CVE Tools

Security news, decoded.

75 stories in the last 7 days, naming 205 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 23 of 36 · newest first · times in UTC

Monday, Jul 63 stories

  1. The Hacker News
  2. SecurityWeek
    Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

    A proof-of-concept exploit has been released for the Linux “Bad Epoll” issue, which is a race-condition use-after-free in the epoll subsystem. The vulnerability is tracked as CVE-2026-46242 and affects Linux kernels 6.4+ (including confirmation on Pixel 10 devices using kernel 6.6), where attackers may achieve kernel memory leakage and root privileges. Since this can be used to bypass privilege boundaries, it matters for desktops, servers, and Android systems that run affected kernels.

    PoC publicepoll
  3. Check Point Research
    6th July – Threat Intelligence Report

    Check Point Research reports multiple incidents this week, including ransomware cases impacting River Bank & Trust, Indra Group, Nidec Chaun Choung Technology, and a major Aflac Japan breach affecting nearly 4.4 million customers. The update also covers AI-driven threats such as LLM-generated ransomware that abuses Chrome’s File System Access API and AI domain “phantom squatting” used for phishing. On the vulnerability side, critical issues including CVE-2026-46817 (Oracle E-Business Suite), CVE-2026-46242 (Linux kernel Bad Epoll), CVE-2026-8451 (Citrix NetScaler), and CVE-2026-8037 (Progress Kemp LoadMaster) are emphasized due to exploitation risk and rapid weaponization.

    AdvisoryERP Systems

Sunday, Jul 52 stories

  1. Help Net Security
    New ClamAV security patch closes seven scanner bugs dating back two decades

    Cisco Talos’ ClamAV released security patch versions 1.5.3 and 1.4.5 to address seven vulnerabilities affecting its executable and archive parsing logic, plus quarantine handling hardening. The fixes cover CVE-2026-20213, CVE-2026-20214, CVE-2026-20217, CVE-2026-20215, CVE-2026-20243, CVE-2026-20216, and CVE-2026-20244, which can lead to memory corruption, crashes, scanner bypass conditions, or unstable behavior when processing crafted inputs. These updates also matter because ClamAV is commonly used in mail gateways and endpoint/file scanning workflows where attackers may leverage malformed files to disrupt or evade scanning.

    PatchClamAV
  2. Help Net Security
    Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

    Attackers are actively exploiting CVE-2026-48558 in SimpleHelp RMM, using the authentication-bypass weakness to deploy the Djinn Stealer malware across Windows, macOS, and Linux systems. In parallel, threat intelligence reports exploitation attempts against CVE-2026-46817 affecting Oracle E-Business Suite Payments, with the Oracle Payments module targeted via weekend activity. These incidents matter because they show how quickly patched (or still-fresh) enterprise flaws can be weaponized, increasing the urgency of remediation and monitoring for both vendors.

    Advisory

Saturday, Jul 41 story

  1. BleepingComputer
    JadePuffer ransomware used AI agent to automate entire attack

    Researchers report a ransomware case, JadePuffer, in which an autonomous LLM agent handled reconnaissance through credential theft, lateral movement, persistence, privilege escalation, and finally encryption. Initial access was achieved by exploiting CVE-2025-3248 in Langflow, with later impact on Alibaba Nacos also involving CVE-2021-29441 for an authentication bypass that enables rogue admin creation. This matters because AI-driven “agentic” malware could reduce the expertise needed to run full intrusion chains while also changing detection requirements for defenders.

    Researchlangflow

Friday, Jul 36 stories

  1. The Hacker News
    Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

    runZero disclosed seven vulnerabilities in FatFs, a filesystem library used to access FAT and exFAT volumes on removable storage. The issues are tracked as CVE-2026-6682, CVE-2026-6683, CVE-2026-6684, CVE-2026-6685, CVE-2026-6686, CVE-2026-6687, and CVE-2026-6688, including integer overflows that can lead to memory corruption and possible code execution when a device mounts attacker-controlled or malformed storage/update images. This matters because FatFs is bundled into many embedded platforms and firmware (e.g., Espressif ESP-IDF, STMicroelectronics STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, and the SWUpdate updater), expanding potential impact across consumer IoT, industrial systems, drones, and crypto wallets.

