CVE Tools

Security news, decoded.

75 stories in the last 7 days, naming 205 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 22 of 36 · newest first · times in UTC

Thursday, Jul 99 stories

  1. SecurityWeek
    Palo Alto Networks Patches 13 VulnerabilitiesPatchPalo Alto Networks products
  2. Help Net Security
  3. SecurityWeek
  4. SecurityWeek
    Microsoft Patches Defender ‘RoguePlanet’ Vulnerability

    Microsoft has issued patches for a vulnerability in Microsoft Defender, known as RoguePlanet, identified as CVE-2026-50656. The flaw allows attackers to escalate privileges due to a race condition. A proof-of-concept exploit was published by researcher Nightmare Eclipse on June 9, though it had limited reliability at the time. Microsoft addressed the issue through an automatic update to the Microsoft Malware Protection Engine, requiring no manual action from users. While there are currently no reports of exploitation, previous vulnerabilities from the same researcher have been used in attacks.

    PatchMicrosoft Defender
  5. The Hacker News
    Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

    Microsoft has issued a security update for a critical privilege escalation flaw in the Microsoft Malware Protection Engine, known as RoguePlanet (CVE-2026-50656). The vulnerability allows attackers to gain SYSTEM-level privileges through a race condition in 'mpengine.dll'. It affects the core component responsible for malware scanning and detection. The fix is included in version 1.1.26060.3008 of the engine. While no active exploitation has been reported, the flaw could enable arbitrary code execution or unauthorized system access.

    PatchMicrosoft Malware Protection Engine
  6. BleepingComputer
    Microsoft patches RoguePlanet Defender zero-day vulnerability

    Microsoft has issued a security update to resolve the zero-day vulnerability known as 'RoguePlanet' (CVE-2026-50656), affecting Microsoft Defender on fully patched versions of Windows 10 and Windows 11. The flaw allows attackers to gain SYSTEM-level privileges through a race condition in the security software, regardless of real-time protection settings. A proof-of-concept exploit was publicly shared by researcher Nightmare Eclipse, who has previously reported several other high-profile vulnerabilities. The issue was resolved with the release of Microsoft Malware Protection Engine version 1.1.26060.3008.

    PoC publicMicrosoft Defender
  7. The Hacker News
    Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

    Researchers have demonstrated a novel method to bypass the safety mechanisms of AI coding assistants, using a technique dubbed 'Friendly Fire.' The attack targets Anthropic's Claude Code and OpenAI's Codex when operating in autonomous modes—specifically versions 2.1.116–2.1.199 of Claude Code and 0.142.4 of Codex. By embedding a malicious script within a seemingly benign README.md file in an open-source project, attackers can trick the AI agent into executing arbitrary code on the host machine. The vulnerability lies in how these tools interpret and act upon instructions found in documentation files, rather than in their core codebase. While no active exploitation has been reported, the flaw highlights a critical design issue that cannot be resolved through model updates alone. Developers are advised to avoid running untrusted code through command-capable agents unless strict manual oversight is applied.

    ResearchClaude Code
  8. SecurityWeek
    Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices

    A security researcher uncovered an undocumented backdoor in several versions of Tenda firmware that allows attackers to gain administrative access to the device's web management interface. The flaw, tracked as CVE-2026-11405, resides in the login function of the web server binary and enables authentication bypass. Additionally, CERT/CC reported another vulnerability in HP Deskjet 2800 series printers (CVE-2026-13753), where unauthenticated access to API endpoints exposes sensitive information like Wi-Fi credentials and printer serial numbers. Both issues remain unpatched, and users are advised to disable remote web management and update their configurations to mitigate risks.

    AdvisoryTenda Firmware
  9. The Hacker News
    GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

    Researchers at Wiz discovered a vulnerability dubbed GhostApproval affecting six popular AI-powered coding assistants. By exploiting symbolic links (symlinks), attackers can trick developers into approving edits to seemingly harmless files—while the changes actually target critical system files such as SSH keys or shell configurations. The affected tools include Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. Three of the vendors have already issued patches, while two remain unpatched and one vendor, Anthropic, disputes the classification as a bug. The flaw allows malicious repositories to execute unauthorized actions by misleading the approval prompts shown to users. Wiz recommends updating to fixed versions and exercising caution when interacting with unfamiliar projects.

