Articles tagged "CVE"

Found 574 articles

Critical
igloohome Smart Lock Mobile Application

All CISA Advisories

A vulnerability in the igloohome Smart Lock Mobile Application has been discovered, affecting version 3.2.3 and earlier. This flaw, identified as CVE-2026-16581, allows unauthorized access to backend services due to sensitive information being included in the application's source code. As a result, attackers could exploit this weakness to access functionality that should be protected by authentication measures. igloohome has addressed the issue by enhancing access controls to prevent unauthorized requests. Users are advised to ensure they are using the latest version of the app to mitigate risks.

Read Original

JetBrains has addressed a significant security vulnerability in its TeamCity software, identified as CVE-2026-63077, which has a CVSS score of 9.8. This flaw allows unauthenticated attackers to execute arbitrary code on affected on-premise servers, posing a serious risk to organizations using TeamCity. All versions of TeamCity On-Premises are vulnerable, which means that a wide range of users could be impacted if they do not take immediate action. The potential for server takeover highlights the importance of applying security updates promptly to safeguard systems. JetBrains has released patches to mitigate this vulnerability, urging users to update their installations as soon as possible.

Read Original

JetBrains has addressed a significant security vulnerability (CVE-2026-63077) in its TeamCity On-Premises software that could allow attackers to execute code without authentication. This flaw affects users who host TeamCity servers themselves, making it crucial for administrators to act swiftly. JetBrains is urging these users to upgrade their installations immediately to protect against potential exploitation. For those unable to upgrade right away, the company has provided a security patch plugin as a temporary fix. Given TeamCity's popularity as a continuous integration and delivery tool, the urgency of this update is clear, as unpatched systems could become prime targets for cyberattacks.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities associated with Arista VeloCloud Orchestrator and Fortinet's FortiOS to its Known Exploited Vulnerabilities catalog. The specific vulnerability for Arista is identified as CVE-2025-68686. This inclusion indicates that these flaws are being actively exploited, posing a significant risk to users of these products. Organizations using Arista's VeloCloud Orchestrator or Fortinet's FortiOS should take immediate action to address these vulnerabilities to safeguard their systems from potential attacks. The urgency of this update emphasizes the need for timely patching and monitoring of network security.

Read Original

JetBrains has alerted users of on-premise TeamCity versions about a serious security vulnerability that could allow attackers to execute arbitrary commands on affected systems without needing to log in. This flaw, identified as CVE-2026-63077, has a high severity score of 9.8, indicating the potential for significant damage if exploited. It impacts all versions of TeamCity On-Premises, prompting JetBrains to recommend that users immediately update to the latest versions, 2025.11.7 or 2026.1.3, to safeguard their installations. TeamCity Cloud users are not affected, as the vulnerability has already been patched in that environment. This issue stresses the importance of timely software updates to prevent unauthorized access and control over systems.

Read Original

A researcher at STAR Labs has disclosed a significant security vulnerability in the Linux kernel, specifically affecting the CentOS Stream 9 build. The flaw, identified as CVE-2026-53264, has a CVSS score of 7.8, indicating a high severity level. This vulnerability is a use-after-free race condition in the kernel's network traffic-control subsystem, allowing a local user to escalate their privileges to root. The researcher, Lee Jia Jie, noted that artificial intelligence tools assisted in discovering the bug and accelerating the exploit's development. This incident raises concerns for users running the affected version, as it enables potential unauthorized access and control over systems.

Read Original

A serious security flaw has been discovered in the on-premises version of Arista's VeloCloud Orchestrator, identified as CVE-2026-16812, which carries a maximum CVSS score of 10.0. This vulnerability is a command injection issue that could allow attackers to execute arbitrary code on affected systems. As it is actively being exploited in the wild, organizations using this software need to be particularly vigilant. The flaw affects on-premises deployments of the VeloCloud Orchestrator, which is used for managing network services. The implications of this vulnerability are significant, as it could lead to unauthorized access and control over critical network functions if left unaddressed.

Read Original

n8n, an automation platform, has addressed a serious security vulnerability that could allow authenticated users to execute operating system commands on the server. This flaw was discovered by Security Joes during their investigation of a previous fix related to CVE-2026-27577. The vulnerability affects versions 2.32.0 and earlier, specifically those prior to 2.32.1. The situation is critical as it could enable potential attackers to gain unauthorized access and control over the server, posing significant risks to any organization using n8n for their automation needs. Users are strongly urged to update to the patched versions to mitigate these risks.

