Attackers are exploiting two serious vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing unauthorized users to log in as any WordPress user, including those with administrative privileges. These vulnerabilities, identified as CVE-2026-61979, have a CVSS score of 8.1, indicating a high severity level. This situation puts numerous WordPress sites at risk, as it could enable attackers to gain complete control over these sites without needing valid credentials. The vulnerabilities were disclosed by Patchstack, underscoring the need for site administrators to take immediate action. Promptly addressing these flaws is crucial to prevent unauthorized access and potential data breaches.
Articles tagged "CVE"
Found 571 articles
Researchers have identified two vulnerabilities in WordPress plugins, tracked as CVE-2026-61979 and CVE-2026-15981, that can be exploited together to bypass authentication and potentially take over admin accounts. This poses a significant risk to users of affected plugins, as attackers could gain unauthorized access to sensitive areas of WordPress sites. The vulnerabilities are particularly concerning for website administrators who may not be aware of these security flaws. It's crucial for users to check if their plugins are affected and take appropriate action to secure their sites, especially since the potential for exploitation exists. Prompt updates and vigilance are key to maintaining site security in light of these findings.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent three-day deadline for agencies to address a serious vulnerability in Zimbra, identified as CVE-2026-73570. This flaw enables attackers to take complete control over a user's communications, posing a significant risk to organizations using this software. The vulnerability could lead to unauthorized access to sensitive information and disrupt business operations. As Zimbra is widely used for email and collaboration, the implications of this vulnerability are considerable, affecting both public and private sector entities. Agencies are urged to act quickly to implement the necessary patches to mitigate this risk.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, specifically CVE-2026-21962, which affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. This vulnerability involves improper access control and has been linked to active exploitation, making it a significant risk for federal agencies and other organizations. CISA's Binding Operational Directive (BOD) 26-04 mandates that federal agencies prioritize fixing high-risk vulnerabilities like this one, especially on publicly exposed systems. While the directive is aimed at federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Companies are urged to act swiftly to mitigate this risk and report any additional vulnerabilities for consideration in the KEV Catalog.
Red Hat and the Keycloak project have issued important patches to fix a severe security vulnerability in Keycloak, an open-source identity and access management server. This flaw, identified as CVE-2026-18963, allows unauthenticated attackers to reset passwords and potentially take over any user account without needing prior access. Rated 9.1 on the CVSS scale, this vulnerability poses a significant risk to organizations using Keycloak for managing user identities and access. Users and administrators are strongly advised to apply the patches immediately to protect their systems and prevent unauthorized account access.
Help Net Security
Microsoft has identified and patched a severe vulnerability in Entra ID, its cloud identity service, which was previously known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, has a maximum severity score of 10.0 and allows unauthenticated attackers to execute code remotely. This vulnerability, discovered by a Microsoft security engineer, poses a significant risk as it affects systems that manage logins and access to Microsoft 365, Azure, and various third-party applications. Due to its exploitation in the wild, companies using Entra ID need to act quickly to protect their systems. Users should ensure their services are updated with the latest security patches to mitigate potential risks.
Security Affairs
CERT Polska has reported that a critical vulnerability in the Zimbra Collaboration Suite, known as CVE-2026-73570, is being actively exploited by attackers. This flaw allows for unauthenticated remote code execution, posing significant risks to users of the software. The vulnerability was patched on July 20, but the fact that it is now being exploited in the wild raises concerns for organizations that may not have yet applied the update. Affected users are urged to implement the patch immediately to protect their systems from potential breaches. The urgency of this situation highlights the need for timely software updates and vigilance against emerging threats.
Help Net Security
Citrix has identified and patched two vulnerabilities in its NetScaler ADC and NetScaler Gateway products, one of which is a serious authentication bypass flaw designated as CVE-2026-19490. This vulnerability could allow unauthorized access to systems, putting customer data at risk. Citrix is urging all users of the affected appliances to check if their deployments are impacted and to promptly upgrade to the recommended builds. Anil Shetty, a senior VP at Cloud Software Group, emphasized the importance of this upgrade to maintain security. Users need to act quickly to prevent potential exploitation of this flaw.
