CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 26 of 36 · newest first · times in UTC

Wednesday, Jun 248 stories

  1. Daily CyberSecurity (securityonline.info)
  2. The Hacker News
  3. SecurityWeek
    Hackers Exploiting Cisco Unified CM Vulnerability

    Security researchers report that CVE-2026-20230 in Cisco Unified Communications Manager (Unified CM) is being exploited in the wild shortly after Cisco released patches on June 3. The unauthenticated, remote issue can be leveraged for SSRF, arbitrary file writes to the underlying OS, and privilege escalation to root (with exploitation tied to enabling the WebDialer service, which is disabled by default). This matters because Unified CM is a widely deployed on-premises call control platform, making the flaw attractive for both criminal and state-sponsored actors.

    Reported exploitedCisco Unified CM
  4. Daily CyberSecurity (securityonline.info)
  5. Daily CyberSecurity (securityonline.info)
  6. Daily CyberSecurity (securityonline.info)
  7. Daily CyberSecurity (securityonline.info)
  8. Daily CyberSecurity (securityonline.info)

Tuesday, Jun 2317 stories

  1. Daily CyberSecurity (securityonline.info)
  2. BleepingComputer
  3. SecurityWeek
    Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

    SecurityWeek reports that four security issues in the open source AI platform Dify can be abused in multi-tenant cloud setups to access or exfiltrate data belonging to other customers. The affected vulnerabilities are tracked as CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, and CVE-2026-41950, and they impact components such as Dify tracing, the plugin daemon, and file handling/permissions, enabling actions like reading other tenants’ chats, previewing documents, and invoking cross-tenant APIs. Zafran further notes the preview endpoint relied on a vulnerable Chromium PDFium binary (126.0.6462.0) tied to CVE-2024-5846, and Dify version 1.14.2 is released with patches to address these findings—users should upgrade promptly and consider WAF mitigations for CVE-2026-41948.

    ResearchDify
  4. BleepingComputer
    The Exploit Doesn't Exist. You Can Still Prove It Works Against You

    A recent report highlights that exploit development is increasingly happening in hours rather than months, putting pressure on traditional remediation timelines and leaving gaps between patching and active attack development. It calls out the risk that even when exploitation details aren’t publicly available or can’t be safely tested, teams still need evidence-based exposure decisions—for example, Windows CLFS issue CVE-2025-29824 (CLFS use-after-free leading to SYSTEM). The takeaway: faster pentests aren’t enough when live firing isn’t possible, so organizations should validate the required attacker TTP chain against their actual controls instead of relying solely on CVSS/EPSS-style scoring.

    Research
  5. SecurityWeek
    Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks

    Researchers uncovered a long-standing high-severity vulnerability in Samsung’s KNOX kernel affecting nearly all Galaxy devices from Galaxy S9 through S25. The issue, tracked as CVE-2026-20971, can be triggered via interactions between PROCA and FIVE and may result in kernel memory corruption through a race-condition use-after-free scenario, even though exploitation is described as requiring local conditions and user interaction. Samsung addressed the problem in its January 2026 update for affected Android releases including Android 13, 14, 15, and 16, and device coverage spans both Exynos- and Qualcomm-based models; timely patching matters because mobile attacks can be leveraged for deeper compromise.

    ResearchGalaxy S9
  6. SecurityWeek
    FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances

    A heap out-of-bounds write in FFmpeg’s libavcodec MagicYUV decoder, tracked as CVE-2026-8461 (CVSS 8.8), can allow attackers to crash applications and potentially execute arbitrary code using specially crafted video files. JFrog describes the PixelSmash flaw as stemming from a mismatch in how the frame allocator and decoder calculate chroma plane heights, and notes that exploitation can be tailored to target FFmpeg’s AVBuffer refcounted buffer handling. Fixed in FFmpeg version 8.1.2, the issue affects a wide range of media players and servers that decode videos with FFmpeg, including Kodi, mpv, ffmpegthumbnailer, Jellyfin, Emby, Nextcloud, Immich, PhotoPrism, and OBS Studio—so updating promptly matters.

