CVE Tools

Security news, decoded.

73 stories in the last 7 days, naming 202 CVEs; 57 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 3 of 36 · newest first · times in UTC

Saturday, Sep 191 story

  1. The Hacker News
    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    CISA has added Linux kernel vulnerabilities CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its Known Exploited Vulnerabilities catalog after evidence of active attacks. The flaws can expose memory, cause denial-of-service conditions, corrupt cryptographic results, or enable local privilege escalation, making timely remediation important; federal agencies have been directed to apply fixes by September 21, 2026.

    Reported exploitedLinux Kernel

Friday, Sep 188 stories

  1. The Hacker News
    Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

    Working exploit code is public for four Linux kernel local privilege-escalation flaws: CVE-2026-80844 (DirtyAH6), CVE-2026-81000 (TUNderflow), CVE-2026-68121 (PPPoEject), and CVE-2026-74469 (DiagSpill). The bugs affect IPsec AH6, TUN/TAP, PPPoE, and SCTP code, allowing kernel-memory corruption that can give a local attacker root access; no in-the-wild exploitation has been reported. Update to a kernel release containing all fixes—starting with 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, or 7.2.4—or confirm that your distribution has backported them.

    PoC publicLinux Kernel
  2. SecurityWeek
    In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    This week’s security developments include a nearly 13-year Swiss prison sentence for the developer linked to Lockergoga, MegaCortex, and Nefilim ransomware. Defiant reported active exploitation of a file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin, which can enable PHP webshell uploads; users should update to version 2.0.3.2. SAP customers should urgently patch CVE-2026-44756, an unauthenticated memory-corruption issue affecting Extended Passport processing in products including S/4HANA, NetWeaver, and Business Suite. TP-Link also fixed Tapo C200 flaws CVE-2026-15315 and CVE-2026-15316 in firmware V51.4.6, while Plugin4Shell exposed silent plugin takeover risks for AI coding agents.

    Reported exploitedSAP
  3. The Hacker News
    Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

    Microsoft remediated CVE-2026-85889 (CVSS 10.0) in Azure AI Foundry, where missing authentication could have allowed an unauthenticated remote attacker to elevate privileges. The company also mitigated CVE-2026-85885 in Microsoft 365 Copilot, CVE-2026-85878 in Azure Database for PostgreSQL, and CVE-2026-87701 in Azure Cosmos DB; these cloud issues require no customer action, and CVE-2026-85889 has not been seen exploited. An out-of-band Windows 11, version 26H1 update, KB5129194 (28000.2956), addresses CVE-2026-62721 in Windows User-Mode Power Service (UMPS) and CVE-2026-85921 in Windows Secure Kernel Mode, which could enable local privilege escalation.

    PatchAzure AI Foundry
  4. SecurityWeek
    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    Microsoft has remediated 18 vulnerabilities affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, Microsoft 365 Copilot, Copilot, Microsoft 365 Copilot Business Chat, Azure Machine Learning, and Azure Portal. The issues include privilege escalation, information disclosure, and spoofing flaws; Microsoft says none are known to be exploited and the server-side fixes require no customer action. Separately, Windows users must install updates for the privilege escalation flaw CVE-2026-85921, which Microsoft assesses as less likely to be exploited.

    PatchAzure
  5. BleepingComputer
    New Check Point flaw lets hackers execute code with root privileges

    Check Point has issued a LivePatch for CVE-2026-91843, a stack-based buffer overflow in the login process of Security Management Server that also affects Log Server. An unauthenticated attacker could exploit the flaw with low complexity to run code remotely with root privileges, and Check Point says all Security Management Server deployments are affected regardless of configuration. Organizations unable to deploy the update should apply the vendor's hardening guidance and restrict trusted client access; no active exploitation has been reported.

    PatchSecurity Management Server
  6. SecurityWeek
    Critical Orkes Conductor Vulnerability Exploited in Attacks

    Attackers are exploiting CVE-2026-58138, a CVSS 9.8 remote code execution vulnerability in Orkes Conductor that can be triggered without authentication through malicious workflow definitions. The flaw was fixed in Conductor 3.30.2; organizations should update, limit access to workflow API endpoints, and investigate suspicious workflow activity.

