Articles tagged "CVE"

Found 571 articles

Broadcom has issued security updates to fix several vulnerabilities affecting VMware products, including ESX, vCenter, Workstation, and Fusion. Among these, three flaws are deemed critical, with CVE-2026-59309 being the most severe, rated at 9.8 on the CVSS scale. This particular flaw allows attackers with network access to VMware vCenter to bypass authentication, potentially leading to unauthorized access. Other vulnerabilities could enable code execution and VM escape, which poses significant risks for virtualized environments. Organizations using these VMware products should prioritize applying the updates to safeguard against potential exploits.

Read Original

Broadcom has addressed a serious vulnerability in VMware ESXi that could allow attackers to execute code on a host machine from a compromised virtual machine. This flaw, identified as CVE-2026-47876, has a high severity rating of 9.3 on the CVSS scale, indicating a significant risk. Alongside this critical issue, Broadcom released patches for four other vulnerabilities affecting VMware's ESXi, vCenter, Workstation, and Fusion products, three of which are also classified as critical. Companies using these systems should prioritize applying the patches to safeguard their environments, as the potential for exploitation could lead to severe data breaches or system compromises.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, marking it as a significant risk due to active exploitation. The vulnerability, identified as CVE-2026-20316, affects the Cisco Secure Firewall Management Center and involves the use of a hard-coded password. This type of vulnerability is a common target for attackers and poses serious risks, particularly for federal agencies. CISA's Binding Operational Directive 26-04 mandates that federal agencies prioritize rapid fixes for such vulnerabilities to protect their systems. While the directive specifically applies to federal agencies, CISA encourages all organizations to adopt similar practices to manage vulnerabilities effectively.

Read Original

Researchers at Nebula Security have discovered a serious vulnerability in the Tor Browser, linked to a flaw in Firefox's Just-In-Time (JIT) compiler. This vulnerability, identified as CVE-2026-10702, allows attackers to execute arbitrary code within the browser's renderer process simply by having a user visit a malicious webpage. Mozilla has classified this issue as high severity and has released a patch in Firefox version 151.0.3 to address the flaw. Since the Tor Browser is built on Firefox, users of Tor are particularly at risk, as no special settings or actions are needed from them to be compromised. This situation raises significant concerns about the security of users relying on the Tor network for privacy and anonymity online.

Read Original

A serious security flaw has been discovered in Check Point's SmartConsole, allowing attackers to bypass authentication. This vulnerability, identified as CVE-2026-16232, has a high severity rating of 9.3 and affects both the Check Point Security Management Server and Multi-Domain Security Management Server (MDS). Researchers have found that this vulnerability is currently being exploited in the wild, which raises significant concerns for organizations using these systems. Companies should take immediate action to secure their environments as the flaw can enable unauthorized access, potentially leading to data breaches or system compromises. It's crucial for affected users to stay updated on this issue and apply any necessary patches as they become available.

Read Original

Gitea has addressed a serious remote code execution (RCE) vulnerability that could allow users with write access to repositories to execute shell commands. This flaw, identified as CVE-2026-60004, has a high severity score of 9.8 and affects Gitea versions from 1.17 up to, but not including, 1.27.1. Essentially, an attacker could manipulate patch content to create a Git hook that runs commands as the Gitea service account. The vulnerability poses a significant risk to self-hosted Git users, as it could lead to unauthorized access and control over systems running Gitea. Users are strongly advised to update to version 1.27.1 to mitigate this risk.

Read Original

OpenWrt has released version 24.10.8 to address a serious vulnerability in its DHCPv6 service, identified as CVE-2026-53921. This flaw has a CVSS score of 9.8, indicating a high level of risk, as it allows unauthenticated attackers to exploit a stack overflow in the odhcpd component. If attackers can reach the DHCPv6 server, they could potentially execute code with root privileges. This vulnerability affects users running OpenWrt versions that include the vulnerable DHCPv6 stack, which is enabled by default in many configurations. Users are strongly advised to update their systems to maintain security and prevent unauthorized access.

Read Original
Critical
Siemens Mendix Runtime

All CISA Advisories

Siemens has issued a warning regarding vulnerabilities in the Mendix Runtime, specifically related to the documentation on access rules for the System.User entity. Developers may unintentionally set overly permissive access rules due to inadequate guidance, which can lead to unauthorized access to sensitive user data or privilege escalation in applications. A notable misconfiguration involves the anonymous user role, which could allow access to all stored records without explicit permissions. Siemens is urging Mendix developers to review their access configurations in light of this issue. This vulnerability affects all versions of Siemens Mendix Runtime and has been assigned the CVE identifier CVE-2026-7891, with a critical severity rating of 9.1 on the CVSS scale.