    ResearchAmazon Q Developer

Wednesday, Jul 813 stories

  1. Ars Technica (Security)
    Google pays $250K for Linux vulnerability allowing guest VM escapes

    A critical vulnerability in the KVM virtualization component of Linux, identified as CVE-2026-53359, enables untrusted guest virtual machines to achieve root-level access on the host system. This flaw, dubbed Januscape, resides within the shadow MMU emulation and could allow attackers to disrupt or take control of cloud environments. Discovered after remaining undetected for 16 years, it impacts both AMD and Intel-based systems using KVM. Researchers have demonstrated a proof-of-concept exploit that crashes the host OS from within a guest VM.

    ResearchKVM
  2. BleepingComputer
    Hackers exploit Roundcube flaw to spy on academic researchers

    A China-linked threat group has been exploiting vulnerabilities in Roundcube webmail servers at U.S. and Canadian universities to steal login details and install backdoor malware. The attackers, tracked as UNKMassTraction, have focused on institutions conducting research in physics, engineering, and national security. They use a cross-site scripting flaw (CVE-2024-42009) to deliver a credential-stealing payload named IceCube, followed by additional exploits like CVE-2025-49113 to gain deeper access. Security experts recommend applying the latest patches from Roundcube to mitigate these risks.

    Reported exploitedRoundcube
  3. Qualys Security Blog
    FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices

    A large-scale credential exposure campaign dubbed 'FortiBleed' is exploiting reused or previously stolen credentials to attack internet-reachable FortiGate and SSL-VPN gateways. The threat involves brute-force and password-spraying techniques, not a new zero-day vulnerability. Organizations using Fortinet products with exposed interfaces, weak authentication, or legacy hashes are at highest risk. Affected CVEs include CVE-2026-24858, CVE-2025-59718, and others. Immediate steps such as enforcing multi-factor authentication (MFA), rotating credentials, and completing PBKDF2 migration are strongly recommended.

    Reported exploitedFortiGate
  4. SecurityWeek
    China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

    A China-linked APT group, tracked as UAT-7810, has expanded its toolkit with new backdoor variants targeting SOHO routers from Ruckus and Asus. Researchers at Cisco Talos have uncovered updated malware families—LongLeash, DogLeash, and JarLeash—that exploit known vulnerabilities such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. These tools enable attackers to maintain persistent access, manage tunnels, and execute remote commands. The threat actor is also linked to a broader espionage campaign involving thousands of compromised devices.

    Reported exploitedRuckus wireless routers
  5. The Hacker News
    Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

    Ubiquiti has issued security updates to resolve several high-severity vulnerabilities affecting its UniFi product line, including UniFi Connect, Talk, Access, Protect, and OS. These flaws could allow attackers to perform command injections, escalate privileges, or manipulate devices through improper access controls. The affected CVEs include CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-55115, CVE-2026-54402, and CVE-2026-55116. While no active exploitation has been reported, the fixes are crucial due to the potential for remote code execution and unauthorized device manipulation.

    PatchUniFi Connect
  6. Help Net Security
    Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)

    Attackers are exploiting a recently cataloged vulnerability in Langflow (CVE-2026-55255), an open-source AI workflow framework, to harvest credentials and sensitive data. CISA added this insecure direct object reference (IDOR) flaw to its Known Exploited Vulnerabilities list on July 7, following active exploitation observed by the Sysdig Threat Research Team. The flaw enables authenticated attackers to execute another user’s flow using just the flow ID, potentially leading to cross-tenant data exposure and secret theft. Federal agencies have until July 10 to apply the fix, as mitigation is critical due to ongoing attacks.

    Reported exploitedLangflow
  7. SecurityWeek
    CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about actively exploited vulnerabilities in Adobe ColdFusion, Langflow, and two popular Joomla extensions. These flaws—CVE-2026-48282, CVE-2026-55255, CVE-2026-48908, and CVE-2026-56290—are being used by threat actors to gain unauthorized access and execute malicious code on affected systems. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities catalog and mandated that federal agencies apply patches within three days. Organizations using any of the impacted software should prioritize remediation immediately.

    Reported exploitedAdobe ColdFusion
  8. BleepingComputer
    CISA orders feds to prioritize patching Langflow auth bypass flaw

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies apply a critical security update by Friday to address an actively exploited vulnerability in Langflow, a widely used AI development framework. The flaw, identified as CVE-2026-55255, is an insecure direct object reference (IDOR) issue that permits authenticated attackers to access other users’ workflows and sensitive data through a malicious request. This vulnerability has already been observed being used in attacks aimed at achieving code execution and deploying implants. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the urgency of remediation under Binding Operational Directive 26-04.

