CVE Tools

Security news, decoded.

73 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 28 of 36 · newest first · times in UTC

Thursday, Jun 186 stories

  1. ESET WeLiveSecurity
  2. SecurityWeek
    F5 Patches Critical, High-Severity NGINX Vulnerabilities

    F5 has issued out-of-band updates to fix multiple NGINX vulnerabilities, including critical issues in HTTP modules tracked as CVE-2026-42530 and CVE-2026-42055. These flaws (CVSS 9.2) could be exploited without authentication to trigger memory corruption (use-after-free or heap-based buffer overflow), potentially leading to denial-of-service and, if ASLR is disabled or bypassable, arbitrary code execution. F5 also patched additional NGINX Gateway Fabric bugs CVE-2026-11311 and CVE-2026-50107 that may let authenticated attackers inject malicious configuration directives, plus other medium-severity NGINX issues affecting memory disclosure or stability.

    PatchNGINX Plus
  3. Daily CyberSecurity (securityonline.info)
  4. Daily CyberSecurity (securityonline.info)
  5. Daily CyberSecurity (securityonline.info)
  6. Daily CyberSecurity (securityonline.info)
    Zyxel Patches Stack-Based Buffer Overflow in GS1900 Switches (CVE-2026-7273)

    Zyxel has released firmware updates to address a stack-based buffer overflow in its GS1900 series switches, tracked as CVE-2026-7273 and scored 8.8 (CVSS). The issue impacts the GS1900-8, GS1900-24, and GS1900-48HPv2, among other GS1900 models running firmware version 2.90 or earlier, and could allow a LAN-based, unauthenticated attacker to execute commands and potentially take control of the device. Because affected switches are often central to network operations, patching promptly is important to reduce the risk of intrusion and lateral movement.

    PatchGS1900 series switches

Wednesday, Jun 1722 stories

  1. Dark Reading
  2. Daily CyberSecurity (securityonline.info)
  3. Daily CyberSecurity (securityonline.info)
    Active Gravity SMTP Vulnerability Exploited in the Wild

    A vulnerability in RocketGenius Gravity SMTP is being exploited in the wild, tracked as CVE-2026-4020 (CVSS 7.5). The issue affects Gravity SMTP versions ≤ 2.1.4 by allowing unauthenticated attackers to access a REST API endpoint that returns system report details, including sensitive email integration credentials (API keys, secrets, and OAuth tokens). This matters because exposed credentials can enable account compromise and follow-on spam or phishing activity; affected users should upgrade to Gravity SMTP 2.1.5 and rotate any email integration secrets.

    Reported exploitedGravity SMTP
  4. Daily CyberSecurity (securityonline.info)
  5. The Hacker News
  6. Daily CyberSecurity (securityonline.info)
    Critical Apache Shiro LDAP Injection Flaw Uncovered

    Researchers identified a critical LDAP injection issue in Apache Shiro’s DefaultLdapRealm that could let attackers bypass authentication by manipulating the LDAP Distinguished Name (DN) construction. The vulnerability is tracked as CVE-2026-49268 and affects Apache Shiro versions below 2.2.1, as well as versions 3.0.0-alpha-0 through 3.0.0-alpha-1, with a high CVSS score of 8.8. Organizations should remediate by updating to Apache Shiro 2.2.1 or later (or 3.0.0-alpha-2 and later) to prevent impersonation and unauthorized access.

    PatchApache Shiro
  7. SecurityWeek
    Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software

    Rockwell Automation has released security updates for vulnerabilities in several ICS products, including Logix and CompactLogix controllers, Flex I/O dual-port Ethernet/IP adapters, RSLinx, and the FactoryTalk automation suite. The advisories address issues such as authentication bypass and denial-of-service risks in FactoryTalk Historian Site Edition (CVE IDs not specified in the article), improper API authorization in FactoryTalk Analytics PavilionX, multiple DoS flaws in certain CompactLogix/ControlLogix and GuardLogix controllers (including CVE IDs not specified), and a critical adapter weakness that could let an unauthenticated attacker reset a web interface password. While Rockwell noted in-the-wild exploitation of an older issue tracked as CVE-2021-22681, the article says the newly patched vulnerabilities have not yet been targeted by threat actors.