    PoC publicesp-idf
  2. The Hacker News
    New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

    A newly disclosed Linux kernel issue called “Bad Epoll” (CVE-2026-46242) enables unprivileged local users to gain root access. It impacts Linux systems and Android devices that run affected kernel builds, because an epoll use-after-free race can corrupt kernel memory and turn a normal account into full control. Fixes are available via upstream (commit a6dc643c69311677c574a0f17a3f4d66a5f3744b) and distribution backports, and timing makes the bug hard but the published proof of concept reliably achieves escalation on tested setups.

    PoC publiclinux kernel
  3. The Hacker News
    New Avalon Malware Framework Packs CrownX Ransomware Capabilities

    Researchers uncovered the modular malware framework Avalon, which uses a multi-stage phishing chain to bypass security controls and ultimately deploy a ransomware component internally tracked as CrownX. Avalon is designed to harvest credentials and browser data, establish remote access and lateral movement, suppress forensic visibility (including ETW interference), and then encrypt files while disrupting recovery using shadow copy removal. The same report also highlights a JADEPUFFER agentic ransomware campaign that gained access via CVE-2025-3248 affecting a Langflow instance, underscoring how readily AI-assisted tooling can accelerate ransomware development and attack execution.

    Research
  4. The Hacker News
    Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

    Security researchers attribute a campaign by the threat actor Armored Likho to attacks against government organizations and the electric power sector in Russia, Brazil, and Kazakhstan. The activity includes spear-phishing and malware that deploys BusySnake Stealer, a Python-based information stealer for Windows that can exfiltrate browser data (including cookies), screenshots, clipboard contents, and other sensitive material. The intrusion chain also leverages a Windows shortcut-related flaw, tracked as CVE-2025-9491 (aka ZDI-CAN-25373) and patched by Microsoft in November 2025, enabling remote code execution when LNK files are handled improperly.

    Researchgovernment agencies
  5. SecurityWeek
    Agentic AI Used to Conduct Ransomware Attack via Langflow

    A threat actor used agentic LLM-driven automation to carry out a ransomware operation after compromising internet-exposed Langflow via CVE-2025-3248, a critical missing authentication issue that enables arbitrary Python code execution on the host. The intruder tracked as JadePuffer then used AI-assisted reconnaissance and credential harvesting, before targeting a production MySQL and Alibaba Nacos setup, including abuse of CVE-2021-29441 and Nacos weaknesses tied to a default JWT signing key. This matters because it demonstrates how capable models can lower the barrier for large-scale, hands-off malicious actions against neglected and improperly hardened application and configuration infrastructure.

    Reported exploitedlangflow
  6. SecurityWeek
    Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution

    Cato Networks reports two critical vulnerabilities in the AI code editor Cursor that could enable remote code execution on the host operating system by escaping the IDE’s sandbox. The issues are tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8), collectively referred to as DuneSlide, and they can be triggered through crafted prompts that abuse Cursor’s automatic terminal command execution and weaknesses in file path handling involving symbolic links. This matters because a malicious payload could move from an injected IDE action to unrestricted OS-level code execution.

    Researchcursor

Thursday, Jul 214 stories

  1. The Hacker News
    Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

    Threat actors linked to the Anubis ransomware operation have been seen abusing Citrix Bleed 2 to gain initial access, specifically via CVE-2025-5777 affecting Citrix NetScaler ADC and Gateway (CVSS 9.3). The same reporting highlights their use of remote access tools, credential theft, RDP/PsExec for lateral movement, and follow-on data theft before deploying ransomware. In related ransomware activity, Kaspersky described The Gentlemen RaaS using a Go-based backdoor and weaponizing a BYOVD scenario involving the ktapi.sys driver for kernel-level abuse, while Sophos reported a VECT and TeamPCP supply-chain partnership that enables ransomware deployment across victims of Trivy and LiteLLM supply chain attacks. These developments matter because they combine high-impact exploitation and credential compromise with scalable “industrialized” deployment tactics that lower the barrier for attackers.