    PatchFFmpeg
  7. Daily CyberSecurity (securityonline.info)
  8. Daily CyberSecurity (securityonline.info)
  9. Daily CyberSecurity (securityonline.info)
  10. The Hacker News
    OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

    OpenAI says it is expanding its Daybreak initiative by releasing an improved trusted version of GPT-5.5-Cyber for defenders to help analyze large codebases, validate security issues, and generate/test patches. It is also updating the Codex Security plugin to accelerate vulnerability discovery and patch workflows, including triaging findings from scanners and advisories. The article highlights that Daybreak efforts have been associated with vulnerabilities such as CVE-2026-47729 (Squidbleed) and CVE-2026-8390 (WebAssembly in Mozilla Firefox), underscoring why faster remediation matters as frontier AI can also shorten the time between disclosure and exploitation.

    Research
  11. SANS Internet Storm Center
    CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.

    SonicWall addressed the improper access control flaw CVE-2024-40766 in SonicOS, impacting the management interface and SSLVPN service on Gen 5, Gen 6 and Gen 7 firewalls; however, threat actors (including Akira and Fog) have continued exploiting patched devices by abusing leftover configuration and credential issues rather than “new” bypasses. Active intrusions have also highlighted additional risk on Gen 6 related to CVE-2024-12802, where firmware-only patching may not remove the MFA bypass condition. The takeaway: organizations must not only apply SonicOS updates, but also complete post-patch cleanup (rotate passwords, remove stale/orphaned users, correct LDAP group settings, and restrict the Virtual Office Portal) to close the exploitable gaps.

    Reported exploitedSonicOS
  12. Daily CyberSecurity (securityonline.info)
  13. Daily CyberSecurity (securityonline.info)
  14. Daily CyberSecurity (securityonline.info)
  15. Daily CyberSecurity (securityonline.info)
  16. Daily CyberSecurity (securityonline.info)
  17. Daily CyberSecurity (securityonline.info)

Monday, Jun 2215 stories

  1. Dark Reading
  2. BleepingComputer
    FFmpeg fixes PixelSmash flaw in widely used video decoder

    FFmpeg has patched a newly reported “PixelSmash” issue (CVE-2026-8461), a heap out-of-bounds write in the MagicYUV decoder that can be triggered by specially crafted video files in AVI, MKV, or MOV formats. The flaw matters because it may lead to remote code execution on affected FFmpeg-based products under specific conditions (e.g., when ASLR is disabled or combined with other weaknesses), and it can also cause denial-of-service crashes; reported targets include Jellyfin and media software such as Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. The fix is included in FFmpeg version 8.1.2, and anyone using libavcodec with MagicYUV support should update and assess exposure.

    PatchMagicYUV decoder
  3. The Hacker News
    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

    ShapedPlugin says multiple WordPress Pro plugins were backdoored in a supply chain incident after attackers tampered with its official release and licensed update distribution. The affected plugins are Product Slider Pro for WooCommerce (versions before 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post Show Pro (versions before 4.0.2), delivered through ShapedPlugin’s Easy Digital Downloads (EDD) infrastructure at account.shapedplugin[.]com—while free versions on WordPress.org were not impacted. Security researchers link the incident to CVE-2026-10735 (CVSS 9.8) and CVE-2026-49777 (CVSS 10.0), highlighting the risk to legitimate license holders via trusted vendor updates and the potential for credential theft and persistence.

    Reported exploitedProduct Slider Pro for WooCommerce
  4. The Hacker News
  5. Check Point Research
    22nd June – Threat Intelligence Report

    This week’s Check Point Research roundup highlights multiple incidents and vulnerabilities affecting several vendors. A supply-chain attack targeting ShapedPlugin WordPress plugins delivered a hidden malicious WooCommerce component to steal admin, database, and 2FA credentials, while Fortinet FortiSandbox flaws CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 are reported as being exploited via unauthenticated API requests. Other actively targeted issues include Microsoft Defender CVE-2026-50656, Cisco Catalyst SD-WAN Manager CVE-2026-20262, and Splunk Enterprise CVE-2026-20253, where exploitation can enable privilege escalation or remote code execution—making patching and exposure review urgent.

