Articles tagged "CVE"

Found 571 articles

Researchers at the CERT Coordination Center have identified two serious vulnerabilities in Kaltura's HTML5 video player library. These flaws, tracked as CVE-2026-19913 and CVE-2026-19912, allow remote, unauthenticated attackers to read arbitrary files from a server and execute malicious code. Both vulnerabilities stem from unsafe deserialization within the mwEmbedLoader.php endpoint of the mwEmbed player. This poses a significant risk for any organization using Kaltura's video services, as attackers could exploit these weaknesses to gain unauthorized access to sensitive data or disrupt operations. As of now, there are no known patches or fixes available for these vulnerabilities, making it crucial for affected users to take immediate action to protect their systems.

Read Original

A serious vulnerability, designated CVE-2026-60004, has been identified in the Gitea Git platform, and attackers are now exploiting it in the wild. This code injection flaw allows malicious users to compromise self-hosted Gitea instances, potentially leading to unauthorized access and control over the affected systems. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, indicating the urgency of the situation. A report from a developer on the Russian blog Habr described an incident where their organization's Gitea instance was compromised due to this vulnerability. Organizations using Gitea should take immediate action to protect their systems, as the risk of exploitation is high.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability affecting Gitea, an open-source platform, to its Known Exploited Vulnerabilities catalog. This flaw is linked to potential exploits that could compromise the security of Gitea installations. It is vital for organizations using Gitea to address this vulnerability promptly to prevent unauthorized access or data breaches. The inclusion in CISA's catalog indicates that this issue is being actively exploited or poses a significant threat to users. Organizations should prioritize applying security updates and monitoring their systems closely to mitigate risks.

Read Original

A newly discovered vulnerability, identified as CVE-2026-75501, affects Calix routers running the EXOS/6.6.47 firmware. This flaw allows remote attackers to potentially expose home networks, raising significant security concerns for users of these devices. The issue lies in how the firmware handles certain requests, which could lead to unauthorized access to sensitive network data. Home users with these routers should be particularly vigilant, as this vulnerability could make their networks easier targets for cybercriminals. It's crucial for affected users to take immediate action to secure their devices and prevent potential breaches.

Read Original

Marimo has fixed a serious security flaw in its notebook software that could allow attackers to run unauthorized commands. This vulnerability, identified by VulnCheck's CVE Numbering Authority, enables an attacker to execute Model Context Protocol (MCP) commands when a specially crafted notebook is opened in edit mode. If exploited, this could lead to unauthorized actions on a user's system, particularly affecting individuals using the notebook software in environments where sensitive data is handled. Users are urged to update their software promptly to mitigate potential risks associated with this flaw.

Read Original
Actively Exploited

CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, specifically CVE-2026-60004, which is a code injection vulnerability in Gitea. This vulnerability is being actively exploited and poses significant risks, particularly to federal agencies. In response, CISA has emphasized the urgency for federal agencies to prioritize the remediation of this high-risk vulnerability, as it can grant attackers total control over affected systems. While the directive primarily targets Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based vulnerability management practices. The agency will continue to update the KEV Catalog with vulnerabilities that meet its criteria, and organizations are encouraged to report any known exploits not currently listed.

Read Original
Critical
Ebyte NE2-D11

All CISA Advisories

Ebyte's NE2-D11 firmware, version FW-9167-0-11, has multiple serious vulnerabilities that could allow attackers to gain unauthorized access and control over devices. Issues include inadequate authentication, cleartext transmission of sensitive information, and weaknesses in session management, which could lead to unauthorized configuration changes and data breaches. The vulnerabilities, which have a CVSS score as high as 9.8, affect critical sectors like manufacturing and energy, and their impact is global. Ebyte has acknowledged the problems and is working on a patch, but there has been little communication about its status. Users are advised to contact Ebyte for updates and to implement security measures in the meantime.

Read Original
Critical
Rently Smart Home

All CISA Advisories

Rently Smart Home has a critical vulnerability affecting versions 20.1.0 and earlier, which allows attackers to access sensitive information, including Master Pins, and override user permissions. This issue arises from insufficiently protected credentials. The vulnerability is particularly concerning for users in commercial facilities and information technology sectors across the United States and India. Rently has addressed this flaw with a patch released in late June 2026, meaning users do not need to take any additional action. However, organizations are still encouraged to improve their cybersecurity measures to mitigate risks associated with such vulnerabilities.

