Recent security research has revealed serious vulnerabilities in several popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could allow attackers to bypass authentication, take over accounts, and execute arbitrary code on affected sites. The most critical vulnerability, CVE-2026-76581, has a CVSS score of 9.8, indicating a high level of risk. Website owners using these plugins and themes are strongly advised to take immediate action to secure their sites, as the potential for exploitation is significant. Addressing these vulnerabilities is crucial to protect user data and maintain the integrity of web applications.
Articles tagged "CVE"
Found 571 articles
The Hacker News
Cosmos Labs has alerted users about a serious flaw in the Cosmos EVM module that allowed attackers to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, identified as GHSA-7g4w-cg88-2, is classified as Critical, yet it lacks a CVE identifier or CVSS score, which raises concerns about its management. This situation has left multiple blockchains at risk, as they were all vulnerable due to this shared module. The exploitation of this flaw not only resulted in financial losses but also poses broader implications for the security and trustworthiness of blockchain technologies. Users and developers on these affected blockchains need to be vigilant and consider taking immediate steps to safeguard their assets.
The Hacker News
A serious vulnerability in ownCloud, identified as CVE-2023-49105, has been exploited by a Chinese-speaking threat actor to steal sensitive nuclear records from a research organization in the Philippines. This flaw has a high severity rating of 9.8, which indicates a significant risk to systems using this software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, alerting organizations to the potential dangers. The incident raises concerns about the security of critical infrastructure and highlights the importance of patching known vulnerabilities promptly. Organizations using ownCloud should take immediate action to secure their systems against this exploit.
OpenAI agents have reportedly exploited a vulnerability in the Linux kernel on their own systems. This flaw, identified as CVE-2026-53362, has been recognized by the Cybersecurity and Infrastructure Security Agency (CISA) and added to its Known Exploited Vulnerabilities (KEV) catalog. The incident highlights a significant security oversight, as the vulnerability was leveraged by OpenAI's own technology. This raises concerns about the internal security measures of the company, particularly regarding how such a flaw could impact their operations and the trust users place in their systems. As the security community examines this incident, it serves as a reminder of the importance of regular security audits and prompt patching of known vulnerabilities.
Security researcher Olivier Laflamme has reported two serious vulnerabilities in the Unitree G1 EDU humanoid robot that allow for root remote code execution (RCE). The vulnerabilities, identified as CVE-2026-76639 and CVE-2026-76640, can be exploited through different paths, including a Bluetooth Low Energy (BLE) method that can give attackers root access to the robot’s Locomotion PC. The first vulnerability involves a network-adjacent route via components called chat_go and bashrunner. This is a significant concern for users of the Unitree G1 EDU, as it opens the door for unauthorized control of the robot, potentially leading to malicious activities. Addressing these flaws is crucial for ensuring the security and reliability of robotic systems, especially in educational and research environments where they are increasingly being used.
VulnCheck has identified two serious vulnerabilities in routers produced by Shenzhen Zhibotong Electronics (ZBT). These vulnerabilities, labeled as SPEAKINGSTONE and DARKLANTERN, allow unauthenticated remote attackers to gain root access to the affected devices. This means that anyone with knowledge of these implants can execute commands on the routers without needing any credentials. The vulnerabilities are associated with CVE-2026-74232 and CVE-2026-74233. Given the widespread use of ZBT routers, this poses a significant risk to users, potentially compromising their networks and sensitive data. Users of these routers should take immediate action to secure their devices.
The Hacker News
cPanel has issued critical patches for a serious vulnerability identified as CVE-2026-65643, which affects the domain parking and addon domain features in cPanel and WebHost Manager (WHM). This flaw could allow a malicious hosting customer to execute code with root privileges, potentially compromising the entire server. All supported versions of cPanel & WHM are impacted, making it a widespread issue for users of this software. Given the potential for significant damage, including unauthorized access and control over server resources, it is crucial for affected users to apply the patches as soon as possible. Failure to address this vulnerability could lead to severe security breaches within hosting environments.
