A serious vulnerability identified as CVE-2026-19478 has been discovered in GitLab, allowing attackers to exploit it without needing authentication. This flaw enables unauthorized users to modify or delete public projects and user data, posing a significant risk to organizations that rely on GitLab for their development processes. Shortly after its disclosure, reports indicated that the vulnerability was actively being exploited, heightening concerns for users. Companies using GitLab should take immediate action to safeguard their data and projects. The situation emphasizes the need for prompt updates and vigilance regarding security practices.
Articles tagged "CVE"
Found 571 articles
The Hacker News
Researchers have identified a serious vulnerability in the Elementor Pro plugin for WordPress, designated as CVE-2026-32475. This flaw, which has a CVSS score of 9.0, allows unauthenticated attackers to upload malicious PHP files and execute code on affected sites. The issue is found within the Forms module's file upload functionality, posing a significant risk to WordPress installations using this plugin. If exploited, this could lead to unauthorized access and control over websites, making it crucial for users and site administrators to address the issue promptly. As the vulnerability is particularly dangerous, it is essential for those using Elementor Pro to take immediate action to secure their sites.
On August 18, 2026, Apple addressed a significant security vulnerability in its image handling framework that could allow malicious images to execute harmful code on both desktop and mobile devices. This vulnerability is identified as CVE-2026-65346 and poses a risk to users who may unknowingly open compromised image files. The issue could potentially lead to unauthorized access or control over affected devices, making it crucial for users to update their systems promptly. Apple has released patches to fix this vulnerability, emphasizing the importance of keeping software up to date to protect against such threats. Users of both macOS and iOS devices should ensure they are running the latest versions to mitigate this risk.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, identified as CVE-2026-64849, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects the MLflow platform and allows for server-side request forgery (SSRF), which attackers can exploit to gain unauthorized access to sensitive systems. The addition to the catalog indicates that there is active exploitation of this vulnerability, posing significant risks, particularly to federal agencies. As part of its guidelines, CISA emphasizes the need for rapid remediation of such high-risk vulnerabilities. While the directive primarily targets federal agencies, CISA encourages all organizations to prioritize addressing vulnerabilities listed in the KEV Catalog to safeguard their systems effectively.
The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified four critical vulnerabilities that are currently being exploited in the wild, adding them to its Known Exploited Vulnerabilities (KEV) catalog. Among these is CVE-2026-65400, a serious authentication flaw in Apple macOS that could allow unauthorized access. Other vulnerabilities affect Microsoft SharePoint, VMware vCenter, and Microsoft IKE, all of which pose significant risks to organizations using these platforms. With a CVSS score of 9.8 for CVE-2026-65400, it’s crucial for users and companies to act quickly to mitigate these risks. The exploitation of these vulnerabilities could lead to severe data breaches or unauthorized access, making it essential for affected parties to stay informed and apply necessary updates and patches.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, specifically targeting flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE. One notable vulnerability, CVE-2026-33824, relates to the Windows Internet Key Exchange (IKE) Service Extensions and poses a risk of remote code execution. These vulnerabilities could allow attackers to exploit systems running the affected software, potentially leading to unauthorized access or data breaches. It's crucial for users and organizations utilizing these platforms to take immediate action to mitigate the risks associated with these vulnerabilities. Keeping software updated and applying any available patches is essential to protect against potential exploitation.
Siemens Simcenter Nastran has been found to contain a stack overflow vulnerability that could allow attackers to execute arbitrary code by tricking users into running a malicious string as a file argument. This vulnerability affects specific versions of Simcenter Femap and Simcenter Nastran, specifically those earlier than version 2606. Siemens has responded by releasing updated versions to patch the vulnerability and is urging users to upgrade to these latest versions to safeguard their systems. Given that this issue impacts sectors such as critical manufacturing, defense, and healthcare, it is crucial for organizations to act promptly to mitigate potential risks associated with this vulnerability.
CISA Malcolm, a network traffic analysis tool, has several vulnerabilities that could allow attackers to execute arbitrary code or cause denial-of-service conditions. Versions prior to 26.07.0 are particularly affected by issues related to file extraction and role-based access control, allowing unauthorized access to sensitive areas and the potential execution of malicious code. Specifically, CVEs 2026-55676, 2026-63133, 2026-63134, 2026-63177, and 2026-19670 highlight problems with file upload handling and directory traversal protections. Users of Malcolm are urged to update to the latest versions—26.07.0 or 26.06.1—to mitigate these risks. These vulnerabilities are significant as they could compromise the integrity and availability of systems utilizing CISA Malcolm worldwide.
