CVE Tools

Security news, decoded.

73 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 29 of 36 · newest first · times in UTC

Tuesday, Jun 1610 stories

  1. SecurityWeek
    Cisco Patches Another SD-WAN Zero-Day Exploited in AttacksReported exploitedCatalyst SD-WAN Manager
  2. The Hacker News
    Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw

    Cisco has released security updates for CVE-2026-20262, a medium-severity vulnerability in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that is being actively exploited in the wild. The issue can let an authenticated remote attacker abuse a file upload path-handling weakness to create or overwrite files on the device’s filesystem, which may be leveraged toward higher privileges depending on attacker access. The fix is available across multiple Cisco Catalyst SD-WAN releases, including Cisco Catalyst SD-WAN Release 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2, covering Cisco Catalyst SD-WAN Manager On-Prem, Cisco SD-WAN Cloud-Pro, Cisco SD-WAN Cloud (Cisco Managed), and Cisco SD-WAN for Government (FedRAMP).

    Reported exploitedCatalyst SD-WAN Manager
  3. The Hacker News
  4. Daily CyberSecurity (securityonline.info)
    Three Tornado Security Vulnerabilities Patched in Version 6.5.6

    Tornado maintainers have released version 6.5.6 to patch three security issues in the Python web framework, including CVE-2026-49853, CVE-2026-49855, and CVE-2026-49854. CVE-2026-49853 (7.7) can leak Authorization headers when SimpleAsyncHTTPClient follows redirects to a different origin, potentially exposing credentials across sites. CVE-2026-49855 (7.5) addresses a gzip bomb that could exhaust memory, while CVE-2026-49854 (5.3) fixes an out-of-bounds read in Tornado’s optional native extension that could reveal small amounts of uninitialized memory. Upgrading to Tornado 6.5.6 is the recommended mitigation, especially to address the credential-leak risk.

    PatchTornado (Python web framework)
  5. Daily CyberSecurity (securityonline.info)
  6. Daily CyberSecurity (securityonline.info)
    Haskell TLS Vulnerability Lets Attackers Forge Trusted Certificates (CVE-2026-9648)

    A critical issue in the Haskell library crypton-x509-validation (CVE-2026-9648, CVSS 9.1) allows TLS clients to accept forged certificates because the library does not enforce X.509 NameConstraints as required by RFC 5280. This matters because it can let attackers extend trust beyond the permitted scope of a name-constrained CA, potentially enabling credential/session interception in real-world deployments, especially delegated PKI used by financial institutions. CERT/CC reports that upgrading to crypton-x509-validation version 1.9.1 is the recommended mitigation.

    Patchcrypton-x509-validation
  7. Daily CyberSecurity (securityonline.info)
  8. Daily CyberSecurity (securityonline.info)
  9. Daily CyberSecurity (securityonline.info)
    Thousands of phpBB Forums Exposed by Critical Authentication Bypass

    phpBB has disclosed a critical authentication bypass, tracked as CVE-2026-48611, that can allow an unauthenticated attacker to log in as arbitrary users (including administrators) by abusing phpBB’s OAuth-related session handling. The flaw affects phpBB versions up to and including 3.3.16, and the 4.0.0 alpha branch, meaning many installations are exposed by default. This is a severe risk because it enables account takeover via a crafted request, and administrators should update to 3.3.17 (or apply the official mitigations/workarounds) as an urgent priority.

    PatchphpBB 3.x
  10. Daily CyberSecurity (securityonline.info)
    LiteSpeed cPanel Privilege Escalation Flaw Exploited in the Wild (CVE-2026-54420)

    CVE-2026-54420 is a privilege escalation issue in the LiteSpeed cPanel plugin (before version 2.4.8) that is reportedly under active attack, allowing a low-privileged tenant on shared hosting to escape isolation and obtain full root access. The flaw involves improper handling of user-controlled symlinks when the server runs CloudLinux/CageFS, which matters because compromising one account can put all sites on the same host at risk. LiteSpeed has remediated the problem in cPanel plugin v2.4.8 (bundled with WHM Plugin v5.3.2.1), so administrators should patch immediately and investigate logs for suspicious activity.

