CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 7 of 36 · newest first · times in UTC

Friday, Sep 411 stories

  1. The Hacker News
    PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

    PostgreSQL has released security updates to address CVE-2026-6471, a high-severity vulnerability present since version 9.4 in 2014 that permits users with the REPLICATION attribute to execute arbitrary code as the database server's operating system user. The flaw arises because the logical decoding mechanism allows malicious specification of output plugin libraries, bypassing standard load restrictions. Affected versions include those prior to PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24; administrators must apply these updates and configure the new outputpluginlibraries parameter to whitelist permitted plugins, particularly if using third-party tools like wal2json.

    PoC publicPostgreSQL
  2. SecurityWeek
    Sangoma Switchvox Vulnerabilities Exploited in the Wild

    Horizon3 has confirmed active exploitation of CVE-2026-9586, a critical-severity vulnerability in Sangoma Switchvox with a CVSS score of 9.3. This unauthenticated SQL injection flaw allows attackers to achieve remote code execution against the backend PostgreSQL database by sending crafted requests. In response to the ongoing attacks, CISA added this vulnerability to its Known Exploited Vulnerabilities catalog alongside five other issues affecting products such as JFrog Artifactory, SonicWall SMA1000, Starlette, Kestra, and LiteLLM. Federal agencies are directed to remediate the Switchvox flaw within three days, while patches for the associated Kestra and Starlette vulnerabilities must be applied within two weeks.

    Reported exploitedSangoma Switchvox
  3. Help Net Security
    Google patches actively exploited Chrome zero-day (CVE-2026-85046)

    Google has addressed twelve security flaws in its browser, including a high-severity vulnerability in the V8 engine known as CVE-2026-85046. This bug is currently being leveraged by attackers to run arbitrary code within the browser's sandbox through malicious web content. The patch has been distributed in Chrome version 152.0.7977.82 and 152.0.7977.83 for desktop platforms. Users should ensure their browsers are updated to mitigate the risk of remote exploitation.

    Reported exploitedChrome
  4. SecurityWeek
    12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

    Cyera researchers disclosed a high-severity flaw, tracked as CVE-2026-6471 (CVSS 7.2) and dubbed "PostGREShell," affecting all PostgreSQL releases from 2014 onward. This unauthorized access issue exists within the logical decoding mechanism, allowing an attacker holding specific Replication privileges to execute arbitrary code on the server operating system. By exploiting the defect, threat actors can escalate permissions to full superuser status, extract sensitive data, and establish persistent backdoors. The PostgreSQL Global Development Group has resolved the vulnerability in recent point releases, specifically versions 18.6, 17.11, 16.15, 15.19, and 14.24.

    PatchPostgreSQL
  5. BleepingComputer
    Google warns of new Chrome zero-day flaw exploited in attacks

    Google has released updates for Chrome, upgrading desktop versions to 152.0.7977.82 and .83 on Windows/macOS and 152.0.7977.82 on Linux, to remediate an actively exploited high-severity zero-day vulnerability in the V8 engine. The flaw, identified as CVE-2026-85046, is a type confusion issue reported by researcher Salvatore Gulizia that could potentially lead to remote code execution via malicious JavaScript. This marks the sixth time Google has patched an in-the-wild Chrome exploit in 2026; users are advised to update promptly to protect their systems.

    Reported exploitedChrome
  6. SecurityWeek
    VMware Workstation and Fusion Updates Patch Critical Vulnerability

    Broadcom has released updates for VMware Workstation and VMware Fusion to address two security flaws affecting versions 25H2 and 26H1. The most severe issue, identified as CVE-2026-59346 with a CVSS score of 9.3, allows an attacker with local administrator access on a guest VM equipped with a VMXNET3 adapter to execute code on the host via an integer overflow. A second vulnerability, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow that similarly permits code execution within the host's VMX process under specific privilege conditions. No workarounds are available for these defects, so Broadcom strongly advises users to update to version 26H1u1 immediately. While there is no current evidence of active exploitation and both bugs were reported privately, the frequent targeting of VMware products by threat actors underscores the urgency of applying this patch.

    PatchVMware Workstation
  7. SecurityWeek
    Google Patches 6th Chrome Zero-Day of 2026

    Google has released security updates for Chrome 152 to address twelve vulnerabilities, most notably an actively exploited zero-day tracked as CVE-2026-85046. This high-severity flaw is a type confusion bug within the V8 JavaScript and WebAssembly engine, which attackers can leverage via crafted HTML pages to execute remote code. This marks the sixth zero-day patched in Chrome during 2026, following previous fixes in earlier releases. Users are advised to update immediately to version 152.0.7977.82 or 152.0.7977.83 depending on their operating system.

