CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 25 of 36 · newest first · times in UTC

Friday, Jun 2613 stories

  1. Help Net Security
  2. SecurityWeek
    Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets

    Security researchers report that the Russia-linked APT Turla has been using a new .NET espionage backdoor called StockStay to target Ukrainian government and military organizations, and in some cases related European entities. The malware has been delivered through phishing themes and can be installed via malicious RDP configuration files, with recent activity in November 2025 also leveraging exploitation of CVE-2025-8088 (WinRAR) for payload execution. This matters because the infection chain shows continued refinement of Turla’s initial access and stealthy command-and-control methods against high-value targets.

    Reported exploitedTurla
  3. SecurityWeek
    First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

    CVE-2026-12569 has been exploited by threat actors in real-world attacks, marking the first confirmed abuse of a PTC issue targeting the Windchill and FlexPLM product line. The vulnerability stems from improper input validation that can be triggered remotely without authentication to achieve arbitrary code execution. CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities (KEV) catalog, signaling urgency for remediation—important because Windchill is widely used in industrial and manufacturing environments, including critical supply chains and operational technology systems.

    Reported exploitedPTC Windchill
  4. Daily CyberSecurity (securityonline.info)
  5. The Hacker News
    Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

    Google Threat Intelligence has linked the Russian state-sponsored actor Turla to a previously unknown Windows .NET backdoor named STOCKSTAY, used against government and military targets in Ukraine and other organizations with Italian foreign policy interests. The malware is built from multiple cooperating components that communicate via a secure WebSocket channel and inter-process communication, and it has been used both for initial access and post-exploitation during operations where Turla also relies on Kazuar. Some delivery waves used archives exploiting CVE-2025-8088 (a WinRAR flaw), which matters because it can enable fast malware deployment to targeted environments.

    AdvisoryGoogle
  6. Daily CyberSecurity (securityonline.info)
  7. Daily CyberSecurity (securityonline.info)
  8. Daily CyberSecurity (securityonline.info)
    CISA Adds Cisco Unified CM and PTC Windchill Flaws to KEV CatalogReported exploitedCisco Unified Communications Manager
  9. Daily CyberSecurity (securityonline.info)
  10. Daily CyberSecurity (securityonline.info)
  11. Daily CyberSecurity (securityonline.info)
  12. Daily CyberSecurity (securityonline.info)
  13. Daily CyberSecurity (securityonline.info)
    Critical Event-Driven Ansible Flaw Leaks Stored CredentialsPatchRed Hat Ansible Automation Platform

Thursday, Jun 2519 stories

  1. Dark Reading
    In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

    In under 24 hours of proof-of-concept release, attackers started actively exploiting a critical Cisco Unified Communications Manager (CUCM) vulnerability to obtain root access. The issue, tracked as CVE-2026-20230, is an unauthenticated SSRF input validation flaw affecting Cisco Unified CM and Unified CM SME deployments when the WebDialer service is enabled. This matters because public exploit chains have been observed in the wild, enabling attackers to deploy web shells and escalate privileges on exposed systems; Cisco issued fixes on June 3 and organizations should patch or disable WebDialer if not required.

    Reported exploitedCisco Unified Communications Manager
  2. The Hacker News
  3. SecurityWeek
  4. SecurityWeek
  5. Daily CyberSecurity (securityonline.info)
  6. SecurityWeek
    25-Year-Old Vulnerability Patched in Curl

    The open source data transfer tool and library curl has shipped a security update addressing 18 vulnerabilities (four medium and 14 low). The most notable issue is CVE-2026-8932, affecting libcurl applications (not the curl command-line tool) and related to mTLS connection reuse that can enable authentication bypass; it traces back to behavior introduced in version 7.7. Other tracked flaws include CVE-2026-8926 (credential confusion), CVE-2026-8925 (double-free), CVE-2026-9080 and CVE-2026-10536 (use-after-free), and CVE-2026-9547 (improper host validation). Because curl is widely used across servers and devices, unpatched flaws in libcurl can be attractive targets for attackers.

    Patchcurl
  7. ESET WeLiveSecurity
  8. Daily CyberSecurity (securityonline.info)
  9. Daily CyberSecurity (securityonline.info)
  10. SecurityWeek
    Cisco SD-WAN Zero-Day Exploited Months Before PatchingReported exploitedCisco Catalyst SD-WAN Manager
  11. The Hacker News
    Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

    Mandiant reports that an unknown actor exploited a Cisco Catalyst SD-WAN zero-day tracked as CVE-2026-20245 (CVSS 7.8) well before public disclosure, achieving elevated execution by feeding a crafted file that bypasses insufficient input validation. The attack targeted Cisco Catalyst SD-WAN controllers and included credential and anti-forensics activity, with unauthorized peering connections also linked to CVE-2026-20127 and CVE-2026-20182 during earlier observed activity. This matters because edge network devices like Cisco Catalyst SD-WAN often lack deep telemetry, making detection and forensic investigation harder after compromise.