    Reported exploitednetscaler
  2. Cisco Talos
    Catan and Mouse

    Cisco Talos highlights ARToken, a phishing-as-a-service operator panel for Microsoft 365 focused on device code phishing, Primary Refresh Token (PRT) persistence, email access/BEC operations, and SharePoint exfiltration—capabilities exposed through 80+ API endpoints. Separately, Talos notes that a recently reported authentication bypass in SimpleHelp remote monitoring and management (RMM), tracked as CVE-2026-48558, has been exploited in the wild to obtain a fully authenticated technician session for malware delivery. These findings matter because they indicate both increasing maturity in credential/theft-driven phishing tooling and active exploitation of authentication weaknesses.

    Reported exploitedMicrosoft 365
  3. watchTowr Labs
    It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)

    Adobe has released APSB26-68 addressing a large set of security issues in Adobe ColdFusion, impacting ColdFusion 2025 (Update 9 and below) and ColdFusion 2023 (Update 20 and below). The bulletin includes fixes for multiple remote-impact vulnerabilities such as CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48283, CVE-2026-48313, CVE-2026-48315, CVE-2026-48307, CVE-2026-48285, and CVE-2026-48314. These issues matter because they can enable arbitrary file read/write and privilege escalation pathways—potentially escalating to remote code execution when vulnerable features are reachable and misconfigured.

    PatchAdobe ColdFusion
  4. The Hacker News
    ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

    Security coverage this week describes multiple weaknesses that let attackers slip through “allowed” paths, including AI compute hijacking via misconfigured Ollama model servers used as the reasoning engine in offensive tooling. Apple’s Hide My Email service has a reported flaw that can reveal users’ real addresses, while research also details an attack chain against Claude Cowork on Windows that can lead to root-level execution in its sandbox and potential data exfiltration. Separately, CISA confirmed Microsoft Defender’s BlueHammer (CVE-2026-33825) was exploited in ransomware attacks, underscoring how quickly real-world impact can follow once patching lags.

    ResearchApple Hide My Email
  5. SecurityWeek
    New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure

    Threat actors reportedly started attacking affected Citrix NetScaler ADC and NetScaler Gateways almost immediately after public disclosure, with exploitation observed in under 24 hours. The issue, tracked as CVE-2026-8451 (CVSS 8.8), is an out-of-bounds read in the NetScaler XML parser that can disclose memory contents via the NSCTASS cookie when appliances are configured as SAML IDP; no authentication is required for successful exploitation. This matters because the rapid weaponization suggests exposed internet-facing systems could be targeted quickly, so organizations should prioritize patching or mitigate by disabling SAML IDP and checking relevant logs and cookies.

    Reported exploitedCitrix NetScaler ADC
  6. Bishop Fox
  7. BleepingComputer
    Cisco finally confirms attackers exploiting Unified CM flaw

    Cisco has confirmed that attackers are actively exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June: CVE-2026-20230. The issue is a remote, low-complexity server-side request forgery (SSRF) that can be abused by attackers without privileges via crafted HTTP requests, potentially leading to file-related impacts on affected systems. This matters because it indicates real-world compromise is underway, and Cisco recommends upgrading to fixed releases and using mitigations like disabling the vulnerable WebDialer service when updates can’t be applied immediately.

    Reported exploitedCisco Unified Communications Manager
  8. BleepingComputer
    CISA: Microsoft SharePoint RCE flaw now actively exploited

    CISA says attackers are now actively using a high-severity remote code execution weakness in Microsoft SharePoint, tracked as CVE-2026-45659. The issue is caused by unsafe deserialization of untrusted data and can let authenticated attackers with minimal permissions run arbitrary code on unpatched SharePoint servers via low-complexity, network-based attacks. Microsoft has released fixes for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, and CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch by the applicable deadline.

    Reported exploitedMicrosoft SharePoint Server
  9. SecurityWeek
    Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability

    Cisco reports that CVE-2026-20230 has been exploited in the wild in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The issue stems from improper validation of certain HTTP requests and could enable SSRF-style activity that may ultimately allow arbitrary file drops and potential root access. This matters because only devices with the WebDialer service enabled are affected (disabled by default), and Cisco advises upgrading to fixed releases to remediate.