    Reported exploitedChrome
  8. The Hacker News
    Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

    Wordfence has reported active exploitation of two critical remote code execution vulnerabilities affecting the WordPress plugins Super Forms and Elementor Pro, with over 440,000 attempted attacks recorded so far. CVE-2026-14894 (CVSS 9.8) in Super Forms – Drag & Drop Form Builder enables unauthenticated users to upload arbitrary PHP files due to missing file type validation, a flaw fixed in version 6.3.314. Similarly, CVE-2026-32475 (CVSS 9.0/9.8) in Elementor Pro allows unrestricted file uploads through form widgets, leading to code execution on systems patched in version 4.2.2. Attackers are using these flaws to deploy web shells, such as "Mushr00wupl.php," to gain full control of compromised sites. Site administrators should update both plugins immediately and scan for unauthorized modifications to mitigate this ongoing threat.

    Reported exploitedSuper Forms
  9. The Hacker News
    Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

    Plex has released version 1.43.3 of Plex Media Server and version 1.115.0 of Plex Desktop to remediate multiple undisclosed security vulnerabilities, with CVE identifiers currently pending assignment. The company advises all administrators and users to apply these updates as soon as possible, noting that NAS installations may require manual package installation until local repositories update. Although specific details remain private, this release follows previous incidents involving high-severity authentication flaws and infrastructure exposure risks affecting the platform.

    PatchPlex Media Server
  10. The Hacker News
    Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 engine that is currently being exploited in the wild. The flaw allows remote attackers to execute arbitrary code within the browser sandbox via crafted web content. Users are urged to upgrade immediately to version 152.0.7977.82 on Windows and macOS, or 152.0.7977.82 on Linux, to mitigate this active threat.

    Reported exploitedChrome
  11. Help Net Security
    September 2026 Patch Tuesday forecast: All we need is more time

    Security professionals face a continued surge in vulnerabilities heading into the September 2026 Patch Tuesday, driven by AI-assisted discovery techniques that have expanded the patch backlog significantly. While the previous update cycle resolved nearly four hundred issues, urgent attention is required for specific threats where exploitation has already begun or proof-of-concept code is available. Notably, threat actors are chaining CVE-2026-55040 and CVE-2026-63520 to achieve authentication bypass and remote code execution on SharePoint servers, while Exchange Server faces pressure from CVE-2026-62911, a high-severity elevation of privilege flaw. Additionally, Microsoft Defender is under scrutiny due to CVE-2026-69414, nicknamed 'ShieldBreak,' which grants system privileges through the malware engine and currently has public exploit code, though a fix is pending. Administrators must also prepare for several products reaching end of life this month, including specific Windows 11 editions and older Exchange Server versions, necessitating immediate upgrade planning. As the monthly cadence approaches, similar updates are expected from Adobe, Apple, and Mozilla, with recent Chrome releases already addressing actively exploited bugs.

    Reported exploitedSharePoint

Thursday, Sep 39 stories

  1. BleepingComputer
    HPE patches critical ArubaOS-CX remote code execution flaw

    Hewlett Packard Enterprise has released security updates for ArubaOS-CX to address CVE-2026-73749, a critical buffer overflow vulnerability that permits unauthenticated remote attackers to execute code with elevated privileges. By sending specially crafted packets to an affected daemon process, malicious actors can compromise enterprise network switches running the operating system. The vendor advises administrators to upgrade affected devices to specific fixed releases, such as version 10.18.1002 or higher, depending on their current branch. While no active exploitation or public proof-of-concept tools have been identified yet, the bulletin also details 23 additional high-severity flaws affecting various components of the platform.

    PatchArubaOS-CX
  2. The Hacker News
    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    Cisco has issued updates for a critical vulnerability, identified as CVE-2026-20212 with a CVSS score of 9.8, affecting ten models of Silicon One-based Nexus 9000 switches. This defect allows unauthenticated remote attackers to achieve root-level code execution by sending crafted input to exposed TCP ports 43210 and 43211 within the default Layer 3 VRF instance. Alongside this specific fix, Cisco released an IOS XR hardening update addressing seven umbrella CVEs, two of which carry a maximum severity rating of 9.8, impacting all versions without available workarounds.