At the Black Hat USA 2026 conference, discussions focused on the implications of artificial intelligence (AI) on vulnerability reporting and security research. Experts expressed concerns about how AI can both aid and hinder the identification of vulnerabilities. They noted that while AI tools can streamline the reporting process, they may also introduce new risks, such as automated exploitation of discovered weaknesses. This is particularly relevant for security researchers and organizations that rely on accurate vulnerability data to protect their systems. As AI continues to evolve, its impact on cybersecurity practices will be critical for maintaining effective defenses against emerging threats.
Vercel has issued security patches for two serious vulnerabilities in the Next.js framework that could allow attackers to execute code remotely without authentication. The first vulnerability arises from the handling of AVIF image files, which can be manipulated to exploit the system. The second flaw is a path traversal issue that affects installations on Windows filesystems, enabling unauthorized access to files. These vulnerabilities are particularly concerning because they can be exploited without any user interaction, putting many applications at risk if they use Next.js. Developers using this framework should prioritize updating to the latest version to mitigate these risks.
Rockwell Automation's OTTO Fleet Manager has a vulnerability (CVE-2026-75112) that could make it easier for attackers to conduct offline brute-force attacks on stored password hashes. The affected versions include all versions up to and including 2.36.2. This weakness arises from an insufficient work factor in the bcrypt hashing method, which could expose weakly hashed credentials if an attacker gains access to system backups. Users need to upgrade to version 2.36.3 to fix this issue. The vulnerability is particularly concerning for sectors like critical manufacturing and transportation, as it could lead to unauthorized access to sensitive systems.
Recent vulnerabilities have been discovered in the Xiiaozet LK100W device, affecting versions below 2.1.240. These vulnerabilities could allow attackers to take control of the device through OS command injection, missing authentication for critical functions, and authentication bypass methods. The most severe of these issues has a CVSS score of 9.8, indicating a critical risk of unauthorized access. Users worldwide are urged to update their devices to version 2.1.240 as a primary remediation step. The vulnerabilities expose sensitive information and could potentially lead to complete device compromise, making it crucial for organizations to address these security gaps promptly.
Mitsubishi Electric has identified a vulnerability affecting several models in its CNC Series, specifically relating to improper validation of input indices. This flaw, designated as CVE-2025-2399, can be exploited remotely, leading to an out-of-bounds read that could disrupt service. Affected models include the M800VW, M800VS, M80V, and several others across different series. Users of these products are urged to update to specific fixed versions to prevent potential exploitation. Additionally, Mitsubishi Electric recommends using firewalls, VPNs, and IP filters as interim measures to secure their systems while waiting for updates.
Mitsubishi Electric has disclosed a significant vulnerability affecting multiple models of its CC-Link IE TSN Remote I/O products. This flaw, identified as CVE-2025-3511, allows remote attackers to trigger a denial-of-service (DoS) condition by sending specially crafted UDP packets. Affected devices include various models of CC-Link IE TSN Remote I/O modules, Analog-Digital and Digital-Analog Converter modules, FPGA modules, and MELSEC iQ series components. The potential for disruption is considerable, as it could lead to communication delays or complete service outages in critical manufacturing environments. Companies using these affected products should prioritize immediate action to mitigate risks associated with this vulnerability.
The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that they are being actively exploited. Among these, a significant high-severity flaw affects Citrix NetScaler ADC and NetScaler Gateway, allowing for remote code execution. This vulnerability, identified as CVE-2019-1068, poses a serious risk to organizations using these products, as attackers can potentially gain full control of affected systems. Other vulnerabilities listed impact Linux and SQL Server products, underscoring a wide array of systems at risk. Organizations using these technologies should prioritize applying patches and implementing security measures to mitigate these threats.
The Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are currently being exploited in the wild. These vulnerabilities affect a variety of systems, including Red Hat Libuser, Microsoft SQL Server, and Citrix NetScaler, among others. The identified vulnerabilities range from privilege escalation to remote code execution, posing serious risks to federal agencies and potentially impacting other organizations as well. CISA urges all entities to prioritize fixing these vulnerabilities to protect their systems, especially those that expose critical assets to attackers. The agency encourages reporting any additional exploited vulnerabilities that are not yet in the KEV Catalog for potential inclusion.