Read Original

MikroTik has disclosed a significant vulnerability affecting all versions of its RouterOS and Cloud Hosted Router software, identified as CVE-2026-16347. This flaw allows attackers to bypass safeguards against excessive login attempts, making it easier for them to guess passwords and gain unauthorized access to systems. Users worldwide are at risk, particularly in sectors like information technology and commercial facilities. Currently, no fix is available, prompting MikroTik to advise users to implement several mitigations, such as using strong VPNs, restricting access from untrusted networks, and employing long, complex passwords. The vulnerability underscores the need for organizations to bolster their security measures to protect against potential breaches.

Read Original
Critical
Siemens SIMATIC S7-PLCSIM Advanced

All CISA Advisories

Siemens has identified a vulnerability in its SIMATIC S7-PLCSIM Advanced software that could lead to a denial of service (DoS) condition. This issue arises from the software's inability to manage high-volume multicast network traffic, which can deplete available memory resources and make the application inaccessible. Although no project data is lost during this downtime, the affected application needs to be manually restarted. The vulnerability, tracked as CVE-2026-54429, impacts all versions of the SIMATIC S7-PLCSIM Advanced software and can be exploited by an unauthenticated attacker on the local network. Siemens is currently working on fixes and recommends users take specific countermeasures to mitigate the risk until updates are available.

Read Original
Critical
Siemens Desigo CC

All CISA Advisories

Siemens has issued a warning about a serious vulnerability affecting its Desigo CC product family, which includes versions V7, V8, and V9 prior to 9.0.1. This vulnerability, identified as CVE-2025-15467, can be exploited by remote attackers to trigger a stack-based buffer overflow, potentially leading to denial of service or even remote code execution. The risk arises when parsing certain CMS messages with maliciously crafted parameters. Siemens has released updates for some affected versions and is advising users to upgrade to the latest versions. For those unable to update immediately, Siemens suggests implementing additional security measures to mitigate the risk. This vulnerability is particularly concerning given the critical infrastructure sectors affected, as these systems are essential for operations worldwide.

Read Original
Critical
ABB KNX Update Tool

All CISA Advisories

ABB has confirmed a vulnerability in its KNX Update Tool that affects classic KNX devices, which do not support the newer KNX Secure standard. This vulnerability, identified as CVE-2026-12705, allows an attacker with physical access to the device's bus to potentially render it unusable or alter its behavior by tampering with the firmware. ABB has stated that there are no software updates available to address this issue due to the inherent security limitations of legacy KNX devices. Users are advised to limit physical access to these devices and avoid using them for sensitive applications, as there are no plans for corrective measures from ABB. This incident highlights ongoing security challenges with older industrial protocols.

Read Original
Critical
igloohome Smart Lock Mobile Application

All CISA Advisories

A vulnerability in the igloohome Smart Lock Mobile Application has been discovered, affecting version 3.2.3 and earlier. This flaw, identified as CVE-2026-16581, allows unauthorized access to backend services due to sensitive information being included in the application's source code. As a result, attackers could exploit this weakness to access functionality that should be protected by authentication measures. igloohome has addressed the issue by enhancing access controls to prevent unauthorized requests. Users are advised to ensure they are using the latest version of the app to mitigate risks.

Read Original

JetBrains has addressed a significant security vulnerability in its TeamCity software, identified as CVE-2026-63077, which has a CVSS score of 9.8. This flaw allows unauthenticated attackers to execute arbitrary code on affected on-premise servers, posing a serious risk to organizations using TeamCity. All versions of TeamCity On-Premises are vulnerable, which means that a wide range of users could be impacted if they do not take immediate action. The potential for server takeover highlights the importance of applying security updates promptly to safeguard systems. JetBrains has released patches to mitigate this vulnerability, urging users to update their installations as soon as possible.

Read Original

JetBrains has addressed a significant security vulnerability (CVE-2026-63077) in its TeamCity On-Premises software that could allow attackers to execute code without authentication. This flaw affects users who host TeamCity servers themselves, making it crucial for administrators to act swiftly. JetBrains is urging these users to upgrade their installations immediately to protect against potential exploitation. For those unable to upgrade right away, the company has provided a security patch plugin as a temporary fix. Given TeamCity's popularity as a continuous integration and delivery tool, the urgency of this update is clear, as unpatched systems could become prime targets for cyberattacks.

Read Original
PreviousPage 11 of 39Next