    Reported exploitedCisco Unified Communications Manager
  10. SecurityWeek
    CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability

    CISA says attackers are already exploiting a high-severity Microsoft SharePoint Server vulnerability that stems from unsafe deserialization of untrusted data (CVE-2026-45659, CVSS 8.8). The issue can allow an authenticated attacker with at least Site Member permissions to run arbitrary code on affected SharePoint servers, which makes it particularly dangerous and easy to repeat in practice. SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, and SharePoint Enterprise Server 2016 are affected, and CISA added CVE-2026-45659 to its KEV catalog with an expectation that federal agencies patch within three days.

    Reported exploitedMicrosoft SharePoint Server
  11. The Hacker News
    AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

    Security firm Sysdig reports what it believes is the first ransomware campaign end-to-end automated by an AI agent, operated by “JADEPUFFER.” The intrusion began with CVE-2025-3248 in Langflow (patched in Langflow 1.3.0), a missing-authentication issue that allows unauthenticated remote Python code execution—enabling rapid credential theft, lateral movement, and database encryption and deletion. The attack then leveraged additional weaknesses including CVE-2021-29441 to take over Nacos, underscoring how unpatched internet-exposed services can be chained into fully automated extortion.

    Reported exploitedLangflow
  12. The Hacker News
    FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

    The FortiBleed campaign, which focuses on harvesting credentials from exposed Fortinet FortiGate systems, has been linked by SOCRadar to INC and Lynx ransomware operations—suggesting stolen logins were used for follow-on intrusions. The activity involved probing roughly 11,250 FortiGate portals, gaining admin access on 409 targets, and completing the attack chain on 354, leading to at least 12 ransomware deployments and widespread endpoint encryption. Separately, eSentire reported active exploitation of Fortinet FortiClient EMS vulnerabilities tied to CVE-2026-35616 (CVSS 9.1), enabling deployment of EKZ Stealer to harvest browser credentials.

    Reported exploitedFortiGate
  13. The Hacker News
    New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

    Researchers from YesWeHack and Sekoia report that the Python-based trojan ChocoPoC is distributed through fake GitHub proof-of-concept repositories that look like fixes for newly disclosed issues. The payload steals credentials and local data, then provides remote command execution, affecting fake PoCs tied to CVE-2025-64446, CVE-2025-55182, CVE-2025-14847, CVE-2026-0257, CVE-2026-10520, CVE-2026-50751, and CVE-2026-48908. Because the malicious code is hidden in dependency packages (e.g., frint and skytext), simply reviewing the visible exploit file may miss the threat, making this a serious supply-chain risk for vulnerability researchers and downstream tooling.

    PoC public
  14. The Hacker News
    SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

    CISA has added the Microsoft SharePoint Server remote code execution flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities (KEV) catalog, citing indications that it is being actively exploited in the wild. The issue stems from deserialization of untrusted data and allows an authenticated attacker to run code remotely without requiring admin rights; Microsoft fixed it in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. This matters because it raises the priority for patching—CISA advises Federal Civilian Executive Branch agencies to remediate by July 4, 2026.

    Reported exploitedSharePoint Server

Wednesday, Jul 112 stories

  1. BleepingComputer
    ChocoPoc malware delivered via trojanized exploits on GitHub

    Forscher berichten, dass auf GitHub veröffentlichte, „waffenfähige“ PoC-Exploits den Python-basierten Remote-Access-Trojaner ChocoPoC ausliefern. Dabei werden nach dem Klonen eines Repository heimlich schädliche Python-Pakete von PyPI nachgeladen, die beim Ausführen zusätzliche Komponenten nachladen und letztlich ChocoPoC aktivieren; der Code kann u. a. Kommandos ausführen und Browserdaten sowie Host-Infos exfiltrieren. Betroffen sind u. a. PoCs für FortiWeb (CVE-2025-64446), React2Shell (CVE-2025-55182), MongoBleed (CVE-2025-14847), PAN-OS (CVE-2026-0257), Ivanti Sentry (CVE-2026-10520), Check Point VPN (CVE-2026-50751) und Joomla SP Page Builder (CVE-2026-48908) – wichtig, weil dies Test-/Research-Umgebungen durch glaubwürdig wirkende Code-„Beispiele“ kompromittieren kann.