    PatchCisco Nexus 9000
  3. BleepingComputer
    Critical Elementor Pro flaw exploited to take over WordPress sites

    Attackers are actively exploiting a critical vulnerability in the Elementor Pro WordPress plugin, identified as CVE-2026-32475, to gain remote command execution on affected servers. The flaw, which affects versions 4.2.1 and earlier, permits malicious PHP uploads by bypassing file-validation checks in form elements, resulting in webshell installation. Wordfence reports blocking approximately 200,000 related attack attempts since the fix was released on August 19. Site administrators should immediately update to Elementor Pro 4.2.2 or later and audit the /wp-content/uploads/elementor/forms/ directory for unauthorized files.

    Reported exploitedElementor Pro
  4. Bishop Fox
    Signature Optional - Analysis of CVE-2026-28323

    Bishop Fox researchers have disclosed CVE-2026-28323, a critical unauthenticated SAML authentication bypass affecting SolarWinds Web Help Desk versions 2026.1 and earlier, with a proof-of-concept exploit now available. The flaw permits attackers to forge a SAML Response and bypass signature verification entirely if no certificate is configured or if the assertion lacks a valid signature, enabling them to assume the identity of any known user. SolarWinds released version 2026.2.1 to address this issue by replacing the legacy SAML stack with Spring Security’s enforced validation mechanisms.

    PoC publicSolarWinds Web Help Desk
  5. BleepingComputer
    Plex warns users to patch security vulnerabilities immediately

    Plex has issued an urgent advisory urging users to immediately upgrade their installations to remediate several newly identified security vulnerabilities. These flaws, which have not yet been assigned official CVE identifiers, affect Plex Media Server versions up to and including v1.43.2, prompting the vendor to send direct email notifications to affected customers. The company recommends deploying Plex Media Server 1.43.3 and Plex Desktop 1.115.0 as soon as possible to mitigate potential risks, particularly for those using NAS devices who may need to install the updates manually.

    AdvisoryPlex Media Server
  6. SecurityWeek
    Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

    Security firm Defiant has issued a warning regarding a high-severity flaw in the All-in-One WP Migration and Backup plugin, which leaves approximately 3.2 million WordPress sites exposed to remote code execution attacks. Identified as CVE-2026-19949 with a CVSS score of 8.8, this second-order SQL injection vulnerability resides in the archive restore feature due to inadequate input escaping. An unauthenticated attacker can exploit this by submitting specific trackbacks that allow them to steal a secret key and subsequently upload a malicious plugin, resulting in full site compromise. The issue affects all versions prior to 7.110, so administrators should update their plugins to the latest release to mitigate the risk.

    PoC publicAll-in-One WP Migration and Backup
  7. SecurityWeek
    Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

    Cisco has issued security advisories addressing unpatched S/MIME decryption flaws in Secure Email, identified as CVE-2026-20354 and CVE-2026-20355, which expose users to man-in-the-middle attacks capable of revealing plaintext content. Simultaneously, the vendor deployed urgent patches for critical vulnerabilities in IOS XR and Nexus 9000 series switches, including high-severity defects like CVE-2026-20274 and CVE-2026-20212 that enable remote code execution and authentication bypass. While Cisco reports no active in-the-wild exploitation for these issues, the potential for severe compromise necessitates immediate attention for administrators managing affected network and mail infrastructure.

    PatchCisco Secure Email
  8. The Hacker News
    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    Security researcher Chaotic Eclipse has released a proof-of-concept exploit named FalconFlank, which targets a zero-day privilege escalation vulnerability in the Crowdstrike Falcon Sensor. The flaw enables attackers to escalate privileges by abusing the sensor’s office malicious macros remediation mechanism on fully patched systems, including Windows 11 25H2 and Windows Server 2025. This disclosure follows recent releases by the same researcher demonstrating similar vulnerabilities in Kaspersky and Microsoft Defender products.

    PoC publicCrowdStrike Falcon
  9. The Hacker News
    CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active real-world attacks. Among the critical additions are CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA 1000 Appliances, alongside CVE-2026-82329 in JFrog Artifactory and CVE-2026-9586 in Sangoma Switchvox. Microsoft and other researchers report that threat actors are leveraging these flaws to deploy reverse shells and cryptocurrency miners, with particular focus on AI infrastructure components like Kestra OSS and LiteLLM.