    Reported exploitedConductor
  7. SecurityWeek
    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Check Point patched CVE-2026-91843 in Security Management Server and Log Server, an unauthenticated remote code execution flaw that could grant root privileges; the company reports no evidence of exploitation and urges immediate updates. Tanium also fixed SQL injection, SSRF, and access-control issues in Tanium Asset and Threat Response, while Kaspersky addressed a Redis-related issue in Kaspersky Security 10 for Linux Mail Server that could cause malfunctions or code execution during file processing.

    PatchSecurity Management Server
  8. Patchstack
    WordPress 7.1.1 Maintenance and Security Release

    WordPress 7.1.1 addresses 11 security vulnerabilities and 17 Core bugs, including CVE-2026-93485, an unauthenticated stored XSS flaw in the wpautop() content-formatting function affecting WordPress Core through 7.1. An anonymous visitor could submit a crafted comment that becomes executable script when the comment is published and viewed, potentially affecting any site visitor. WordPress has also backported fixes to supported older branches, but site operators should update to WordPress 7.1.1 or the latest available release.

    ResearchWordPress

Thursday, Sep 1714 stories

  1. The Hacker News
    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Check Point released a LivePatch for CVE-2026-91843, a CVSS 9.8 stack overflow that can let unauthenticated attackers execute code as root on Check Point Security Management Server and Check Point Log Servers through Trusted Clients access. The issue affects R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, R81.10 with Jumbo Hotfix Take 190 or below, and all R82.20 builds; older R81, R80.40, R80.30, R80.20, R80.10 and R80 branches are also affected. Check Point reports no known exploitation, but administrators should install the fix, verify its status, and restrict Trusted Clients to known hosts rather than exposing management access to the internet.

    PatchCheck Point Security Management Server
  2. The Hacker News
    ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

    This ThreatsDay roundup reports ransomware exploitation of VMware vCenter flaw CVE-2026-59310, while Cisco Talos-linked reporting covers attacks involving Cisco Secure FMC vulnerabilities CVE-2026-20079 and CVE-2026-20316. Palo Alto Networks and Oasis Security also detailed campaigns abusing malware distribution channels and exposed LocalAI deployments, including root-level command execution and credential theft. Oracle released its September 2026 Critical Security Patch Update for more than 800 vulnerabilities, none identified as actively exploited.

    Reported exploitedLocalAI
  3. The Hacker News
    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    Docker has fixed CVE-2026-77179, a macOS flaw in Docker Sandboxes 0.28.0 up to but not including 0.42.0 that could let malicious guest code use a symlink race to access or alter host files under the VM host account. The 0.42.0 release also resolves CVE-2026-79994, affecting versions 0.37.0 through 0.41.9, which could redirect authorized Unix socket connections to sockets outside the workspace. Docker reports no known exploitation; users should update to 0.42.0 or later, or use clone mode and avoid read-write host mounts until they can update.

    PatchDocker Sandboxes
  4. Bishop Fox
    MikroTrick: Inside the RouterOS Takeover Chain

    Attackers exploited a chain in MikroTik RouterOS, dubbed MikroTrick, to take over exposed routers without credentials before fixes were publicly disclosed. CVE-2026-67279 bypasses SSH authentication after rekeying, while CVE-2026-86060 can turn a crafted username into a trusted administrative identity on vulnerable RouterOS 7.x builds. Update to 6.49.21, 7.23.4, 7.24.2, or later, and investigate routers for persistent privileged accounts, scripts, and scheduled tasks because patching alone does not remove an existing compromise.

    Reported exploitedMikroTik RouterOS
  5. SecurityWeek
    ISC Patches 14 Vulnerabilities in BIND 9 Security Update

    ISC has released BIND 9 versions 9.21.26 and 9.20.29 to fix 14 vulnerabilities, including seven high-severity flaws that can cause denial-of-service conditions. Remote attack paths affect CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736; CVE-2026-77692 can crash named through one unauthenticated DoH SIG(0) request. The remaining fixes address risks including cache poisoning, resource exhaustion, packet loss, and injection of attacker-controlled data into zones. ISC has not observed exploitation in the wild and recommends updating deployments promptly.

    PatchBIND 9
  6. The Hacker News
    Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

    NLnet Labs released Unbound 1.26.1 to address CVE-2026-81642, a DNSSEC validator heap overflow affecting versions through 1.26.0 that a malicious DNS zone could use to cause denial of service or potentially execute code remotely. The update also fixes CVE-2026-82717, CVE-2026-81634, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501, and CVE-2026-77860. Neither CVE-2026-81642 nor CVE-2026-82717 is known to be exploited, but operators should upgrade to Unbound 1.26.1 or apply the available patches.