    PatchLogix
  8. BleepingComputer
    CISA orders feds to patch max severity Joomla plugin flaw by FridayReported exploitedWidget Factory Joomla Content Editor (JCE) plugin
  9. SecurityWeek
    Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day

    Microsoft has acknowledged a publicly disclosed privilege-escalation flaw in Microsoft Defender’s Microsoft Malware Protection Engine, tracked as CVE-2026-50656 (CVSS 7.8). The issue, dubbed “RoguePlanet,” is linked to a race condition that can let attackers elevate privileges to System on Windows 10 and Windows 11, and it matters because it turns Defender into a local elevation vector. Microsoft says it is working on a high-quality security update to address CVE-2026-50656 and will provide details once the fix is available.

    PoC publicMicrosoft Defender
  10. SecurityWeek
  11. Daily CyberSecurity (securityonline.info)
    JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours

    Black Lotus Labs reports that the China-nexus JDY botnet has grown and is again scanning the internet for newly disclosed vulnerabilities within hours, using masked infrastructure and scanning techniques designed to blend into normal traffic. Compromised devices include Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, and the activity is notably tied to Fortinet systems following publication of CVE-2026-35616. The fast weaponization window matters because edge and embedded deployments are often harder to monitor and patch, increasing the chance of pre-patch probing and exploitation.

    Reported exploitedJDY botnet
  12. BleepingComputer
  13. Daily CyberSecurity (securityonline.info)
    AdGuard Email Tracking Protection: Stop Hidden Pixels

    AdGuard has released a new email filtering capability (AdGuard Email Tracking Protection) designed to stop hidden 1×1 pixel trackers in messages that reveal when an email is opened and can expose client and device details. This matters because many marketing campaigns rely on these “invisible” image loads to measure engagement and track recipients. The article also references AdGuard’s ongoing security work, including CVE-2024-36814, underscoring that privacy and protection features are now a focus across its product updates.

    AdvisoryAdGuard email tracking protection
  14. SecurityWeek
    Joomla, LiteSpeed Vulnerabilities Exploited in Attacks

    Attackers are exploiting security weaknesses in Joomla’s Content Editor (JCE) and the LiteSpeed cPanel plugin to gain code execution and escalate privileges. Joomla JCE Pro versions before 2.9.99.5 are affected by CVE-2026-48907, enabling unauthenticated abuse to upload arbitrary files and run PHP code; fixes were released in 2.9.99.5 and strengthened again in 2.9.99.6. Separately, LiteSpeed’s user-end cPanel plugin versions before 2.4.8 are impacted by CVE-2026-54420, where improper symlink handling can let attackers escalate to root on shared hosting running CloudLinux/CageFS; both issues have been added to CISA’s KEV catalog, underscoring the urgency to patch.

    Reported exploitedJoomla Content Editor (JCE) Pro
  15. SecurityWeek
  16. The Hacker News
    CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionReported exploitedWidget Factory Joomla Content Editor (JCE)
  17. Daily CyberSecurity (securityonline.info)
    Chrome Security Update Fixes 33 Flaws, Seven Critical

    Google has released a major security update for the Google Chrome 149 desktop browser, fixing 33 vulnerabilities in total, with seven rated “Critical.” The Stable channel has moved to 149.0.7827.155/.156 for Windows and Mac, and Linux receives 149.0.7827.155; several top issues are use-after-free memory corruption flaws that can enable remote code execution. Notable CVEs include CVE-2026-12437 (WebShare), CVE-2026-12442 (Passwords), CVE-2026-12443 (Web Authentication), CVE-2026-12439 and CVE-2026-12440 (Digital Credentials), making prompt patching important.

