Articles tagged "Vulnerability"

Found 1435 articles

A newly discovered race condition in Ubuntu's snap-confine component allows local users to escalate their privileges to root on default installations. This vulnerability could enable attackers to gain full control over the system, posing significant risks, especially in environments where users have access to these installations. Users running Ubuntu with default settings should be particularly cautious, as the flaw could be exploited by anyone with local access. The issue highlights a critical need for users and administrators to stay updated on security patches. Ubuntu has not specified a timeline for when a fix will be available, so users are encouraged to monitor official channels for updates and apply any recommended mitigations as soon as they are released.

Read Original

A serious remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is currently being exploited by attackers. This vulnerability has a CVSS score of 9.8, indicating its severity. It was patched during Microsoft's July 2026 Patch Tuesday, but following the release of public proof-of-concept (PoC) exploit code, researchers from watchTowr have observed active exploitation in the wild. Organizations using SharePoint need to ensure they have applied the latest updates to protect against potential breaches. The situation underscores the urgency for companies to stay current on security patches to mitigate risks associated with known vulnerabilities.

Read Original

Rockwell Automation has reported a vulnerability affecting their 1718-AENTR and 1719-AENTR products, specifically version 3.011 of the Ex I/O series. This flaw can lead to a denial-of-service condition, where the device becomes overloaded due to improper handling of a UDP unicast network storm, resulting in loss of communication. Recovery from this issue requires a power cycle. Users worldwide are advised to upgrade to version 3.012 or later to mitigate this risk. For those unable to upgrade, Rockwell Automation recommends following their security best practices to minimize exposure. This vulnerability is significant as it impacts devices used in critical manufacturing sectors, raising concerns about operational stability and security.

Read Original

Rockwell Automation's Studio 5000 Logix Designer has several vulnerabilities that could allow local attackers to execute arbitrary files and alter configurations. Versions affected include Studio 5000 Logix Designer V36.00 and various iterations of V35.00, V35.01, and earlier versions down to V32.00. The vulnerabilities, identified as CVE-2026-9108, CVE-2026-9127, and CVE-2026-9128, have been assigned high severity scores, indicating they could pose significant risks to users. Rockwell Automation has released updates to address these issues, and users unable to upgrade should follow the company's security best practices to mitigate risks. The potential for exploitation of these vulnerabilities highlights the need for organizations to maintain robust cybersecurity defenses.

Read Original
Critical
Siemens CADRA

All CISA Advisories

Siemens has identified multiple vulnerabilities affecting its CADRA software, primarily linked to zlib and Foxit libraries. These vulnerabilities include issues like improper input validation and buffer overflows, which could allow attackers to disrupt service or exploit systems. Siemens is urging users to update to CADRA version V2511 or later to mitigate these risks. For systems that cannot be immediately updated, the company recommends specific countermeasures to reduce exposure until fixes are available. This situation is particularly critical for sectors such as chemical and energy, where security vulnerabilities can have serious implications.

Read Original

Rockwell Automation has disclosed a significant vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60, which could allow attackers to impersonate authorized users. This flaw arises from weak authentication practices, specifically the inability of the application to properly validate JSON Web Tokens (JWT). As a result, low-privilege users could exploit this vulnerability to gain unauthorized access to critical system configurations and permissions. Organizations using FTSP are urged to apply a specific patch (RAID 1158263) or the February 2026 Patch Roll-up to mitigate this risk. As of now, there have been no reports of active exploitation in the wild, but users are advised to follow best security practices to protect their systems.

+1 more
Read Original

A critical vulnerability in the ServiceNow AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This pre-authentication code injection flaw allows unauthenticated users to escape the platform's script sandbox and execute arbitrary code on targeted instances. Researchers from Searchlight Cyber discovered this vulnerability and reported it to ServiceNow in early April 2026. The exploitation of this vulnerability poses significant risks to organizations using the ServiceNow AI Platform, as it could lead to unauthorized access and control over sensitive workflows and data. Companies are urged to take immediate action to safeguard their systems against potential attacks.