    Reported exploitedLiteSpeed cPanel Plugin

Monday, Jun 1521 stories

  1. BleepingComputer
  2. Dark Reading
  3. Dark Reading
    Copilot 'SearchLeak' Attack Allows 1-Click Data Theft

    Researchers describe a new Microsoft Copilot attack dubbed “SearchLeak” that can let an adversary exfiltrate user-accessible Microsoft 365 data, including emails, meeting notes, OneDrive files, and SharePoint documents, using a crafted Copilot Search link with no extra victim action. Varonis Threat Labs says the multi-stage issue relies on a lesser-known parameter-to-prompt Injection (P2P) pattern and can bypass protections by embedding attacker-controlled content in ways that trigger AI behavior before sanitization. Microsoft has patched the vulnerability as CVE-2026-42824, underscoring how prompt-injection weaknesses in LLM-based enterprise assistants can turn internal data access into an attacker-controlled output channel.

    PoC publicMicrosoft 365 Copilot Enterprise Search
  4. BleepingComputer
    Cisco fixes SD-WAN vManage flaw exploited in zero-day attacksReported exploitedCisco Catalyst SD-WAN Manager
  5. The Hacker News
    LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

    Researchers at Obsidian Security report a multi-step vulnerability chain in LiteLLM that can allow a default low-privilege account to escalate to full proxy admin and achieve code execution. The affected issues are tracked as CVE-2026-47101, CVE-2026-47102, and CVE-2026-40217; together they can bypass authorization, elevate privileges, and escape the Custom Code Guardrail’s sandbox. Because LiteLLM sits in the middle of AI requests, a takeover can expose provider keys and sensitive traffic and can also let attackers tamper with prompts/responses processed by downstream agents. BerriAI’s fix is included starting with LiteLLM v1.83.14-stable—upgrade to that release or later to mitigate.

    PoC publicLiteLLM
  6. Daily CyberSecurity (securityonline.info)
  7. The Hacker News
    One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

    Researchers at Varonis Threat Labs describe a chained vulnerability in Microsoft 365 Copilot Enterprise Search that could let attackers steal emails, calendar information, and indexed files after a user clicks a seemingly legitimate microsoft.com link. The issue is tracked as CVE-2026-42824 and matters because it can also expose time-sensitive authentication material such as one-time codes and MFA codes, potentially enabling account takeover. Microsoft has issued a critical mitigation on its backend, but tenant admins still need to monitor for suspicious Copilot Search URLs and related outbound requests.

    PoC publicMicrosoft 365 Copilot Enterprise Search
  8. The Hacker News
  9. Check Point Research
    15th June – Threat Intelligence ReportReported exploitedOracle PeopleSoft
  10. BleepingComputer
    New attack turned Microsoft 365 Copilot into 1-click data theft tool

    A newly detailed attack chain, dubbed SearchLeak, shows how Microsoft 365 Copilot Enterprise can be turned into a one-click data theft mechanism using a specially crafted URL. The technique targets sensitive content from a victim’s mailbox, OneDrive, or SharePoint by abusing Microsoft 365 Copilot Search, ultimately exfiltrating data via browser-driven and Bing-facilitated requests. Microsoft addressed the issue with fixes for CVE-2026-42824, rated critical, which is important because exploiting the weaknesses does not require additional user actions beyond clicking the link.

    PoC publicMicrosoft 365 Copilot Enterprise Search
  11. The Hacker News
  12. Daily CyberSecurity (securityonline.info)
    Jenkins RCE Vulnerability CVE-2026-53435 Now Under Active Exploitation

    Attackers are actively exploiting a critical remote code execution flaw in Jenkins, tracked as CVE-2026-53435. The issue allows adversaries to run arbitrary code on Jenkins controllers, including impersonating users and reaching the Script Console to execute commands or access sensitive files. Jenkins users on Jenkins 2.567 and earlier, as well as LTS 2.555.2 and earlier, should patch immediately; the same advisory also addresses open-redirect issues CVE-2026-53436 and CVE-2026-53437, though they are less severe.

    Reported exploitedJenkins (controllers)
  13. The Hacker News
    Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

    Palo Alto Networks says it has detected active exploitation of a PAN-OS flaw used to gain unauthorized access to GlobalProtect portals, with attack activity beginning May 17, 2026. The issue is tracked as CVE-2026-0257 (CVSS 7.8), an authentication bypass affecting GlobalProtect portal and gateway components that could let attackers establish VPN connections and evade security checks. The U.S. CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog, underscoring the need for urgent mitigation.