    Reported exploitedSonicWall SMA 1000

Wednesday, Sep 218 stories

  1. BleepingComputer
    Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

    Security researchers at Horizon3 have confirmed active exploitation of CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that allows attackers to achieve remote code execution. The flaw exists within the /pa HTTP endpoint, where input from the PhoneIP field is directly concatenated into SQL queries without proper sanitization. Attackers are currently using this weakness to deploy reverse shells and exfiltrate process information from vulnerable systems. Sangoma addressed this issue along with eleven other vulnerabilities in release 8.4.0.2, so immediate upgrades are recommended for all exposed instances.

    Reported exploitedSangoma Switchvox
  2. Dark Reading
    SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    Attackers are actively exploiting two zero-day vulnerabilities in specific SonicWall SMA 1000 models, allowing for unauthenticated remote code execution when the flaws are chained together. The issues include a critical pre-authentication server-side request forgery vulnerability (CVE-2026-83548, CVSS 10.0) and a post-authentication OS command injection flaw (CVE-2026-83549, CVSS 7.8). SonicWall advises customers running versions 12.4.3-03453 or 12.5.0-02835 on models 6210, 7210, and 8200v to immediately update to firmware versions 12.4.3-03526 or 12.5.0-02952. Organizations should also monitor for indicators of compromise and consider reimaging or redeploying appliances if breaches are detected.

    Reported exploitedSonicWall SMA 1000
  3. BleepingComputer
    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    ServMask has released version 7.110 of the All-in-One WP Migration and Backup plugin to fix a high-severity second-order SQL injection vulnerability identified as CVE-2026-19949. Discovered by researcher Jack Taylor and reported via Wordfence, this flaw affects versions through 7.109 and enables unauthenticated attackers to inject malicious code through WordPress trackbacks. The payload executes only when an administrator performs a backup or restore operation, potentially exposing secret keys and allowing full site takeover via a compromised archive. With over five million active installations, approximately 35% of users have already updated, leaving roughly 3.25 million sites still vulnerable.

    PatchWordPress
  4. BleepingComputer
    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    Attackers are actively exploiting a critical authentication bypass vulnerability, tracked as CVE-2026-82329, in self-managed JFrog Artifactory instances. This flaw exists within the default configuration and permits unauthenticated network attackers to forge administrative tokens, granting them full control over the repository manager. The compromise allows adversaries to tamper with trusted software artifacts, potentially injecting malicious code into downstream build and deployment systems that automatically pull packages from Artifactory. Because issued tokens remain valid even after binary upgrades, organizations must revoke existing credentials alongside applying patches. JFrog resolved the issue on August 28 in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.

    Reported exploitedJFrog Artifactory
  5. The Hacker News
    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Manifold Security has published details on a vulnerability class dubbed Git Spawn, affecting command-line AI coding agents from Anthropic, OpenAI, Cursor, and others. By exploiting the core.fsmonitor Git configuration, attackers can embed commands in a repository that execute as the user without sandboxing or approval prompts when the agent initializes. While patches have been released for goose, Claude Code, and Cursor, Manifold confirms that Hermes Agent, Qwen Code, and Grok Build remain vulnerable as of September 1. Affected CVEs include CVE-2026-19592 for Codex and CVE-2026-72718 for goose.

    PoC publicClaude Code
  6. Help Net Security
    Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

    A working exploit for CVE-2026-62911 has appeared online, leaving nearly 22,000 instances of Microsoft Exchange Server vulnerable to a critical authentication bypass. This flaw allows attackers to elevate privileges over the network, with the United States and Germany reporting the highest concentration of unpatched systems. Microsoft issued a fix on August 11, 2026, following disclosure by Orange Tsai in collaboration with Trend Micro’s Zero Day Initiative.

    PoC publicMicrosoft Exchange Server
  7. Help Net Security
    Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

    Threat actors are actively exploiting an unauthenticated SQL injection vulnerability in Sangoma Switchvox, identified as CVE-2026-9586. The flaw affects the SMB Edition 8.3 and allows attackers to execute arbitrary code against the underlying PostgreSQL database via a specific HTTP POST request. Honeypot data indicates that attacks began on August 30, with intruders deploying reverse shells and enumerating system processes. Organizations should immediately verify whether they are running version 8.4.0.2, the patch released by Sangoma on July 14, 2026, which resolves this issue. If updating is not possible immediately, administrators should restrict network access to the affected "/pa" endpoint to mitigate risk.