Read Original

SonicWall discovered that two zero-day vulnerabilities, identified as CVE-2026-15409 and CVE-2026-15410, were exploited by a threat actor known as UTA0533. These vulnerabilities were actively used to deliver custom malware over several weeks before a patch was released. Organizations using affected SonicWall products need to be particularly vigilant, as the malware has already been deployed in the wild. This situation emphasizes the importance of timely patch management and monitoring for unusual activity, given that attackers can exploit such vulnerabilities to gain unauthorized access to systems. Companies should prioritize updating their security infrastructure to mitigate the risk posed by these exploits.

Read Original

A researcher has utilized OpenAI's latest model to create an exploit chain for a serious vulnerability found in WordPress. This development raises concerns for millions of users and organizations that rely on WordPress for their websites. If exploited, this vulnerability could allow attackers to compromise sites, leading to unauthorized access or data breaches. The incident emphasizes the need for website administrators to stay informed about potential vulnerabilities and to apply security updates promptly. As the situation evolves, users should be vigilant about their site security and consider implementing additional protective measures.

Read Original

This week saw multiple security incidents that exploited vulnerabilities in various systems. Notably, a remote code execution vulnerability in WordPress was identified, allowing attackers to run malicious code on affected sites. Additionally, SonicWall reported zero-day vulnerabilities that could lead to unauthorized access. AI services are also being targeted, with attackers using fake prompts to trick users. These incidents highlight the need for organizations to patch outdated systems and be vigilant against social engineering tactics. The situation is concerning as some of these vulnerabilities were already being exploited before they were disclosed, leaving many systems at risk.

Read Original

OpenSSL has addressed a vulnerability known as 'HollowByte' that could allow attackers to launch denial-of-service (DoS) attacks. By sending specially crafted payloads, attackers could exploit the way memory is allocated by the software, potentially leading to server memory exhaustion. This issue affects any systems that utilize OpenSSL for secure communications, which includes a wide range of web servers and applications. The risk is significant because it could lead to service outages for affected systems. Users and administrators are advised to update their OpenSSL versions to mitigate this vulnerability and ensure continued security.

Read Original

A serious vulnerability (CVE-2026-6875) in the ServiceNow AI Platform is currently being exploited by attackers, according to threat intelligence firm Defused. This flaw allows unauthorized code execution, which can lead to significant security breaches for organizations using the platform. Companies that rely on ServiceNow for their IT service management need to be particularly vigilant, as the exploitation of this vulnerability could compromise sensitive data and disrupt services. The urgency of the situation is heightened by the fact that attackers are already taking advantage of this weakness, making it essential for affected organizations to act quickly to protect their systems.

Read Original

A newly discovered vulnerability in 7-Zip, identified as CVE-2026-14266, could allow attackers to execute arbitrary code on a user's machine when they open a specially crafted XZ archive. This security flaw stems from a heap-based buffer overflow that occurs during the processing of XZ chunked data. The issue was detailed by Trend Micro's Zero Day Initiative on July 15, but a fix was already released on June 25 with version 26.02 of 7-Zip. Users of 7-Zip should update to this latest version to protect themselves from potential exploitation. The vulnerability poses a serious risk, as it can run code in the context of the current process, making it a significant concern for anyone using the software.

Read Original

F5 has released important updates to address a critical vulnerability in NGINX, identified as CVE-2026-42533. This flaw allows attackers to send specially crafted HTTP requests that can cause a heap buffer overflow in the NGINX worker process. As a result, this vulnerability could lead to the crashing or restarting of the worker, effectively denying service to legitimate users. The issue affects versions of NGINX prior to 1.30.4 and 1.31.3, as well as NGINX Plus versions before 37.0.3.1. Users running these versions should upgrade immediately to protect their systems from potential exploitation.

Read Original

The latest Security Affairs newsletter reports on two significant cybersecurity issues. First, OpenSSL has addressed a vulnerability known as the HollowByte memory exhaustion bug, which could lead to service disruptions. Users of OpenSSL, particularly those running servers or applications that rely on this library, should ensure they update to the latest version to avoid potential downtime or denial-of-service attacks. Additionally, researchers have discovered Daxin, a malware that has been linked to China, still active on a manufacturer's network despite being over a decade old. This finding raises concerns about the long-term persistence of such malware and its ability to evade detection. Companies must remain vigilant and conduct thorough network security assessments to identify and eliminate such threats.

Read Original
PreviousPage 2 of 96Next