    PoC publicChocoPoC
  2. BleepingComputer
    New ChocoPoC malware targets researchers via trojanized PoC exploits

    Researchers found weaponized PoC exploit repositories on GitHub that ultimately deliver the Python-based RAT ChocoPoC to victims, including researchers. The campaign relies on malicious packages fetched from PyPI during repository cloning, which then lead to execution, data theft, and command execution capabilities. At least seven PoC repos were tied to exploits for FortiWeb (CVE-2025-64446), React2Shell (CVE-2025-55182), MongoBleed (CVE-2025-14847), PAN-OS (CVE-2026-0257), Ivanti Sentry (CVE-2026-10520), Check Point VPN (CVE-2026-50751), and Joomla SP Page Builder (CVE-2026-48908), underscoring why running unverified PoCs or their dependencies can quickly turn vulnerability research into compromise.

    PoC publicChocoPoC
  3. The Hacker News
    Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

    Argo CD’s repo-server component contains an unpatched, unauthenticated remote code execution weakness that can allow attackers to run commands if they can reach its internal gRPC port, potentially leading to full Kubernetes cluster compromise. The issue affects Argo CD v2.13.3 and has no CVE or fixed release; researchers at Synacktiv report the flaw abuses kustomize’s --helm-command handling to execute attacker-controlled scripts. This matters because compromised repo-server access can be chained with prior exposure of Argo CD’s Redis cache behavior, re-enabling deployment poisoning similar to CVE-2024-31989—so administrators should verify Kubernetes network policies restrict repo-server and Redis access.

    Researchrepo-server
  4. The Hacker News
    Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

    Adobe has issued fixes for multiple highest-severity vulnerabilities affecting Adobe ColdFusion and Adobe Campaign Classic. In ColdFusion, multiple CVSS 10.0 issues (CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282) plus additional high-severity flaws (CVE-2026-48313, CVE-2026-48315) could enable arbitrary code execution, privilege escalation, arbitrary file reads, and security bypasses, with patches available in ColdFusion 2023 Update 21 and ColdFusion 2025 Update 10. Adobe Campaign Classic is also affected by CVE-2026-48286 (CVSS 10.0), where incorrect authorization can lead to arbitrary code execution; it is fixed in ACC v7: 7.4.3 build 9397 for affected on-premise Windows and Linux deployments.

    PatchColdFusion
  5. The Hacker News
    Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

    AI code editor Cursor has two critical issues, tracked as CVE-2026-50548 and CVE-2026-50549, where prompt injection can bypass Cursor’s command sandbox and execute arbitrary commands on a developer’s machine without any user click or approval. The flaws matter because they allow attackers to neutralize the safety boundary using seemingly normal inputs (such as content read via MCP or web results), potentially leading to full local compromise and access to connected workspaces. Cursor fixed both problems in Cursor 3.0; all versions prior to 3.0 are affected.

    PatchCursor AI Code Editor
  6. The Hacker News
    Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

    A critical Progress Kemp LoadMaster vulnerability is being actively exploited, with eSentire reporting targeting of CVE-2026-8037 (CVSS 9.6). The issue is an OS command injection in a pre-auth API path that can allow unauthenticated attackers to achieve arbitrary code execution on vulnerable appliances. Although observed exploitation attempts reportedly failed and did not progress further, the availability of proof-of-concept details may accelerate real-world attacks.

    Reported exploitedProgress Kemp LoadMaster
  7. The Hacker News
    AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

    Researchers report a new ransomware attack chain that was developed with DeepSeek and operates entirely within the browser on Google Chrome and other Chromium-based browsers on Windows and Android, using the File System Access API. The campaign centers on the malware sample InfernoGrabber v9.0 and a Python Flask application, which performs local file enumeration, exfiltration, encryption, and shows a “WinLocker” Bitcoin demand without installing a native payload. VirusTotal also links the code to browser exploitation routines involving CVE-2023-4863, underscoring how AI can turn speculative concepts into practical threats and why permission and browser security boundaries matter.

    ResearchInfernoGrabber
  8. BleepingComputer
    Over 900 Oracle E-Business instances exposed to ongoing attacks

    More than 900 Oracle E-Business Suite (EBS) instances are reportedly reachable online while attackers are actively targeting a critical issue, CVE-2026-46817, in the File Transmission component of Oracle Payments. The flaw can be abused by unauthenticated attackers with HTTP network access to take over vulnerable systems through low-complexity techniques, making exposure particularly risky for exposed deployments. Oracle has released fixes in its May 2026 Critical Security Patch Update, and defenders are urged to patch immediately as scanners such as Shadowserver continue to observe a large number of potentially vulnerable installations.

