS. The group says it took server logs, source code, Grav CMS plugins, and onion-service private keys, although only the uploaded file and defacement have been independently confirmed. The incident follows a dispute tied to Clop's Oracle E-Business Suite campaign, which exploited CVE-2025-61882, and ShinyHunters says it intends to extort Clop over the alleged theft.

    Reported exploitedGrav CMS
  3. The Hacker News
    Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

    Hacktron researchers used Claude Opus 5 to combine CVE-2026-32882 in libheif with an OpenAI single sign-on flaw, gaining access to ChatGPT and Codex accounts belonging to OpenAI employees. The controlled research led to a harmless pull request in an internal OpenAI repository; the team reported the issues, and OpenAI fixed its login-side flaw and paid a $6,500 bounty. Discourse instances running unpatched libheif 1.19.7 should rebuild with a fixed release, as image-processing exposure and shared SSO can turn a public-service compromise into broader account access.

    ResearchDiscourse
  4. The Hacker News
    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    SolarWinds has fixed CVE-2026-28326, an 8.8-severity hard-coded static key issue in Access Rights Manager (ARM) that could allow unauthenticated remote code execution. All versions of Access Rights Manager 2026.2 and prior are affected; the company addressed the flaw in ARM 2026.2.1 and has not reported active exploitation. SolarWinds also recently resolved Web Help Desk flaws CVE-2026-28323 and CVE-2026-28299 in WHD 2026.2.1, and released Serv-U fixes for CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321, CVE-2026-28323.

    PatchSolarWinds Access Rights Manager
  5. The Hacker News
    Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

    Attackers are actively exploiting CVE-2026-58138, a pre-authentication remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2. Crafted workflow definitions can abuse unsandboxed JavaScript or Python evaluation to run operating-system commands as the Conductor process; organizations should upgrade to Conductor 3.30.2 or later and restrict access to workflow API endpoints.

    Reported exploitedOrkes Conductor
  6. The Hacker News
    CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

    CrowdSec says an attacker used a former employee's GitHub OAuth token to copy about 170 private repositories after the TanStack npm supply-chain attack tracked as CVE-2026-45321. Malicious TanStack npm packages stole developer credentials, and CrowdSec had not yet removed the former employee's GitHub access when the repositories were copied. The archive later published online included private source code, 83 user email addresses, and information on 51 potential investors; CrowdSec says its infrastructure and databases were not accessed and exposed credentials have been rotated.

    Reported exploitedTanStack

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store