    PatchUnbound
  7. SecurityWeek
    Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

    Cisco has issued fixes for dozens of vulnerabilities in Cisco Secure Firewall Management Center, Cisco Identity Services Engine, and Cisco Nexus Dashboard, including multiple critical-severity issues. Cisco Identity Services Engine patches address CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, which could enable SQL injection, data modification, or command execution for attackers with administrative access. The FMC updates include CVE-2026-20332, while related flaws CVE-2026-20079 and CVE-2026-20316 have been exploited in the wild; organizations should apply Cisco's updates promptly.

    Reported exploitedCisco Secure Firewall Management Center
  8. Help Net Security
    Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

    Cisco has confirmed that attackers are exploiting CVE-2026-76460, an authentication bypass in an API of Cisco Identity Services Engine (ISE). The flaw affects Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC), releases 3.0 through 3.5, and can let unauthenticated remote attackers access devices through the web-based management interface. Organizations should review logs across every deployment node and external network and firewall logs, then upgrade to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4; Cisco provides no workaround.

    Reported exploitedCisco Identity Services Engine
  9. Cisco Talos
    Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

    Cisco Talos recorded 90 ransomware incidents affecting Japanese organizations from January through July 2026, with The Gentlemen the most frequently observed group and Qilin second. Talos linked The Gentlemen infrastructure to reconnaissance, credential theft, lateral movement, data theft and attempted exploitation of CVE-2025-2479 and CVE-2025-24799, while Qilin scripts showed signs of generative AI assistance for ransomware deployment and backup destruction.

    Reported exploitedThe Gentlemen
  10. ESET WeLiveSecurity
    Beware the SparroWock: The backdoor that bites, the commands that catch

    ESET researchers found FamousSparrow deploying its new SparroWocky backdoor against government organizations across Latin America since at least August 2025. The modular Windows implant replaces SparrowDoor and can run commands, steal files, capture screenshots, proxy network traffic, and execute Beacon Object Files while using evasion features to hinder detection.

    Reported exploitedSparroWocky
  11. The Hacker News
    BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

    ISC has released BIND 9.20.29 and 9.21.26 to address 14 vulnerabilities: CVE-2026-77692, CVE-2026-76163, CVE-2026-19667, CVE-2026-19666, CVE-2026-80274, CVE-2026-19662, CVE-2026-81563, CVE-2026-81736, CVE-2026-19668, CVE-2026-75029, CVE-2026-19941, CVE-2026-77119, CVE-2026-19033, and CVE-2026-78301. CVE-2026-77692 allows an unauthenticated party to crash named on BIND 9 servers handling DNS-over-HTTPS with a malformed SIG(0) request, while other issues can crash resolvers, exhaust CPU or memory, or enable DNS data integrity attacks under specific conditions. ISC reports no active exploitation; administrators should update BIND 9, noting that the unsupported 9.18 branch has no fixes for 12 of these issues.

    PatchBIND 9
  12. BleepingComputer
    Cisco warns of max severity ISE zero-day exploited in attacks

    Cisco has patched CVE-2026-76460, a maximum-severity authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which is being exploited in the wild. A crafted request to an affected API can let a remote attacker evade authentication and access the device's web management functions. Organizations should upgrade to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, as Cisco has not provided a workaround.

    Reported exploitedIdentity Services Engine (ISE)
  13. The Hacker News
    Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

    Cisco says CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), is being exploited in the wild. A crafted request to an affected API can let an unauthenticated remote attacker bypass the web management interface and potentially obtain root-level command execution. Update to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4; Cisco reports no workaround.

    Reported exploitedIdentity Services Engine (ISE)
  14. SecurityWeek
    Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

    Cisco has issued emergency fixes for CVE-2026-76460, a CVSS 10/10 authentication bypass in an API endpoint affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which is being exploited in the wild. Crafted API requests can bypass the web management interface, potentially grant device access and permit root-level command execution; organizations should upgrade to ISE or ISE-PIC versions 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, or 3.1 Patch 12 and investigate affected nodes for compromise.