    Reported exploitedLangflow
  9. The Hacker News
    China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

    Cisco Talos reports that the China-linked threat actor UAT-7810 is extending its Operational Relay Box (ORB) network by improving its custom malware, including an updated version of ShortLeash dubbed LONGLEASH along with new tools DOGLEASH and LEASHTEST. The campaign targets internet-facing networking gear, leveraging known issues in Ruckus wireless routers tied to CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, and also points at ASUS AiCloud Routers affected by CVE-2025-2492. This matters because ORB expansion can help secondary attackers gain infrastructure for further intrusion and exploitation against high-value targets.

    IncidentUAT-7810
  10. BleepingComputer
    Ubiquiti warns of new max severity UniFi OS vulnerability

    Ubiquiti has released security updates to address seven critical vulnerabilities across UniFi OS, including a maximum-severity command injection issue tracked as CVE-2026-50746. The flaw affects UniFi Connect Application (versions 3.4.16 and earlier) and could allow an attacker with network access to inject commands and compromise the host device. In addition, Ubiquiti patched six other critical-severity issues (CVE-2026-50747, CVE-2026-50748, CVE-2026-54400, CVE-2026-54402, CVE-2026-55115, CVE-2026-55116) affecting UniFi Talk, UniFi Access, UniFi Protect, the UniFi OS Server, and a range of Ubiquiti routers, gateways, NAS, and surveillance systems. With many UniFi OS instances exposed online, timely upgrades matter to reduce the risk of automated compromise.

    AdvisoryUniFi Connect Application
  11. BleepingComputer
    CISA orders feds to patch max severity ColdFusion flaw by Friday

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal civilian agencies to remediate an actively exploited, maximum-severity vulnerability in Adobe ColdFusion by Friday, June 10. The issue, tracked as CVE-2026-48282, impacts ColdFusion versions 2025.9 and 2023.20 (and earlier) and can allow remote attackers to execute code on unpatched systems without special privileges. Adobe has already released security updates and warned administrators to deploy them immediately, underscoring the fast-moving exploitation risk that prompted CISA to add CVE-2026-48282 to its Known Exploited Vulnerabilities catalog.

    Reported exploitedAdobe ColdFusion
  12. The Hacker News
    15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

    Researchers at Nebula Security disclosed GhostLock (CVE-2026-43499), a long-standing Linux kernel flaw (present since 2011) that allows a logged-in user on unpatched systems to gain full root privileges and break out of containers. The issue is triggered via ordinary local threading behavior with no special permissions or network access, making it a serious risk for multi-tenant hosts, cloud instances, CI runners, and shared environments. Nebula published working exploit code, underscoring the urgency of applying the latest kernel updates from affected distributions.

    PoC public
  13. The Hacker News
    CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

    The U.S. CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active in-the-wild abuse affecting Adobe ColdFusion, Joomlack Page Builder, JoomShaper SP Page Builder, and Langflow. The affected CVEs are CVE-2026-48282 and CVE-2026-56290 (both with CVSS 10.0), CVE-2026-55255, and CVE-2026-48908 (CVSS 10.0), spanning issues like path traversal and improper access control that can enable remote code execution and other takeovers. This matters because KEV-listed bugs are prioritized for remediation, with FCEB agencies advised to patch by July 10, 2026.

    Reported exploitedAdobe ColdFusion

Tuesday, Jul 712 stories

  1. BleepingComputer
    Chinese hackers develop LONGLEASH malware to expand ORB network

    Researchers at Cisco Talos say a China-aligned actor tracked as 'UAT-7810' is expanding its Operational Relay Box (ORB) infrastructure by compromising internet-exposed networking devices, with a focus on unpatched Ruckus routers. The campaign includes new malware components such as LONGLEASH (an upgraded SHORTLEASH backdoor) and others, and the initial access targets multiple vulnerabilities including CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 (as well as similar issues in ASUS AiCloud devices). This matters because ORB networks can proxy malicious traffic through seemingly legitimate local infrastructure, making detection and attribution significantly harder.

    IncidentRuckus routers
  2. BleepingComputer
    Hidden backdoor in Tenda router firmware grants admin access

    CERT/CC reports a hidden authentication backdoor in multiple Tenda router firmware builds, tracked as CVE-2026-11405 (and also referenced in the bulletin as CVE-2026-13753), that can grant full administrator access to the web management interface without needing the configured admin username. The issue affects Tenda devices including FH1201 (USFH1201V1.0BRV1.2.0.14(408)ENTD), W15E (USW15EV1.0brV15.11.0.5(10681567841)ENTDE), AC10 (USAC10V1.0reV15.03.06.46multiTDE01), AC5 (USAC5V1.0RTLV15.03.06.48multiTDE01), and AC6 V2 (USAC6V2.0RTLV15.03.06.51multiT). With no patch currently available, the practical impact is that attackers could reconfigure the device and weaken local-network security; users are advised to disable remote web management and reduce exposure to automated scanning.

