Articles tagged "CVE"

Found 602 articles

Actively Exploited

Attackers are now exploiting a significant vulnerability in Citrix NetScaler, identified as CVE-2026-19490, which allows for authentication bypass. This flaw poses a severe risk as it could enable unauthorized access to systems using affected versions of NetScaler. Companies that utilize Citrix NetScaler for application delivery or networking are particularly at risk, as this vulnerability can compromise their security posture. Security researchers from Previdian have reported that the flaw is actively being exploited in the wild, indicating an urgent need for users to assess their systems. Organizations should prioritize applying any available patches or implementing mitigation strategies to protect against potential breaches.

Read Original

PostgreSQL has issued updates to fix a serious security vulnerability, tracked as CVE-2026-6471, that has existed for 12 years. This flaw allows users with the REPLICATION attribute to execute arbitrary code as the operating system user running the database server. The vulnerability affects several versions of PostgreSQL, specifically those released before 18.6, 17.11, 16.15, 15.19, and 14.24. The potential for attackers to exploit this flaw poses a significant risk to database security, making it crucial for users to apply the updates promptly. The vulnerability was introduced with the logical decoding feature in PostgreSQL 9.4, highlighting the importance of regularly updating database systems to protect against long-standing vulnerabilities.

Read Original

Researchers from Wordfence have discovered that hackers are taking advantage of two serious vulnerabilities in popular WordPress plugins: Super Forms and Elementor Pro. The first vulnerability, identified as CVE-2026-14894, has a CVSS score of 9.8 and allows unauthenticated attackers to upload files of any type due to a lack of file type validation in the Super Forms plugin. This flaw has led to over 440,000 exploit attempts. The Elementor Pro plugin is also affected, although specific details about its vulnerabilities were not provided. This situation is alarming for website owners using these plugins, as successful exploitation can lead to unauthorized access and potential data breaches. Website administrators should take immediate action to secure their sites against these threats.

Read Original

Plex is urging users to update their software due to multiple undisclosed security flaws that have been patched in recent updates. Users are advised to upgrade to Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0. While Plex has not provided specific details about the vulnerabilities, they have requested CVE identifiers, indicating that they take the issues seriously. This call to action is important for all Plex server owners and desktop users to ensure their systems remain secure. Failing to update could leave users vulnerable to potential attacks that exploit these unpatched flaws.

Read Original

Google has rolled out a security update to address 12 vulnerabilities in Chrome, including a high-severity flaw tracked as CVE-2026-85046. This vulnerability, identified as a type confusion bug in V8, the JavaScript and WebAssembly engine used by Chrome, has been actively exploited in the wild. Users of Chrome versions prior to 152.0.7977.82 are particularly at risk, as this flaw could allow attackers to execute malicious code remotely. This situation underscores the urgent need for users to update their browsers to the latest version to protect against potential attacks. Keeping software up to date is crucial in safeguarding against emerging threats.

Read Original

Cisco has issued critical patches for a vulnerability in its Nexus 9000 series switches, specifically those based on Silicon One architecture. This flaw, identified as CVE-2026-20212, carries a CVSS score of 9.8, indicating a severe risk. It allows remote attackers, without needing to authenticate, to execute code with root privileges on impacted systems. Alongside this vulnerability, Cisco also released a hardening update for IOS XR that includes seven additional CVEs, two of which are also rated very high at 9.8. Users of these Nexus switches should prioritize applying the patches as there are currently no workarounds available for the IOS XR versions affected.

Read Original

A serious vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress has been discovered and is currently being exploited by attackers. This flaw allows them to deliver a webshell payload, enabling them to execute arbitrary commands on compromised servers. Websites using Elementor Pro are particularly at risk, as the vulnerability can lead to full site takeover. The situation is urgent, as the vulnerability is actively exploited, highlighting the need for immediate action from site administrators to protect their data and resources. Users of this plugin should ensure they have updated to the latest version to mitigate the risk of exploitation.