    Reported exploitedIdentity Services Engine (ISE)

Wednesday, Sep 1617 stories

  1. Dark Reading
    BragJack Attack Can Turn a Browser's Agentic AI Against It

    Researchers released the BragJack proof of concept, showing how malicious browser extensions could seize control of built-in AI agents in Chrome, Edge, Opera Neon, Comet, and Claude in Chrome. The flaws, including CVE-2026-0628 in Chrome and CVE-2026-55945 in Edge, could enable access to sensitive data and actions on authenticated websites; the affected vendors have addressed the reported issues.

    PoC publicChrome
  2. The Hacker News
    Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

    Attackers are exploiting CVE-2026-89026 in Issabel Framework, affecting Issabel PBX, to execute operating-system commands remotely without authentication. The flaw uses a JWT signing key shared across installations, allowing forged tokens to invoke Asterisk functionality and run commands as the Asterisk user. A patch released on August 1, 2026 moves the key into "/etc/issabel.conf"; users should apply the latest fixes.

    Reported exploitedIssabel PBX
  3. The Hacker News
    Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

    Kaspersky reports that NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls have targeted Russian enterprises with backdoors, ransomware, and destructive malware. NightEagle compromised Microsoft Exchange Server and exploited CVE-2019-0708 for lateral movement, while Hacking Cat abused Microsoft Exchange vulnerabilities CVE-2021-26855 and CVE-2026-42897 to deploy Gorilla RAT and Monkey ransomware. Toy Ghouls used WinRM to install Bird Agent backdoors that use MQTT or Matrix-based Element communications, increasing the risk of persistent access across affected networks.

    Reported exploitedMicrosoft Exchange Server
  4. The Hacker News
    One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

    Forever Security published a proof of concept showing that a malicious browser extension with common permissions could hijack AI assistants in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. The demonstrated attacks could make agents act for an attacker; Chrome and Comet could also expose local files, while Chrome could enable camera and microphone access. Google fixed CVE-2026-0628 in Chrome version 143.0.7499.192, and Microsoft fixed CVE-2026-55945 in Edge version 150.0.4078.48; the remaining findings have no CVE, and no in-the-wild exploitation has been reported.

    PoC publicChrome
  5. Qualys Security Blog
    Oracle Critical Security Patch Update, September 2026 Review

    Oracle’s September 2026 Critical Security Patch Update fixes 673 vulnerabilities across product lines including Oracle E-Business Suite, Oracle Fusion Middleware, and Oracle Database. The release includes 104 critical-rated issues; Oracle E-Business Suite received 159 fixes, including network-reachable CVE-2026-83327, CVE-2026-83452, and CVE-2026-83462, each with a CVSS score of 9.8. Oracle Fusion Middleware received 153 patches, 78 of which can be exploited remotely without authentication, while Oracle Database products received 13 updates.

    PatchOracle E-Business Suite
  6. The Hacker News
    Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

    A public PoC for CVE-2026-90894 shows how a non-admin local user can gain root privileges on a Mac running vulnerable Parallels Desktop for Mac. The flaw abuses appliance extraction to inject tar options through the root-run prldispservice, affecting builds below Parallels Desktop 27.0.0. JFrog identifies version 27.0.0 as fixed, but Intel Macs cannot install the 27.x line and may remain without a confirmed fix on Parallels Desktop 26.

    PoC publicParallels Desktop for Mac
  7. SecurityWeek
    Pixel Modem Zero-Day Exploited in Targeted Attacks

    Google has patched CVE-2026-58704, a high-severity zero-day in the Google Pixel cellular modem that has seen limited, targeted exploitation. A logic flaw can let a nearby attacker bypass permissions and gain elevated privileges without user interaction. The latest Pixel updates also address more than 100 additional device-specific vulnerabilities, so affected owners should install them promptly.

    Reported exploitedGoogle Pixel
  8. Help Net Security
    Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

    A public proof of concept has highlighted CVE-2026-90894, also known as ParaShells, an argument injection issue in Parallels Desktop for Mac v26.4.0 on Apple ARM-based macOS systems. A low-privileged local user can abuse the root-running prldispservice to obtain root access, potentially exposing other users' data and enabling persistence; Parallels fixed the flaw in Parallels Desktop v27.0.0, so organizations should upgrade.