    PatchGoogle Chrome Stable 149.0.7827.155/.156
  18. Daily CyberSecurity (securityonline.info)
  19. Daily CyberSecurity (securityonline.info)
    Critical Yarbo Robot Vulnerability Exposes Global Fleet

    Researchers report that Yarbo Android and iOS apps contain hard-coded MQTT credentials, tracked as CVE-2026-10557, which can be extracted from the apps and used to access MQTT brokers supporting a large global robot fleet. A second issue, CVE-2026-7368, is a lack of proper per-device/per-user authorization in the Yarbo cloud, meaning a single valid login could allow fleet-wide access. This matters because attackers may be able to subscribe to telemetry and issue commands across many robots rather than affecting only one device.

    AdvisoryYarbo Android app
  20. Daily CyberSecurity (securityonline.info)
  21. Daily CyberSecurity (securityonline.info)
    NVIDIA Patches Three High-Severity NeMo Framework Code Injection Flaws

    NVIDIA has released an urgent security update for its NeMo Framework, addressing three High-severity code-injection-related flaws: CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228. The issues can enable remote or local code execution depending on the CVE, including potential privilege escalation and data tampering, and affect all NeMo versions from 0.0 up to 2.7.2. Users should upgrade to version 2.7.3 or later to reduce the risk of exploitation, especially on shared training or AI pipeline infrastructure.

    PatchNVIDIA NeMo Framework
  22. Daily CyberSecurity (securityonline.info)
    MongoDB Server Vulnerability Wave Hits Document Databases

    MongoDB Server has disclosed a new set of security issues affecting document databases, with fixes covering several MongoDB release lines (including 7.0, 8.0, 8.2, and 8.3). The advisories include CVE-2026-11933 (use-after-free in server-side JavaScript that can leak memory or crash when reachable by an authenticated user), CVE-2026-9740 (an unauthenticated denial-of-service crash via BSON validation recursion), CVE-2026-9750 and CVE-2026-9743 (authenticated and aggregation-related crash or incorrect-results scenarios). Because at least one bug can be triggered without authentication, upgrading to the provided fixed versions such as 8.0.26, 8.2.11, and 8.3.4 is a priority.

    PatchMongoDB

Tuesday, Jun 1612 stories

  1. The Hacker News
    Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

    Google Cloud Vertex AI SDK for Python contained a bug that let an attacker with their own Google Cloud project and the victim’s project ID hijack model uploads and get code to execute in Google’s model serving infrastructure. The issue is in the SDK’s default temporary Cloud Storage bucket handling, enabling cross-tenant model replacement (notably for pickle/joblib-based models) and theft of OAuth tokens from the serving container; Unit 42 reported the risk and Google patched it in v1.148.0 (update from versions such as 1.139.0 and 1.140.0). No CVE has been published for this specific problem as of the article’s publication, but users should upgrade and explicitly set stagingbucket to a bucket they control.

    PatchVertex AI SDK for Python
  2. Daily CyberSecurity (securityonline.info)
    ShapedPlugin Supply Chain Attack Exposes WordPress Sites

    Researchers say a ShapedPlugin supply chain attack compromised the vendor’s distribution pipeline and inserted malicious backdoor code into premium Pro plugin releases, impacting WordPress sites that update normally. The activity is tracked under CVE-2026-10735 and CVE-2026-49777, with confirmed exposure including Real Testimonials Pro version 3.2.5 plus other premium plugins such as Product Slider Pro and Smart Post Pro. This matters because the malware also targets authentication (including 2FA/TOTP secrets), potentially allowing attackers to bypass multi-factor protections.