    Reported exploitedCisco Catalyst SD-WAN
  12. Daily CyberSecurity (securityonline.info)
    ManageEngine Account Takeover Flaw CVE-2026-11374

    Zoho disclosed a critical account takeover weakness, CVE-2026-11374 (CVSS 9.0), in zohocorp manageengineadselfserviceplus when deployed as part of ManageEngine AD360. The flaw allows unauthenticated attackers to predict SSO tickets, letting them obtain user identity/role information and take over targeted accounts. Organizations using affected builds—6528 or earlier, 6320 or earlier, 4816 or earlier, and 8702 or earlier—should upgrade to 6529, 6321, 4817, and 8703 immediately, as exploitation has not been confirmed in the wild.

    PatchADSelfService Plus
  13. Daily CyberSecurity (securityonline.info)
    Laravel Livewire Vulnerability Exposes Over 6,000 Apps

    A critical unauthenticated remote code execution issue in livewire/livewire (composer) has been actively exploited in the wild, tracked as CVE-2025-54068. Systems using versions = 3.0.0-beta.1 and < 3.6.4 are at risk during Livewire property update hydration, which can allow attackers to run arbitrary code and steal secrets from environments, including database credentials and cloud/payment tokens. With CVE-2025-54068 patched in 3.6.4, organizations should upgrade immediately to limit widespread data exposure.

    Reported exploitedLaravel Livewire
  14. Daily CyberSecurity (securityonline.info)
    Critical Langflow Flaws Allow Unauthenticated Remote Code Execution

    IBM disclosed two critical security issues in IBM Langflow OSS that can be triggered without authentication, including remote code execution in PythonREPLComponent via Builtins Injection (CVE-2026-10561) and an authorization bypass in the MCP transport endpoint (CVE-2026-7664). Both problems allow attackers to reach privileged functionality when instances expose the affected endpoints, making public-facing deployments especially risky. The report notes no confirmed exploitation so far, but it urges upgrading Langflow OSS to version 1.9.4 to remediate.

    PatchLangflow OSS
  15. Daily CyberSecurity (securityonline.info)
  16. Daily CyberSecurity (securityonline.info)
    Critical Gitea Security Flaws Expose Servers to Takeover

    A pair of critical security issues in Gitea could allow remote attackers to bypass authentication and perform Server-Side Request Forgery (SSRF) attacks, potentially leading to full takeover of administrative accounts. The affected vulnerabilities are tracked as CVE-2026-20896 (critical, impacts Gitea Docker deployments using reverse proxy authentication due to overly trusting proxy headers) and CVE-2026-22874 (high, allows incomplete SSRF filtering in webhook and repository migration paths). Both issues affect Gitea versions 1.26.2 and earlier, so administrators should upgrade to Gitea version 1.26.3 immediately.

    PoC publicGitea
  17. Daily CyberSecurity (securityonline.info)
  18. SANS Internet Storm Center
    What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary]

    A SANS Internet Storm Center assessment based on honeypot observations describes campaigns from TerraBot, r00ts3c, and rondo (aka: RondoDox) that repeatedly scan and attempt exploitation of devices and web services. The activity targets multiple flaws including CVE-2016-20017 (legacy D-Link DSL gateway routers) and CVE-2018-10561 (Dasan GPON routers), plus CVE-2016-20016 on legacy MVPower CCTV DVRs/JAWS Webserver RCE; later phases also include CVE-2025-34037 (Linksys E-series routers), CVE-2021-44228 (Log4Shell WAF Evasion), CVE-2023-48022 (ShadowRay), CVE-2023-26801 (LB-LINK command injection), and CVE-2018-6000 (ASUS AsusWRT NVRAM manipulation). The takeaway is that high-volume automation and quickly evolving payload chains can turn “background noise” into persistent, cross-environment risk—even when individual exploit attempts contain errors.

    ResearchDSL gateway routers
  19. Daily CyberSecurity (securityonline.info)
    CVSS 8.7 Unauthenticated RCE Impacts Multiple TP-Link Routers

    TP-Link has disclosed CVE-2026-11834, a high-severity command injection flaw that can lead to unauthenticated remote code execution for TP-Link Systems Inc. Archer MR200 v07 devices with affected firmware builds: < 1.3.0 Build 250605, < 1.5.0 Build 260605, < EUV1260330, < EUV5260317, < USV5260419, < V6260608 (+1 more). The issue stems from improper handling of externally provided DHCP options during device initialization, which can let a nearby attacker trigger arbitrary command execution without authentication. TP-Link reports no confirmed public exploitation yet, but the recommended mitigation is to upgrade to fixed releases such as 1.3.0 Build 250605 and 1.5.0 Build 260605 (and the corresponding EU/US builds listed by the vendor).

    PatchTP-Link Routers

Wednesday, Jun 248 stories

  1. BleepingComputer
    Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

    Mandiant has detailed how attackers exploited Cisco Catalyst SD-WAN command injection vulnerability CVE-2026-20245 to escalate privileges to root during zero-day attacks. The issue affects Cisco Catalyst SD-WAN Manager (vManage), Controller (vSmart), and Validator (vBond), enabling authenticated attackers to execute arbitrary commands as root by uploading a crafted file—leading to actions such as creating a rogue root account, altering credentials, and exfiltrating configuration data. This matters because it demonstrates a reliable path from initial access to full device control, with anti-forensic steps that can make detection and incident response harder.