    Reported exploitedSangoma Switchvox
  8. SecurityWeek
    Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

    Rockwell Automation has issued patches and workarounds for over a dozen vulnerabilities spanning several of its industrial automation platforms. The updates address high-severity denial-of-service issues in RSLinx Classic and ControlLogix, as well as remote code execution flaws in FactoryTalk Historian and arbitrary code execution risks in the ControlFLASH firmware management utility. Additional fixes resolve cross-site scripting attacks in ArmorStart Distributed Motor Controllers and privilege escalation vulnerabilities in both FactoryTalk Activation Manager and the Redundancy Module Configuration Tool. While an initial advisory flagged CVE-2026-9637 as exploited, CISA and subsequent documentation confirm there is no evidence of active exploitation.

    PatchRSLinx Classic
  9. SecurityWeek
    Exploit Published for Fresh Cleo Harmony Vulnerability

    A working exploit has been made available for CVE-2026-84115, a critical authentication bypass vulnerability affecting the Cleo Harmony file transfer application. The defect lies within the JWT refresh token logic, specifically allowing attackers to manipulate bearer tokens in HTTP headers to escalate privileges and bypass access controls. This poses a severe risk as organizations can suffer from persistent access or lateral movement across integrated systems. Users are urged to update to Cleo Harmony version 5.8.1.11 immediately, particularly because the product is a frequent target for ransomware groups such as Cl0p.

    PoC publicCleo Harmony
  10. The Hacker News
    Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

    SonicWall has released patches for two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series, confirming active exploitation in the wild where attackers may be chaining the flaws together. The issues include a critical pre-authentication SSRF vulnerability, CVE-2026-83548 (CVSS score: 10.0), and a post-authentication command injection flaw, CVE-2026-83549 (CVSS score: 7.8), both of which can lead to unauthorized access or remote code execution. Users running versions prior to 12.4.3-03526 or 12.5.0-02952 on SMA 6210, 7210, and 8200v models are urged to upgrade immediately and check for indicators of compromise.

    Reported exploitedSonicWall SMA 1000 Series
  11. Help Net Security
    SonicWall SMA 1000 appliances under attack via zero-day flaws

    SonicWall has verified that attackers are actively leveraging two newly disclosed flaws, identified as CVE-2026-83548 and CVE-2026-83549, against its SMA 1000 line of secure remote access appliances. The first issue is a pre-authentication server-side request forgery vulnerability, while the second allows administrators to execute remote code through OS command injection in the management console. Affected hardware includes physical models 6210 and 7210, as well as the virtual 8200v instance, whereas SMA 100 devices and other SonicWall firewalls remain unaffected. Given the critical nature of the risk, the vendor advises organizations to deploy the available emergency hotfix without delay and to perform a thorough compromise assessment.

    Reported exploitedSonicWall SMA 1000 Appliances
  12. The Hacker News
    GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

    OSGeo has released updates for GeoNetwork, addressing two vulnerabilities that allow attackers to achieve remote code execution without authentication. The exploit chain combines CVE-2026-63219, a missing authorization check on the formatter upload endpoint, with CVE-2026-58400, an unsafe configuration of the Saxon XSLT processor. These flaws affect versions prior to 4.4.12 and 4.2.17, which were fixed in July 2026. Because GeoNetwork underpins many government geoportals, including the European INSPIRE portal, this exposure is significant. Security researchers identified over 120 exposed instances worldwide, with the majority belonging to public sector organizations. Administrators should upgrade immediately or block write requests to the formatter endpoint as a temporary mitigation.

    PatchGeoNetwork
  13. SecurityWeek
    Chrome and Firefox Updates Patch Dozens of Vulnerabilities

    Google and Mozilla have released updated versions of their respective browsers to address numerous security vulnerabilities. The new Chrome 152 update includes fixes for 26 bugs, notably critical use-after-free flaws identified as CVE-2026-84353 and CVE-2026-84352, alongside nine high-severity defects. Concurrently, Firefox 155 was deployed to resolve 29 security issues, including 13 high-severity problems involving sandbox escapes and memory corruption within various core components. These updates are available for Windows, macOS, and Linux users, with corresponding patches also released for Thunderbird and Firefox ESR branches. Neither vendor has indicated that these specific vulnerabilities are currently being exploited in the wild.

    PatchChrome
  14. The Hacker News
    Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

    Forescout Research utilized Anthropic's Claude to adapt a pre-authentication remote code execution exploit from one Siemens-made WAGO Programmable Logic Controller model to another, successfully executing shellcode on the target hardware. The attack leverages CVE-2021-31886, a critical stack-based buffer overflow in the Nucleus RTOS FTP server that allows unauthenticated attackers to inject malicious code via TCP port 21. As no software update is currently available for the affected WAGO devices, CERT@VDE recommends disabling the FTP service, implementing network segmentation, and closely monitoring traffic for suspicious activity.