    Reported exploitedPro plugin releases
  3. Bishop Fox
  4. BleepingComputer
    CISA warns of another cPanel plugin flaw exploited in attacks

    CISA has directed U.S. federal agencies to patch within three days a actively exploited vulnerability in the LiteSpeed cPanel user-end plugin, tracked as CVE-2026-54420. Reported as CVE-2026-48172, the high-severity flaw affects user-end plugin versions before 2.4.8 and can let attackers with FTP or web shell access escalate to root on shared hosting systems running CloudLinux/CageFS due to a UNIX symlink-following issue. This is included in CISA’s Known Exploited Vulnerabilities Catalog, making timely remediation critical to reduce the risk of widespread compromise.

    Reported exploitedLiteSpeed cPanel user-end plugin
  5. The Hacker News
  6. BleepingComputer
  7. The Hacker News
    China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth

    Researchers report two new Windows builds of the SprySOCKS backdoor—tracked internally as WINDRV and WINPLUS—previously believed to target Linux. The Windows versions use hard-coded command-and-control with TCP, UDP, and WebSocket communications and expand capabilities for reconnaissance, service/process management, and file operations, with WINDRV leveraging kernel drivers and WINPLUS using the Windows Print Spooler to load the payload more covertly. Evidence suggests UEFI-boot persistence may be involved, potentially exploiting CVE-2023-24932, a Windows Boot Manager security bypass that Microsoft fixed in May 2023.

    ResearchSprySOCKS
  8. BleepingComputer
    Critical Fortinet FortiSandbox flaws now exploited in attacks

    Threat actors are reportedly exploiting multiple critical Fortinet FortiSandbox vulnerabilities in the wild, enabling privilege escalation and remote code execution without authentication or user interaction. The affected flaws are tracked as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, and Fortinet released security updates on April 14—organizations should upgrade to the latest fixed versions to stop active attacks. This matters because FortiSandbox weaknesses have previously been leveraged in ransomware and intrusion campaigns to break into target networks.

    Reported exploitedFortiSandbox
  9. BleepingComputer
    Windows version of SprySOCKS Linux malware used to attack govt orgs

    ESET found Windows versions of the SprySOCKS backdoor being used in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras during 2023–2024. The activity is assessed with high confidence as the work of the Earth Lusca threat actor (also tracked as FishMonger, Aquatic Panda, Red Dev 10, and TAG-22), and the malware’s Windows variants add kernel-level stealth plus covert command-and-control through diverted TCP traffic. Researchers also noted signals that a possible UEFI bootkit component could involve CVE-2023-24932 (a Secure Boot issue), which matters because it may indicate additional pre-OS persistence risk alongside the already stealthy Windows backdoors.

    ResearchSprySOCKS
  10. Daily CyberSecurity (securityonline.info)
  11. Daily CyberSecurity (securityonline.info)
    curl Project Pauses Vulnerability Reports for “Summer of Bliss”

    The lead maintainer of the curl project announced a temporary halt in accepting vulnerability reports for the period July 1, 2026 (00:00 CEST) through August 3, 2026 (09:00 CEST), including submissions via HackerOne or email. The pause is intended as a scheduled rest rather than a response to a security incident, and it also shifts the planned release of version 8.22.0 to September 2, 2026. While urgent issues may still be handled earlier for companies with paid support contracts, other reports will be deferred, which matters for organizations relying on fast disclosure handling.

    Advisorycurl
  12. Daily CyberSecurity (securityonline.info)
    Inside the Stealthy Agent Tesla Infection Chain

    Attackers are using phishing emails that deliver obfuscated script-based loaders to trigger an advanced Agent Tesla infection chain, moving from attachment execution to process injection, stealthy data theft, and exfiltration with minimal user awareness. The article highlights how this modern approach shifts away from older Microsoft Office exploitation commonly associated with CVE-2017-11882, CVE-2017-0199, and CVE-2018-0802, while still referencing CVE-2023-24059 in the context of the observed threat. This matters because the reliance on in-memory payload execution, process hollowing, and anti-analysis checks can make traditional detection harder, increasing the risk of credential and session compromise.

    Reported exploitedAgent Tesla

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store