    Reported exploitedCisco Catalyst SD-WAN
  2. Dark Reading
    Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure

    Mandiant reports that threat actors began exploiting a critical Cisco Catalyst SD-WAN flaw as early as March, about two months before Cisco’s early-June disclosure. The issue is tracked as CVE-2026-20245 and can let an attacker with administrator credentials execute commands that result in root-level access via the Cisco Catalyst SD-WAN Controller command-line interface. Because the vulnerability was added to CISA’s known exploited list and abused in attempts that also involved other SD-WAN Controller issues (CVE-2026-20182 and CVE-2026-20127), organizations should prioritize patching and hardening of Internet-facing network management components.

    Reported exploitedCisco Catalyst SD-WAN
  3. The Hacker News
    CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

    The U.S. CISA has issued an urgent warning that a critical vulnerability in Lantronix EDS5000 Series devices is being actively exploited in the wild. The issue, CVE-2025-67038 (CVSS 9.8), is a code injection weakness that can allow attackers to execute arbitrary commands with elevated/root privileges via the HTTP RPC logging behavior. CISA urged Federal Civilian Executive Branch agencies to apply the available fixes by June 26, 2026, highlighting the risk of full device compromise and potential broader network impact.

    Reported exploitedEDS5000
  4. BleepingComputer
    CISA warns of max severity Ubiquiti flaws exploited in attacks

    CISA says threat actors are taking advantage of high-impact vulnerabilities in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers, putting networks at risk of takeover and data exposure. The Ubiquiti issues listed as Known Exploited Vulnerabilities are CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which enable unauthorized changes, sensitive file access, and remote command execution, respectively; Bishop Fox also showed they can be chained for full remote code execution. For Lantronix, CVE-2025-67038 is a critical root-level command injection in HTTP RPC affecting EDS5000 firmware 2.1.0.0R3, with mitigation requiring an upgrade to EDS5000 version 2.2.0.0R1.

    Reported exploitedUniFi OS
  5. SecurityWeek
    macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

    XM Cyber demonstrated an attack on macOS in which a non-administrative user can silently disable enterprise endpoint security components, including EDR and MDM agents, without kernel exploits or triggering alerts. The technique chained abuse of weakly validated XPC connections with malicious payload injection into Interface Builder (NIB) files, and it was successfully demonstrated against CrowdStrike Falcon Sensor and Kandji MDM; CrowdStrike Falcon Sensor was fully unloaded from a standard account, while Kandji MDM was permanently deactivated. Kandji patched the issue and assigned CVE-2026-39118, underscoring the risk to environments that rely on these agents for detection and device management.

    ResearchmacOS
  6. SecurityWeek
    Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs

    CISA says threat actors are targeting multiple critical vulnerabilities in Ubiquiti UniFi OS devices—tracked as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 (CVSS 10.0)—which were patched by Ubiquiti last month. These issues include an authentication access control bypass (CVE-2026-34908), a path traversal that can enable manipulation of OS files to reach underlying accounts (CVE-2026-34909), and a command injection reachable over the network (CVE-2026-34910). Because UniFi OS is used for centralized infrastructure management, exploitation could enable attackers to gain footholds and move laterally; CISA added the three CVEs to its Known Exploited Vulnerabilities catalog, urging rapid remediation.

    Reported exploitedUniFi OS
  7. Dark Reading
    Apple's MacOS Gap Lets Users Disable Security Tools

    Researchers from XM Cyber reported a macOS privilege-escalation technique that lets a non-administrator disable enterprise security tooling by impersonating trusted application components, leveraging how macOS caches and reuses application trust data (CDHash). The reported impact includes CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM), both of which can be neutralized without kernel exploits or triggering alerts. Kandji has released an updated Agent to address the issue tracked as CVE-2026-39118, underscoring why organizations should urgently review macOS XPC-based security products for mitigations.

    ResearchmacOS
  8. Kaspersky Securelist
    StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

    Kaspersky reports a previously undocumented malware family, SharkLoader, linked to a broader activity tracked as StrikeShark, which deploys Cobalt Strike Beacon on compromised systems. Initial access was observed by exploiting internet-facing products such as Microsoft Exchange (CVE-2021-26855) and Openfire (CVE-2023-32315), as well as other targets including CVE-2024-36401; the article also lists additional affected RCE/auth-bypass issues across multiple vendors (e.g., Apache Shiro CVE-2016-4437, Microsoft SharePoint CVE-2021-27076, Fortinet FortiOS CVE-2024-21762, Cisco IOS XE Web UI CVE-2023-20198). This matters because the activity combines public exploit code, webshell-based persistence, and DLL side-loading techniques to move quickly from intrusion to Cobalt Strike deployment across many countries and sectors.

    ResearchSharkLoader

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store