    PoC publicWAGO PLCs
  15. The Hacker News
    Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

    Attackers are actively exploiting a critical unauthenticated SQL injection vulnerability, tracked as CVE-2026-9586, in Sangoma Switchvox SMB Edition 8.3 (104997). This flaw, which carries a CVSS score of 9.3, permits remote code execution as the PostgreSQL superuser without requiring any credentials by manipulating data through the /pa endpoint. Sangoma released a patch for this issue in version 8.4.0.2 on July 14, 2026, but recent reports indicate that exploitation attempts began appearing in the wild starting August 30, 2026. Security researchers have observed attackers deploying reverse shells and attempting to exfiltrate sensitive keys from roughly 4,000 exposed instances, many of which remain vulnerable.

    Reported exploitedSwitchvox SMB Edition
  16. BleepingComputer
    SonicWall warns of actively exploited SMA1000 zero-day flaws

    SonicWall has issued an urgent advisory stating that threat actors are actively exploiting a pair of zero-day vulnerabilities in its SMA1000 secure remote access appliances. The attack campaign chains a maximum-severity command injection flaw (CVE-2026-83548), caused by a server-side request forgery weakness, with a second command injection vulnerability (CVE-2026-83549) accessible to administrators with valid credentials. This combination allows attackers to achieve remote code execution on affected devices. The vulnerabilities impact SMA1000 models 6210, 7210, and 8200v, while SSL-VPN services on other SonicWall firewalls and the SMA 100 Series remain unaffected. SonicWall strongly urges customers to apply the available hotfix release immediately to mitigate these risks.

    Reported exploitedSMA1000
  17. SecurityWeek
    SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

    SonicWall has identified active exploitation of two zero-day vulnerabilities affecting its SMA1000 secure remote access gateways. The critical flaw, CVE-2026-83548, allows unauthenticated attackers to execute unauthorized operations via a server-side request forgery vulnerability in the Appliance Work Place interface. This is often paired with CVE-2026-83549, an authenticated OS command injection issue that can lead to full remote code execution within the management console. SMA1000 models 6210, 7210, and 8200v are susceptible to these attacks. Administrators should apply hotfixes 12.4.3-03526 or 12.5.0-02952 immediately to mitigate the risk.

    Reported exploitedSMA1000
  18. Dark Reading
    Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

    Hunt.io researchers uncovered an active data exfiltration campaign targeting the Philippines Nuclear Regulatory Authority and a maritime contractor supporting the Philippine Navy, revealing that long-unpatched systems remained exploitable despite available fixes. The intrusion leveraged CVE-2023-49105 in ownCloud and CVE-2024-2800 in the LiteSpeed Cache WordPress plugin, both of which have had remediations available for over two years. The attackers harvested approximately 9 GB of sensitive material, including reactor core component databases, fuel inventories, radiation safety protocols, and personnel records such as passports and financial disclosures. This incident underscores the persistent risk posed by internet-facing collaboration tools that lack timely patching and hardened configurations, particularly in regions facing heightened geopolitical cyber threats.

    IncidentownCloud

Tuesday, Sep 12 stories

  1. Dark Reading
    Attackers Pounce on Critical Artifactory Flaw Following Disclosure

    Threat actors have begun active exploitation of CVE-2026-82329, a critical authentication bypass vulnerability in JFrog Artifactory, just days after its public disclosure. With a CVSS score of 9.8, this flaw enables unauthenticated attackers to gain administrative privileges on self-hosted deployments, potentially compromising software repositories and build artifacts. While JFrog clarified that this incident is distinct from recent attacks involving OpenAI and Hugging Face, watchTowr telemetry confirms attackers are already minting admin tokens and enumerating system details. Organizations using affected versions must urgently patch their systems and rotate credentials, as Internet-exposed instances should be treated as compromised.

    Reported exploitedJFrog Artifactory
  2. Dark Reading
    Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

    VulnCheck reports active exploitation of CVE-2026-0768, a critical remote code execution vulnerability in IBM's AI platform Langflow. With a CVSS score of 9.8, the flaw enables attackers to execute arbitrary code on internet-exposed instances, leading to credential theft, lateral movement, and data exfiltration. Despite Langflow's low-code nature simplifying AI agent creation, its default configurations often leave it vulnerable to widespread scanning and persistent backdoor installation by global threat actors.

    Reported exploitedLangflow

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store