The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that they are actively being targeted by cybercriminals. The vulnerabilities include a double free flaw in Microsoft Internet Key Exchange (CVE-2026-33824), a weak authentication issue in Microsoft SharePoint (CVE-2026-55040), a path traversal vulnerability in Broadcom's VMware vCenter (CVE-2026-59310), and an improper authentication vulnerability in Apple macOS (CVE-2026-65400). These vulnerabilities pose significant risks, especially for federal agencies, which are required to prioritize their remediation under Binding Operational Directive 26-04. Although this directive specifically targets federal agencies, CISA encourages all organizations to adopt similar practices to enhance their security posture against these threats.
Help Net Security
GitLab has identified a critical vulnerability that could allow attackers to modify or delete public projects without needing to authenticate. This flaw, cataloged as CVE-2026-19478, affects several versions of both GitLab Community Edition and Enterprise Edition, specifically those released from version 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, and 19.2 to 19.2.3. Users running these versions are strongly urged to upgrade to the latest patched versions: 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The ability to alter or delete projects poses a significant risk, particularly for organizations relying on GitLab for public-facing repositories, as it could lead to data loss or compromise project integrity.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Ray, a data framework, to its Known Exploited Vulnerabilities catalog. This vulnerability, tracked as CVE-2025-62593, has a high severity score of 9.4 and allows for remote code execution, meaning attackers could potentially take control of affected systems without physical access. Organizations using Ray need to be aware of this vulnerability as it poses significant risks to their data and infrastructure. CISA's inclusion of this flaw in their catalog indicates that it is being actively exploited in the wild, prompting an urgent need for users to address the issue. The agency's action serves as a reminder for companies to regularly update their systems and monitor for vulnerabilities to protect against potential attacks.
The Hacker News
GitLab has issued urgent security updates to fix a serious vulnerability in both its Community Edition (CE) and Enterprise Edition (EE) software. This vulnerability, identified as CVE-2026-19478, has a high severity rating of 9.4 on the CVSS scale. Under certain conditions, it could enable unauthenticated attackers to remotely modify or even delete public projects and user data. This flaw poses a significant risk to users and organizations that rely on GitLab for project management and collaboration, as it could lead to data loss and project disruption. Users are advised to apply the latest security updates promptly to safeguard their projects and data.
The Hacker News
A serious vulnerability has been found in Forminator Forms, a popular WordPress plugin with over 600,000 installations. This flaw, identified as CVE-2026-15748 and rated 9.8 out of 10 on the CVSS scale, allows attackers to execute arbitrary code on affected websites without authentication. Discovered by a security researcher, this issue poses a significant risk as it could enable malicious users to upload harmful PHP files, compromising the security of the sites. Website owners using this plugin should be particularly vigilant, as the potential for exploitation is high. Immediate action is necessary to protect their systems and data.
A recently discovered vulnerability, identified as CVE-2026-54121, poses a serious risk to organizations using Enterprise Certificate Authorities (CAs). This flaw allows a standard domain user to escalate their privileges, effectively turning the Enterprise CA into a Domain Controller. This situation can lead to unauthorized access and control over sensitive resources within the network. Organizations need to treat their Public Key Infrastructure (PKI) as a critical part of their security framework, as it plays a vital role in identity management. The importance of addressing this vulnerability cannot be overstated, as it highlights the need for stringent security measures around privileged accounts and trust relationships within IT environments. Patching is essential to mitigate this risk.
Hackers are exploiting a recently patched vulnerability in macOS, known as CVE-2026-65400, which allows unauthorized access to the macOS Screen Sharing feature. This flaw enables attackers to bypass authentication and gain root access to affected systems, leading to the installation of cryptominers without user consent. The Netherlands’ National Cyber Security Centre has issued a warning about this active exploitation, emphasizing the need for users to update their systems. Apple has released patches for macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1) to address this issue, urging all macOS users to upgrade promptly to protect their devices. Failure to do so could leave systems vulnerable to further attacks and unauthorized resource usage.