    RoundupFortinet FortiSandbox
  6. The Hacker News
    29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

    A heap over-read in the Squid web proxy can expose another user’s cleartext HTTP request, potentially including credentials or session tokens, to attackers who already have permission to use the same proxy. The issue, called Squidbleed, is tracked as CVE-2026-47729 and is reported to affect Squid’s default configuration, with the attack requiring access patterns tied to Squid’s FTP parsing (including an FTP server on port 21). This matters because it can break confidentiality in shared proxy environments such as offices, schools, and public Wi‑Fi; however, HTTPS traffic behind CONNECT remains opaque to Squid.

    PoC publicSquid web proxy
  7. SecurityWeek
    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    Calif.io researchers reported a long-standing memory leak issue in Squid Proxy, tracked as CVE-2026-47729, affecting the FTP handling logic dating back to 1997. By manipulating an attacker-controlled FTP server, the proxy can read past a memory buffer and potentially disclose remnants of prior users’ uncleared HTTP requests, which is especially concerning in shared proxy deployments (e.g., corporate networks, schools, and public Wi‑Fi). While the impact is mainly limited to cleartext HTTP scenarios where Squid terminates TLS, sensitive credentials and session data may still be exposed without detection.

    ResearchSquid Proxy
  8. The Hacker News
    Stop Your Legacy Infrastructure from Hijacking Your AI Agents

    A recent analysis from XM Cyber warns that attackers can bypass AI security controls by pivoting through outdated or misconfigured systems that the AI agent depends on. It highlights an example chain involving Apache Tomcat with CVE-2025-24813, where lack of patching can lead to credential theft, Active Directory compromise, and then access to S3 data used by the AI agent’s knowledge base. This matters because CVE-driven weaknesses in “legacy” network and identity layers can translate into full compromise of AI agent outputs without directly attacking the AI stack itself.

    ResearchAWS Bedrock
  9. SecurityWeek
    Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

    Attackers are actively exploiting a medium-severity information exposure weakness in the Gravity SMTP WordPress plugin (all versions before 2.1.5) tracked as CVE-2026-4020 (CVSS 5.3). The flaw allows unauthenticated access to a REST API endpoint that can return the full “System Report” JSON, including server and WordPress configuration details as well as stored connector data like API keys/tokens used for email integrations. This matters because leaked credentials could enable attackers to send emails through the compromised site and use the detailed reconnaissance to pursue further vulnerabilities; Defiant reports exploitation in the wild since early May and a surge in attempts during June.

    Reported exploitedGravity SMTP for WordPress
  10. The Hacker News
  11. SecurityWeek
    Fortinet Responds to FortiBleed Campaign

    Fortinet has responded to the ongoing FortiBleed campaign, which is reportedly targeting its customers’ firewalls and VPNs with large-scale credential harvesting rather than exploiting a new product vulnerability. The activity centers on reusing previously obtained credentials and brute-force attempts against devices with weak password practices and missing multi-factor authentication, affecting Fortinet deployments across many regions. The vendor says earlier FortiCloud SSO login bypass issues—CVE-2026-24858 and CVE-2025-59718/CVE-2025-59719—are the related defects that were patched, underscoring why users must complete the recommended remediations and harden admin/VPN access.

    Reported exploitedFortiGate
  12. Daily CyberSecurity (securityonline.info)
  13. Daily CyberSecurity (securityonline.info)
  14. Daily CyberSecurity (securityonline.info)
  15. The Hacker News
    AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

    QiAnXin’s XLab reports that its AryStinger malware has infected at least 4,300 legacy routers and repurposes them for pre-intrusion reconnaissance and proxying (scanning, service fingerprinting, subdomain enumeration, tunneling, and on-demand command execution). The activity targets routers using Realtek RTL819X chips and exploits older, already-public issues: CVE-2013-3307 (Linksys) and CVE-2016-5681 (D-Link), with the majority of infected devices attributed to D-Link models such as DIR-850L. A separate strain was also observed against QNAP systems via CVE-2025-11837 in QNAP's Malware Remover, underscoring how unsupported networking gear can be used to build resilient attacker infrastructure.

    Reported exploitedLinksys routers (RTL819X-based models)

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store