    PoC publicParallels Desktop
  9. SecurityWeek
    Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

    StellarWP has patched two unauthenticated remote code execution flaws in The Events Calendar plugin for WordPress: CVE-2026-78159 and CVE-2026-78006, both rated CVSS 9.8. The bugs can allow code or PHP object injection and could result in a complete WordPress site takeover when event comments are enabled. Administrators should update to The Events Calendar 6.17.4.1, as versions before 6.17.3.1 are exposed to both issues and CVE-2026-78006 is fixed in 6.17.4.1.

    PatchThe Events Calendar plugin
  10. The Hacker News
    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    Google has patched CVE-2026-58704, an actively exploited privilege-escalation vulnerability in the Pixel Cellular Modem. The logic flaw can bypass permissions and allow a nearby attacker to gain elevated privileges without user interaction; Google says exploitation appears limited and targeted. September 2026 Pixel updates also address 109 other Android and Pixel issues, including CVE-2026-56914 and CVE-2026-58773; install security patch level 2026-09-05 or later.

    Reported exploitedPixel Cellular Modem
  11. BleepingComputer
    Critical ScreenConnect flaw now actively exploited in attacks

    CISA has added ConnectWise ScreenConnect vulnerability CVE-2026-84869 to its Known Exploited Vulnerabilities catalog after attacks began targeting the flaw. The missing-authorization and privilege-management issue affects ScreenConnect clients before version 26.6.5 and can let attackers with basic privileges transfer or run files during active remote sessions without host confirmation. Organizations should update to ScreenConnect 26.6.5 or later, as exposed unpatched instances remain reachable online.

    Reported exploitedScreenConnect
  12. The Hacker News
    Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

    Acronis says CVE-2026-87886 has been used in limited, targeted attacks against its Backup plugin for cPanel & WHM and Backup extension for Plesk. The insecure file permissions issue affects Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 and Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, allowing a low-privileged local attacker to elevate privileges and potentially run arbitrary code; update to 1.9.3 HF3 and the latest Plesk release.

    Reported exploitedBackup plugin for cPanel & WHM
  13. SecurityWeek
    Chrome, Firefox Updates Patch 115 Vulnerabilities

    Google's Chrome 153 fixes 42 security flaws, including CVE-2026-91726 in WebGL and use-after-free vulnerabilities CVE-2026-91721 and CVE-2026-91749; the release is rolling out as 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for Linux. Mozilla's Firefox 156 addresses 73 vulnerabilities, with related fixes also available in Thunderbird 156 and 140.16 and Firefox ESR 153.3, 140.16, and 115.41; neither vendor reports exploitation, but users should update promptly.

    PatchChrome
  14. Kaspersky Securelist
    NightEagle APT targets Russian organizations

    Kaspersky reports that the NightEagle APT group targeted Russian organizations, using stolen VPN credentials and deploying the GhostContainer backdoor on Microsoft Exchange Server. The attackers used Microsoft dev tunnels, rdp2tcp, and Active Directory techniques to sustain access and move through victim networks, while exploiting CVE-2019-0708 (BlueKeep) in at least one incident. The activity can lead to domain controller compromise and exposure of the wider Active Directory environment.

    IncidentExchange Server
  15. SecurityWeek
    Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

    Acronis has released urgent fixes for CVE-2026-87886, an insecure file permissions vulnerability exploited in targeted attacks against the Backup plugin for cPanel & WHM. The flaw can enable local privilege escalation in Linux versions before build 1.9.3.1021 and also affects the Backup extension for Plesk before build 1.8.11.638, though exploitation has not been reported for Plesk; administrators should update immediately.

    Reported exploitedBackup plugin for cPanel & WHM
  16. Help Net Security
    Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

    Acronis says CVE-2026-87886 is being exploited in targeted attacks against its Backup plugin for cPanel & WHM. Insecure file permissions let authenticated attackers elevate privileges locally on Linux servers; administrators should update the cPanel & WHM plugin to version 1.9.3 HF3 and the Backup extension for Plesk to version 1.8.11, though no Plesk exploitation has been observed.

    Reported exploitedBackup plugin for cPanel & WHM
  17. SecurityWeek
    Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

    Attackers are exploiting CVE-2026-5430, a CVSS 10 WSO2 vulnerability patched in April, to bypass JWT authentication and gain unauthorized access. The flaw affects API Manager, Traffic Manager, Universal Gateway, and API Control Plane, and may enable administrative account takeover, access to API credentials and secrets, and interception of sensitive data. Organizations using affected WSO2 products should apply the available patch promptly.

    Reported exploitedAPI Manager

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store