CISA has added a new vulnerability, CVE-2025-62593, related to code injection in the Ray-Project, to its Known Exploited Vulnerabilities Catalog. This vulnerability is currently being exploited, posing a significant risk to federal agencies and potentially impacting organizations that utilize the Ray framework. Under the Binding Operational Directive 26-04, federal agencies are required to prioritize fixing high-risk vulnerabilities, like this one, especially on systems that could give attackers complete control post-exploitation. CISA encourages all organizations, not just federal ones, to adopt similar risk-based vulnerability management practices to enhance their security posture. If anyone is aware of other exploited vulnerabilities not listed in the catalog, they can submit them for consideration through CISA's nomination form.
Articles tagged "CVE"
Found 571 articles
Microsoft is currently developing a security patch for a zero-day vulnerability known as 'ShieldBreak,' which was disclosed last week by researcher Nightmare Eclipse. This vulnerability is tracked as CVE-2026-69414 and poses a significant risk, as it can potentially allow attackers to exploit Microsoft Defender, an essential security tool for many users and organizations. The information about this vulnerability is particularly concerning because it could be leveraged by cybercriminals to bypass security measures, compromising systems and data. Microsoft is urging users to stay vigilant while they work on a fix to mitigate the threat. As the situation develops, it’s crucial for users of Microsoft Defender to monitor for updates and implement any recommended patches as soon as they are available.
A serious vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, has been actively exploited just three days after its disclosure. This flaw allows attackers to execute arbitrary code, which can compromise internal components of the affected systems. Organizations using SAP Commerce Cloud should be particularly vigilant, as the rapid exploitation indicates a high level of risk. The urgency for companies to patch their systems is critical to prevent unauthorized access and potential data breaches. Users and administrators need to prioritize updates to safeguard their environments against this vulnerability.
The Hacker News
Cybersecurity researchers have identified a new security threat linked to a suspected China-nexus advanced persistent threat group. The group is exploiting a serious vulnerability in Broadcom's VMware vCenter, known as CVE-2026-59310, which has a CVSS score of 9.8, indicating its severity. This directory-traversal flaw allows attackers to execute arbitrary code on affected systems. Recent reports show that the attackers are deploying Babuk-derived ransomware during these exploits, raising concerns for organizations using VMware vCenter. Companies that rely on this software need to act quickly to secure their environments and protect sensitive data from potential ransomware attacks.
Security Affairs
A recent cybersecurity concern involves attackers purchasing expired domain names and using them to distribute malware. This tactic allows them to exploit the trust users have in familiar web addresses, potentially leading to security breaches and data theft. Companies and individuals who own domains should monitor their registrations closely to avoid falling victim to this scheme. Additionally, organizations need to educate users about the risks associated with clicking on links from unknown or expired domains. The implications of this practice are significant as it not only affects the victims directly but also undermines overall internet security trust. Staying vigilant and proactive in domain management is essential to mitigate these risks.
A serious vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is currently being exploited by attackers. This flaw, which has a maximum severity score of 10.0, arises from insufficient authorization checks and poor input validation. Just days after SAP issued a patch, reports of active exploitation began to surface. This puts organizations using SAP Commerce Cloud at risk, as attackers could potentially gain unauthorized access to sensitive information or systems. Companies should prioritize applying the latest updates from SAP to protect their environments from these attacks.
The Hacker News
A serious security vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is currently being exploited by attackers. This vulnerability has a maximum severity rating of 10.0 on the CVSS scale and stems from inadequate authorization checks and input validation. As a result, unauthorized users can take advantage of a default authentication client to execute malicious actions. The risk here is significant, as it could lead to unauthorized access to sensitive data or system controls within affected environments. Companies using SAP Commerce Cloud should take immediate action to secure their systems against this vulnerability.
A newly discovered vulnerability in macOS, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and is being actively exploited for unauthorized cryptocurrency mining. This flaw affects the screen sharing feature of macOS, allowing attackers to hijack resources from targeted machines without user consent. Users of macOS devices should be particularly vigilant, as this vulnerability poses a risk to system performance and could lead to increased electricity costs due to the mining activities. It's crucial for users to stay updated on any patches or updates released by Apple to mitigate this issue and protect their devices from exploitation.
SCM feed for Latest
The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.
A newly found zero-day vulnerability in GeoServer is currently being exploited by attackers, as reported by watchTowr. This SQL injection flaw allows for remote code execution (RCE) and has not yet been patched. Researchers first disclosed the issue on August 12, 2026. Users of the open-source GeoServer platform are at risk, as the vulnerability could allow attackers to execute malicious code on affected systems. It’s crucial for organizations using GeoServer to remain vigilant and seek immediate remediation steps, as no updates or patches have been released to address this critical issue.
Security Affairs
Shortly after its public disclosure, hackers began exploiting a serious vulnerability in Adobe Commerce known as CVE-2026-71362, which has a CVSS score of 9.1. This flaw allows attackers to hijack customer accounts without needing authentication, potentially exposing sensitive user data. Businesses using Adobe Commerce should be particularly vigilant, as this vulnerability could lead to unauthorized access to customer information and significant privacy breaches. The urgency of the situation is heightened by the rapid targeting of the flaw by cybercriminals, making it critical for affected organizations to act quickly to safeguard their systems and user data.
Help Net Security
A significant vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, is being actively exploited by attackers. This flaw, which allows for the bypassing of authentication and the impersonation of users, can lead to unauthorized access to files and the ability to alter data. Microsoft issued a patch for this vulnerability during its July 2026 Patch Tuesday updates, but the release of proof-of-concept exploit code by Rapid7 has prompted immediate exploitation in the wild. Organizations using SharePoint should prioritize applying the provided security updates to protect against potential data breaches and unauthorized modifications. The situation highlights the ongoing risks associated with unpatched vulnerabilities, especially when exploit tools become publicly available.
Siemens has identified a serious vulnerability in its Parasolid software, specifically an out-of-bounds read issue affecting versions 38.0 and 38.1. This vulnerability arises when the application processes specially crafted X_T files, which could allow attackers to crash the software or run arbitrary code. Siemens has responded by releasing updated versions, urging users to upgrade to Parasolid V38.0.235 or later for version 38.0 and V38.1.230 or later for version 38.1. This is particularly important for organizations in the critical manufacturing sector, as the flaw can potentially impact operational stability. Siemens also recommends enhancing network security measures to protect devices from unauthorized access.
Siemens License Server (SLS) has been found to contain multiple vulnerabilities that could allow attackers to gain elevated privileges and access arbitrary files on affected systems. Specifically, versions prior to 5.1 and 5.3 are vulnerable to local privilege escalation and path traversal, respectively. The first vulnerability, CVE-2026-69108, stems from an insecure sudoers policy, while CVE-2026-69109 results from inadequate input sanitization. Siemens recommends that users update to version 5.1 or later for the privilege escalation issue and to version 5.3 or later for the path traversal vulnerability. This is crucial as the vulnerabilities could lead to significant security breaches, including complete system compromise.
Siemens has identified a vulnerability affecting its Desigo DXR and PXC controllers that could enable attackers to initiate denial of service (DoS) conditions by sending malformed BACnet packets. This issue can cause the devices to stop responding to BACnet queries, requiring a reset or reboot for recovery. The affected versions include Desigo DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7, all of which are used across various sectors such as healthcare, energy, and transportation. Siemens has released updated versions to address this vulnerability and strongly urges users to apply these updates to maintain device functionality and security.