    PatchTenda FH1201
  3. SecurityWeek
    Critical Gitea Flaw Under Active Exploitation, Researchers Warn

    Attackers are reportedly exploiting a vulnerability in Gitea’s reverse-proxy authentication logic to gain access to internet-reachable instances by providing only a valid username. The issue, affecting Gitea official Docker images before 1.26.3, is tracked as CVE-2026-20896 (CVSS 9.8) and can be triggered using a single HTTP header, enabling authentication bypass when reverse-proxy auth is configured incorrectly. Researchers say exploitation began shortly after disclosure, and organizations should upgrade to patched Gitea versions as quickly as possible to reduce risk of full compromise of repositories and secrets.

    Reported exploitedGitea
  4. SecurityWeek
    Critical Adobe ColdFusion Vulnerability Exploited in Attacks

    Attackers have started exploiting a critical path traversal vulnerability in Adobe ColdFusion shortly after it was made public, with proof of in-the-wild use reported for CVE-2026-48282 (CVSS 10/10). The flaw can enable arbitrary code execution, making it a high-impact risk for systems running Adobe ColdFusion versions patched by Adobe in ColdFusion 2025 update 10 and ColdFusion 2023 update 21. This matters because exploitation began within two hours of disclosure, leaving little time for organizations to validate and deploy mitigations before attackers moved.

    Reported exploitedAdobe ColdFusion
  5. BleepingComputer
    New Januscape Linux flaw allows VM escape on Intel, AMD devices

    A long-standing Linux kernel issue dubbed Januscape allows attackers inside a guest virtual machine to escape into the host, leading to arbitrary code execution or host crashes. The problem, tracked as CVE-2026-53359, is a use-after-free bug in KVM/x86 shadow MMU emulation and has been present for about 16 years before a June 2026 fix (commit 81ccda30b4e8). This matters for multi-tenant cloud environments running KVM, where exploitation can compromise other guests or cause denial of service.

    PoC publicLinux kernel
  6. Help Net Security
    Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)

    Active exploitation attempts have been observed against Adobe ColdFusion shortly after patches were released on June 30, 2026. The targeted issue is CVE-2026-48282, a path traversal vulnerability that can be abused by remote, unauthenticated attackers to upload a malicious file and trigger arbitrary code execution via a web-accessible location. This matters because attackers can leverage the Remote Development Services (RDS) feature when it is enabled and access is not properly restricted, so organizations running affected ColdFusion versions should urgently update and hunt for suspicious artifacts.

    Reported exploitedAdobe ColdFusion
  7. Cisco Talos
    UAT-7810 continues building ORB networks using new malware

    Cisco Talos reports that the China-nexus APT actor UAT-7810 continues expanding LapDogs Operational Relay Box (ORB) networks, adding new malware capabilities to support follow-on attacks on high-value targets. The actor is developing an updated version of SHORTLEASH tracked as LONGLEASH and has introduced additional backdoors including DOGLEASH and the Java-based JARLEASH for remote administration. Talos also observed UAT-7810 exploiting unpatched Ruckus wireless routers using CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717, underscoring the risk of ORB-based persistence and device compromise when these vulnerabilities remain unremediated.

    ResearchRuckus wireless routers
  8. SecurityWeek
    Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

    A newly reported Linux kernel issue, tracked as CVE-2026-53359 and dubbed Januscape, can be exploited by a guest VM to corrupt host state and gain execution on the underlying system via the KVM shadow MMU. This matters for multi-tenant x86 cloud environments—especially those with nested virtualization—because successful exploitation can lead to full host compromise, denial of service, or root-level code execution. Researchers note the flaw was present for 16 years and has been patched in the mainline kernel as of June 19.

    ResearchLinux Kernel
  9. The Hacker News
    Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

    A suspected China-aligned threat group has been observed targeting Roundcube webmail used by physics and engineering departments at U.S. and Canadian universities, enabling credential theft and persistent access. The campaign chains exploitation of CVE-2024-42009 (XSS) and then leverages CVE-2025-49113 for remote code execution, with payloads such as VShell for post-compromise activity; Proofpoint tracks the activity as UNKMassTraction. This matters because opening a crafted email in the Roundcube client can trigger access to the mail server, turning email delivery into a practical path to compromise.