Read Original

Researchers have identified a significant vulnerability in Active Directory Certificate Services (AD CS), designated as CVE-2026-54121, also known as 'Certighost.' This flaw allows attackers to elevate privileges, potentially leading to a complete domain takeover. AD CS is a critical component of Microsoft Windows Server that organizations use to manage their Public Key Infrastructure (PKI). The release of a proof-of-concept exploit means that attackers may quickly learn how to exploit this vulnerability. Organizations using AD CS should be particularly vigilant as the risk of exploitation increases with the availability of this exploit.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being exploited by attackers. The first vulnerability, CVE-2025-68686, affects Fortinet's FortiOS, allowing unauthorized access to sensitive information. The second, CVE-2026-16812, impacts Arista's VeloCloud Orchestrator, enabling command injection attacks on the on-premises operating system. These vulnerabilities pose serious risks, particularly to federal agencies, which are urged to prioritize their remediation under Binding Operational Directive 26-04. While the directive specifically targets federal civilian agencies, CISA recommends that all organizations adopt similar risk-based approaches to vulnerability management to protect against these threats.

Read Original

Attackers are exploiting a serious vulnerability in Fastjson, a JSON library developed by Alibaba for Java applications, particularly those using Spring Boot. This flaw, identified as CVE-2026-16723, allows unauthorized code execution with the privileges of the Java process, posing significant risks to affected systems. The vulnerability has a high severity rating of 9.0, indicating it could lead to severe consequences if not addressed. Currently, there are no patches available to fix this issue, which increases the urgency for developers and organizations using Fastjson to take immediate protective measures. Security firms have reported that this vulnerability is being actively exploited, making it critical for users to assess their systems and implement necessary safeguards.

Read Original

A recent security flaw in Bing's image processing system allowed crafted SVG files to execute commands with elevated privileges, specifically as NT AUTHORITY\SYSTEM on Windows servers and as root on Linux machines. This vulnerability was identified through testing by security researchers at XBOW, who found that the issue was not isolated to a single machine but was present across multiple hosts and network ranges within Bing’s infrastructure. Microsoft responded by issuing two critical CVEs, CVE-2026-32194 and another unnamed one, to address the vulnerabilities. This incident raises significant concerns about the security of cloud-based services and the potential for attackers to exploit similar flaws to gain unauthorized access to sensitive systems. Companies relying on these services should prioritize patching and review their security protocols to mitigate risks from this kind of vulnerability.

Read Original
Critical
MZ Automation lib60870

All CISA Advisories

MZ Automation's lib60870 software, used in critical infrastructure sectors like chemical, energy, and water management, has a serious vulnerability that could lead to denial of service. Specifically, versions 2.4.0 and earlier are affected by an out-of-bounds read issue, which can crash the parsing process. This flaw has a CVSS score of 8.2, indicating high severity. Users are urged to update to version 2.4.1 or later to mitigate the risk. Organizations should also follow CISA's recommendations to secure their control systems, including limiting network exposure and using VPNs for remote access. Currently, there are no reports of this vulnerability being actively exploited in the wild.

Read Original
Critical
Weintek cMT3092X

All CISA Advisories

Weintek's cMT3092X human-machine interface (HMI) has several security vulnerabilities that could allow unauthorized users to escalate their privileges or access sensitive user credentials. The affected firmware versions include those below 20210218 and EasyWeb versions prior to 2.1.20. Notably, vulnerabilities include reliance on unvalidated cookies, incorrect permission assignments, and the storage of passwords in plaintext. Weintek has issued a patch, cmt_typeB_20260316_007, which upgrades EasyWeb to version 2.3.17 to address these issues. Users are urged to apply this patch immediately to protect their systems.

Read Original
Critical
Johnson Controls XAAP Android

All CISA Advisories

A vulnerability has been identified in the Johnson Controls XAAP Android application, specifically in versions prior to 1.53. This flaw allows sensitive data to be stored in cleartext on devices, making it accessible to attackers who have physical access or can exploit another vulnerability on the device. The issue does not require network access and poses risks to users worldwide, particularly in critical manufacturing sectors. Johnson Controls advises users to upgrade to version 1.53 or later to mitigate this risk, and recommends implementing additional security measures such as restricting physical access, enabling device encryption, and using Mobile Device Management solutions to enforce security policies. Currently, there have been no reports of this vulnerability being actively exploited in the wild.

Read Original
PreviousPage 12 of 39Next