    Reported exploitedOracle E-Business Suite
  9. SecurityWeek
    Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities

    Adobe has issued security updates for ColdFusion and Adobe Campaign Classic to address multiple high-severity vulnerabilities, some rated 10/10. Adobe Campaign Classic patches include CVE-2026-48286, which could enable arbitrary code execution via an authorization weakness, with fixes shipped in version 7.4.3 build 9397 for Windows and Linux. For ColdFusion, updates for 2025 and 2023 resolve several issues including CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48283, along with other critical flaws such as CVE-2026-48313 and CVE-2026-48315, CVE-2026-48307, CVE-2026-48285, and CVE-2026-48314; these bugs stem from problems like unsafe file upload handling, input validation gaps, XSS, SSRF, and path traversal. Adobe notes no public exploits are known, but the updates are treated as high priority, so users should apply them promptly.

    PatchColdFusion
  10. SecurityWeek
    Citrix Patches NetScaler Vulnerabilities, Including New ‘HTTP/2 Bomb’ Attack

    Citrix has released new security updates for NetScaler ADC and NetScaler Gateway that address six vulnerabilities, including the recently publicized HTTP/2 Bomb denial-of-service flaw. Affected CVEs include CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816 (memory corruption and arbitrary file read issues), plus CVE-2026-49975 (an out-of-bounds read) and CVE-2026-13474 for the NetScaler-specific HTTP/2 Bomb behavior that can knock Apache HTTP Server offline. These issues matter because exploitation could enable service disruption and, for some bugs, memory-related data exposure; upgrade to the fixed NetScaler versions as indicated by Citrix and verify whether your configuration enables the vulnerable components.

    PatchNetScaler ADC
  11. BleepingComputer
    Adobe patches seven max severity ColdFusion, Campaign flaws

    Adobe has released updates addressing seven maximum-severity vulnerabilities across its ColdFusion web application platform and Adobe Campaign Classic marketing automation product. The ColdFusion issues (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, and CVE-2026-48282) affect ColdFusion versions 2025.9, 2023.20 and earlier and could enable remote code execution without user interaction or special privileges. A Campaign Classic flaw (CVE-2026-48286) affecting versions 7.4.3 build 9396 and earlier can allow arbitrary code execution in the context of the current user, and Adobe notes it impacts only on-premises instances.

    PatchColdFusion
  12. The Hacker News
    Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

    Citrix has released security updates for NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) to remediate six vulnerabilities that could let an attacker perform arbitrary file reads or cause denial-of-service conditions. Affected CVEs include CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474, impacting scenarios such as SAML parsing, gateway/AAA configurations, load balancing/DNS proxy deployments, and HTTP/2 handling. Fixes are available in specified 13.1 and 14.1 NetScaler releases, with additional configuration guidance required for CVE-2026-13474 via the Http2SmallWndTimeout setting when HTTP Strict Profiles are not used.

    PatchNetScaler ADC

Tuesday, Jun 302 stories

  1. watchTowr Labs
    CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)

    watchTowr Labs reports that Citrix has publicly disclosed a pre-auth memory disclosure issue, CVE-2026-8451, in Citrix NetScaler when the NetScaler appliance is configured as a SAML IDP. The vulnerability is described as insufficient input validation leading to memory overread, with affected products including NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61, NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18, NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS, and NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272. This matters because it can cause the appliance to include unintended memory contents in responses (e.g., within cookies), potentially exposing sensitive data to an unauthenticated attacker.

    ResearchNetScaler ADC
  2. The Hacker News
    RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

    Researchers from QiAnXin XLab report a two-stage malware family called RustDuck that compromises home routers, IP cameras, Android boxes, and exposed servers, then uses the infected devices to launch DDoS attacks. The campaign has been linked to multiple vulnerable products and vulnerabilities, including CVE-2017-17215, CVE-2025-29635, CVE-2024-1781, CVE-2024-1781, CVE-2018-8007, plus exposure to ThinkPHP, Jenkins, and Hadoop YARN issues. The risk is amplified by RustDuck’s active evolution and its use of modern encryption and anti-analysis checks, making detection and takedown harder.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store