The Hacker News
A serious vulnerability in GitLab, identified as CVE-2026-19478, has been actively exploited just days after being publicly disclosed. This flaw, which has a high severity score of 9.4, allows unauthenticated attackers to inject code, enabling them to modify or delete publicly accessible GitLab projects. This means that sensitive project data could be rewritten or erased without any authentication. Organizations using GitLab need to be particularly vigilant as this vulnerability poses a significant risk to their data integrity. Immediate action is necessary to mitigate the potential damage from these attacks.
The Hacker News
Microsoft has issued a warning about a severe vulnerability in its Entra ID service, previously known as Azure Active Directory. This security flaw, identified as CVE-2026-69836 and rated 10.0 on the CVSS scale, allows for remote code execution, meaning attackers could potentially execute malicious code on affected systems without needing physical access. Although Microsoft has confirmed that this vulnerability is being exploited in the wild, they have stated that no immediate action is required from customers. This is significant as Entra ID is a critical service for identity and access management in the cloud, and any exploitation could lead to unauthorized access to sensitive data. Users and organizations relying on this service should remain vigilant and monitor for any updates from Microsoft regarding further mitigation steps.
Researchers have found a serious vulnerability in isolated-vm, an open-source sandboxing tool widely used in JavaScript applications. This flaw, identified as GHSA-864f-rcv7-6rh4, allows attackers to break out of the sandbox environment, potentially leading to remote code execution (RCE) on the host system. The issue affects all versions of the library up to and including version 7.0.0, which means many applications using this tool could be at risk. Developers and organizations relying on isolated-vm should take immediate action to secure their systems, as the vulnerability could have significant implications for data security and system integrity. As of now, the flaw has not been actively exploited in the wild, but its existence poses a considerable threat until a fix is implemented.
A serious vulnerability in Zimbra Collaboration Suite (ZCS) has been found and is currently being exploited by attackers. The flaw, identified as CVE-2026-73570, has a high severity score of 8.9 and allows for unauthenticated remote code execution through command injection. This means that attackers could potentially take control of affected systems without needing any prior authentication. The Polish Computer Emergency Response Team (CERT Polska) has warned users that this vulnerability is actively being exploited in the wild. Organizations using Zimbra are urged to apply the latest security patches immediately to mitigate the risk of attack.
A vulnerability in Johnson Controls' Simplex Incident Manager could allow local attackers to extract user credentials stored in cleartext in system memory. This issue affects versions of the software up to and including V2.01 (CVE-2026-27875). Organizations using this application, which is deployed in critical sectors like manufacturing, government, and energy, face risks of unauthorized access to their systems. Johnson Controls has released a patched version (v2.01.01) to address this issue and recommends that users restrict local access to authorized personnel, implement endpoint protection, and enforce strong access controls. While no public exploitation has been reported, the potential for abuse remains a concern for users of the affected software.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities Catalog. These are CVE-2026-72529, which involves missing authentication for critical functions in TrueConf Server, and CVE-2026-72530, a code injection vulnerability in the same software. Both vulnerabilities are currently being exploited in the wild, posing serious risks to federal agencies and potentially other organizations using the affected software. CISA's Binding Operational Directive 26-04 emphasizes the need for federal agencies to prioritize the remediation of these high-risk vulnerabilities quickly. While the directive specifically targets federal entities, CISA encourages all organizations to adopt a similar approach to managing vulnerabilities, especially those listed in the KEV Catalog.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a serious vulnerability in MLflow, identified as CVE-2026-64849, to its Known Exploited Vulnerabilities catalog. This flaw is categorized as a server-side request forgery (SSRF) with a high CVSS score of 9.3, indicating its potential severity. MLflow, which is used for machine learning lifecycle management, could allow attackers to manipulate server requests, potentially leading to unauthorized access or data exposure. Organizations utilizing MLflow should prioritize addressing this vulnerability to safeguard their systems. Given the critical nature of the flaw, it is essential for users to assess their exposure and implement necessary security measures promptly.