    Reported exploitedPAN-OS GlobalProtect (portal and gateway)
  14. Daily CyberSecurity (securityonline.info)
  15. Daily CyberSecurity (securityonline.info)
  16. Daily CyberSecurity (securityonline.info)
  17. Daily CyberSecurity (securityonline.info)
    Critical Wazuh CVSS 10 Vulnerability Details and Proof-of-Concept ReleasedPoC publicWazuh 5.0 inventory pipeline (wazuh-manager)
  18. Daily CyberSecurity (securityonline.info)
  19. Daily CyberSecurity (securityonline.info)
  20. Daily CyberSecurity (securityonline.info)
  21. Daily CyberSecurity (securityonline.info)

Saturday, Jun 134 stories

  1. The Hacker News
    Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

    Splunk released security updates for a critical issue in Splunk Enterprise that allows network-reachable attackers to perform unauthenticated PostgreSQL sidecar file operations, potentially escalating to remote code execution. The vulnerability is tracked as CVE-2026-20253 (CVSS 9.8) and affects Splunk Enterprise versions below 10.2.4 and 10.0.7, with fixes in 10.0.7 and 10.2.4 (Splunk Enterprise 10.4 is not affected). Splunk Cloud is reported as not impacted because it does not use PostgreSQL sidecars. Apply the vendor patches promptly to reduce the risk of exploitation.

    PatchSplunk Enterprise 10.0.7
  2. Daily CyberSecurity (securityonline.info)
    SimpleHelp Authentication Bypass Exploited to Hijack Remote Endpoints

    Researchers report a maximum-severity authentication bypass in SimpleHelp, tracked as CVE-2026-48558 (CVSS 10), that enables unauthenticated attackers to forge identity tokens and obtain administrative control. The flaw is tied to the app’s OIDC single sign-on handling, where submitted tokens can be accepted without proper cryptographic signature verification, also undermining MFA protections. This matters because compromised instances can execute scripts and pivot into managed endpoints, so organizations should review internet-exposed remote support systems and patch or harden OIDC configurations promptly.

    Reported exploitedSimpleHelp
  3. Daily CyberSecurity (securityonline.info)
  4. Daily CyberSecurity (securityonline.info)
    Important Apache CXF Vulnerabilities Demand Immediate Action

    Apache CXF discloses multiple security issues affecting the JCA integration, WS JSON request filtering, and XML parsing behavior, including CVE-2026-50633 and CVE-2026-50634, plus CVE-2026-50628 and CVE-2026-49875. These problems matter because they could enable scenarios like unauthorized code execution, bypassed validation logic, and XML External Entity exposure when systems handle attacker-controlled inputs. Apache recommends upgrading to versions 4.2.2 or 4.1.7 to address the reported issues.

    PatchApache CXF

Friday, Jun 125 stories

  1. watchTowr Labs
    Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)

    Splunk Enterprise has been impacted by CVE-2026-20253, where the “PostgreSQL Sidecar Service Endpoint” does not properly enforce authentication controls and can be invoked in a way that leads to arbitrary file creation and truncation. The issue matters because it can be chained to achieve pre-auth RCE in certain deployments (notably Splunk Enterprise on AWS), despite the endpoint being intended to be reachable only locally. If you run affected versions of Splunk Enterprise, prioritize reviewing the vendor advisory and applying the recommended mitigations for CVE-2026-20253.

    ResearchSplunk Enterprise
  2. Dark Reading
  3. Ars Technica (Security)
  4. The Hacker News
    China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

    Sygnia attributes attacks by a China-nexus group tracked as Velvet Ant to backdooring Linux authentication paths by altering PAM and OpenSSH login components that control who can sign in. The malware appears to have persisted from at least 2016 by replacing trusted login binaries—sometimes to capture real usernames and passwords and sometimes to execute hidden behavior—so standard recovery steps like password resets and session termination may fail. The same actor has previously targeted other products, including F5 BIG-IP and Cisco NX-OS, and Cisco NX-OS exploitation tied to CVE-2024-20399 (with admin access required) was reported as part of its persistence activity, underscoring why integrity checks for critical authentication software matter.

    ResearchLinux PAM
  5. SecurityWeek
    In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine

    CISA added CVE-2026-42271, a command injection issue affecting BerriAI LiteLLM (an AI gateway), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation, making urgent patching important. Separately, South Korea’s PIPC issued a record $400 million penalty to Coupang after security and data-handling failures exposed personal information of more than 30 million customers. In a major enforcement action, an international operation dismantled AudiA6, disrupting a crypto laundering pipeline tied to ransomware financing and seizing related infrastructure and forums.

    Roundup

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store