    Reported exploitedRoundcube webmail
  10. BleepingComputer
    BeyondTrust warns of critical flaws in remote access software

    BeyondTrust has disclosed critical issues in its Remote Support (RS) and Privileged Remote Access (PRA) products that could let attackers bypass authentication and reach protected appliances. The company cites CVE-2026-40138 (RS and PRA versions 25.3.2 or earlier) and CVE-2026-40139, where improper handling of RS authentication requests could allow unauthenticated remote attackers to gain unauthorized access. BeyondTrust also released fixes for CVE-2026-40140 and CVE-2026-40141 affecting unpatched RS and PRA instances, which can lead to denial-of-service or unintended access to restricted resources, making patching urgent.

    PatchRemote Support (RS)
  11. The Hacker News
  12. The Hacker News

Monday, Jul 66 stories

  1. Dark Reading
    CitrixBleed-ing Again? NetScaler Vulnerability Under Attack

    Citrix disclosed CVE-2026-8451, a memory overread issue in NetScaler ADC and NetScaler Gateway devices configured as a SAML identity provider (IDP), with a CVSS score of 8.8. Researchers and security vendors report that threat actors are actively scanning for and using a proof-of-concept-style exploit, potentially leaking sensitive information and enabling further compromise (including privilege escalation and lateral movement). Organizations using affected NetScaler systems should prioritize applying the fixed versions and reviewing SAML IDP activity for suspicious events.

    Reported exploitedNetScaler Application Delivery Controller
  2. The Hacker News
    Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

    Check Point reports that the Iran-linked threat cluster “Cavern Manticore” is using a previously undocumented modular command-and-control framework called Cavern (aka Cav3rn) to target Israeli organizations, with IT service providers and government entities among the main focuses. The activity leverages SysAid software update functionality to trigger DLL side-loading and then delivers additional payload modules via the Cavern agent, enabling tailored reconnaissance, data theft, and lateral movement while complicating analysis through mixed compilation formats. Separately, CVE-2025-52691, CVE-2025-68613, CVE-2025-9316, CVE-2025-34291, and CVE-2025-54068 are referenced as part of broader exploitation activity tied to the same state-linked operations.

    IncidentCavern Manticore
  3. The Hacker News
    16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

    A use-after-free bug in Linux’s KVM shadow MMU can be triggered from a guest VM to corrupt host kernel shadow-page state, with a public proof-of-concept able to panic the host. The issue, tracked as CVE-2026-53359 (“Januscape”), affects KVM on Intel and AMD x86 systems and matters because a malicious tenant could potentially crash the host and, in reported research, even reach host code execution under the right conditions (root in the guest and nested virtualization enabled). Fixes have been merged as commit 81ccda30b4e8 and stable releases include kernel versions such as 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, and 5.10.260.

    PoC publicKVM Hypervisor
  4. Dark Reading
    JadePuffer: The First Complete LLM-Driven Ransomware Attack

    Researchers reported “JadePuffer,” an LLM-driven ransomware operation attributed to an “agentic” threat actor that carried out extortion with no human operator during key stages. The attack began by exploiting CVE-2025-3248 in an Internet-facing Langflow deployment, then moved to compromise a production database server running a MySQL database and an Alibaba Nacos configuration service to enumerate, exfiltrate selected data, delete it, and demand payment. The incident matters because it demonstrates a full, automated ransomware lifecycle that can adapt in real time—highlighting the need to patch Langflow quickly and avoid exposing code-execution endpoints to the Internet.

    Reported exploited
  5. The Hacker News
    Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

    Threat actors have been seen probing recently fixed Gitea Docker images for a critical authentication weakness tracked as CVE-2026-20896 (CVSS 9.8). The issue occurs when the Docker image default trusts all source IPs for the X-WEBAUTH-USER header, which can allow unauthenticated attackers to gain elevated access if reverse-proxy authentication is enabled and the allowlist is not restricted. This affects Gitea Docker image versions before and including 1.26.2, with the fix provided in version 1.26.3.

    Reported exploitedGitea Docker Images
  6. BleepingComputer
    Max severity Adobe ColdFusion flaw now exploited in attacks

    Attackers are exploiting a max-severity Adobe ColdFusion vulnerability, CVE-2026-48282, with KEVIntel reporting in-the-wild use shortly after public details emerged. The issue affects ColdFusion versions 2025.9, 2023.20, and earlier and can enable remote code execution without needing attacker privileges, making unpatched systems a priority risk. Adobe has released fixes and urged administrators to apply updates immediately, with Canadian and other monitoring efforts also warning defenders to remediate.

    Reported exploitedColdFusion

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store