Read Original
Critical
PayRange API

All CISA Advisories

A serious vulnerability has been discovered in the PayRange API, affecting all versions of the product. This flaw allows both authenticated and unauthenticated attackers to access sensitive information about devices on the PayRange network. They could potentially modify device settings, leading to service disruptions or altered device displays. The vulnerability is attributed to a lack of proper authorization on management endpoints, making device details publicly accessible. PayRange has not yet collaborated with CISA to address this issue, and users are encouraged to reach out to their customer support for guidance. Given the nature of this vulnerability, it poses a significant risk to users in the commercial facilities sector across the United States and Canada.

Read Original
Critical
Zoneminder

All CISA Advisories

A serious vulnerability has been identified in Zoneminder, a popular surveillance software, affecting versions 1.37.48 and 1.38.3. This flaw allows authenticated users with permission to view events to execute arbitrary commands on the server through an OS command injection in the event export functionality. While no active exploitation has been reported, the potential for remote code execution poses significant risks to users. Zoneminder recommends that users upgrade to version 1.38.3 or later to mitigate this issue. Organizations utilizing this software should act promptly to protect their systems from possible attacks.

Read Original
Critical
Siemens SIMATIC IoT2050 Advanced

All CISA Advisories

Siemens has identified a serious vulnerability in its SIMATIC IoT2050 Advanced devices that run Industrial OS with Node-RED installed. The flaw arises from a lack of authentication on the Node-RED HTTP interface, which could allow remote attackers to access and manipulate system commands on the server without any authentication. This means they could create harmful flows and execute arbitrary code with full system privileges. Siemens has urged users to update their devices to version 4.3.4.1 or later to mitigate this risk. The affected devices are used across various critical infrastructure sectors, including chemical, manufacturing, energy, and transportation, highlighting the need for immediate action to protect against potential exploitation.

Read Original
Critical
FURUNO FA-50 Class B AIS Transponder

All CISA Advisories

FURUNO Electric has issued a warning regarding vulnerabilities in its FA-50 Class B AIS Transponder, affecting all versions of the device. These vulnerabilities could allow an attacker with knowledge of hard-coded credentials to alter critical device settings. Notably, the product has not received updates since production ended in October 2020, leaving users at risk. FURUNO advises against connecting the device directly to the internet and recommends securing the vessel to prevent unauthorized access. The vulnerabilities have been documented as CVE-2026-59769 and CVE-2026-67578, with a CVSS score of up to 9.1, indicating a critical level of severity. Users of this device need to take immediate action to mitigate potential exploitation.

Read Original
Critical
Bendix EC80 Brake ECU

All CISA Advisories

Bendix has identified critical vulnerabilities in its EC80 Brake ECU, which could allow attackers to disrupt essential vehicle functions like ABS, steering assist, and traction control. The affected versions include multiple models such as EC80ESP+ and EC80ESP PLC across various configurations. These vulnerabilities stem from issues like stack-based buffer overflows, out-of-bounds writes, and the use of hard-coded credentials. Users of the affected products are urged to update their firmware to the latest versions to mitigate these risks. This situation is particularly concerning as it affects vehicle safety systems, making prompt action crucial for those using the impacted equipment.

Read Original
Actively Exploited

At least 274 Zimbra servers have been compromised by attackers exploiting a vulnerability identified as CVE-2026-73570. This particular flaw is a code injection issue in the Zimbra Collaboration Suite (ZCS), which is widely used by organizations that prefer to manage their own data instead of relying on more expensive services like Microsoft 365 or Google Workspace. The vulnerability was patched by Synacor in version 10.1.20 of ZCS, released on July 20, 2026. However, many instances remain unpatched, leaving them vulnerable to exploitation. This incident highlights the risks associated with not keeping software updated, especially for platforms that handle sensitive communication and collaboration.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in Oracle's HTTP Server and Weblogic Server Proxy Plug-in to its Known Exploited Vulnerabilities catalog. This flaw, identified as CVE-2026-21962, carries a maximum severity score of 10.0, indicating it is a critical risk for users. The vulnerability allows unauthenticated attackers to exploit the affected systems, which could potentially lead to unauthorized access and control. Organizations using these Oracle products should take immediate action to assess their systems and implement necessary security measures to mitigate this risk. The inclusion in CISA's catalog suggests that this vulnerability is being actively targeted by malicious actors, making swift remediation essential.

Read Original
PreviousPage 2 of 39Next