Read Original
Critical
Rockwell Automation 1756-ENBT Module

All CISA Advisories

A vulnerability in the Rockwell Automation 1756-ENBT module, identified as CVE-2025-10478, could allow attackers to crash the device by sending a specially crafted CIP packet. This denial-of-service issue affects all versions of the 1756-ENBT module, which is used for communication between Logix 5000 controllers and Ethernet devices. Once compromised, the module requires a restart to return to normal operation. This vulnerability poses risks to critical infrastructure sectors, including manufacturing, agriculture, and transportation. Rockwell Automation advises users to upgrade to the 1756-EN2T or 1756-EN4TR modules to mitigate this risk, while those unable to upgrade should follow security best practices.

Read Original
Critical
Inductive Automation Ignition

All CISA Advisories

Inductive Automation's Ignition platform has a serious vulnerability that allows any authenticated user to create projects, due to a misconfigured setting in versions 8.1.53 and earlier. This is classified as CVE-2026-77393 and has a CVSS score of 8.8, indicating a high-level risk. The issue stems from the 'Create Project Role(s)' setting being left blank, which means no role restrictions were enforced. Users are encouraged to upgrade to version 8.1.54 or later, where project creation is limited to Designer sessions, or to configure their current version to restrict project creation appropriately. This vulnerability poses risks in critical sectors such as manufacturing and energy, making it crucial for organizations using this software to address the issue promptly to prevent unauthorized project creation.

Read Original

A vulnerability in the OPC Foundation's OPC UA LocalDiscoveryServer (LDS) could allow attackers to gain control of high-privilege terminal sessions during installation. This affects versions of the software prior to 1.04.420 and has been assigned CVE-2026-77477. To exploit this vulnerability, an attacker needs elevated privileges and access to the system during installation, potentially allowing them to execute arbitrary commands. This issue is particularly concerning for sectors like energy, chemical, and critical manufacturing, where the software is widely used. Users are advised to upgrade to version 1.04.420 or later to mitigate the risk.

Read Original
Critical
Tycon Systems TPDIN-Monitor-WEB3

All CISA Advisories

Tycon Systems has identified several vulnerabilities in its TPDIN-Monitor-WEB3 device, affecting versions 2.2.9 and earlier. These vulnerabilities could allow attackers to conduct man-in-the-middle attacks, perform factory resets, or access sensitive information due to hard-coded credentials, cross-site request forgery (CSRF), and missing authorization. The CVEs associated with these issues are CVE-2026-77847, CVE-2026-82712, and CVE-2026-82684, with severity ratings ranging from medium to high. Tycon Systems has released a firmware update, version 2.4.2, which addresses these vulnerabilities. Users still operating on the older version are urged to upgrade promptly to enhance their security posture and protect against potential exploits.

Read Original

Schneider Electric has identified a serious vulnerability affecting several of its products, which could allow hackers to hijack user sessions. This flaw, cataloged as CVE-2026-4827, impacts a range of devices including the Easergy MiCOM series, EcoStruxure Power Automation products, and various PowerLogic and Saitel devices. If exploited, attackers could gain unauthorized access, potentially leading to disruptions in critical infrastructure sectors such as energy and water management. Users of the affected versions are urged to apply the necessary updates to mitigate this risk. The vulnerability is significant given the critical nature of the systems involved, necessitating prompt action from users worldwide to secure their operations.

Read Original
Critical
Rockwell Automation ControlFLASH

All CISA Advisories

A vulnerability has been identified in Rockwell Automation's ControlFLASH software, which could allow attackers to execute arbitrary code with the permissions of the logged-in user. This issue affects versions of ControlFLASH up to and including 15.07, and it stems from the software granting write permissions to the 'Everyone' group on its installation directory. Users are urged to update to version 15.08, which addresses the vulnerability. For those unable to upgrade, Rockwell Automation provides a workaround to remove the 'Everyone' group from the permissions. This vulnerability is particularly concerning as it impacts critical infrastructure sectors such as manufacturing, energy, and water management, making it essential for organizations to take prompt action to mitigate potential risks. No public exploitation of this vulnerability has been reported yet, but the nature of the issue poses significant security risks.

Read Original
Critical
Rockwell Automation ArmorStart LT

All CISA Advisories

Rockwell Automation has identified serious vulnerabilities in its ArmorStart LT product, specifically versions up to v2.001. These vulnerabilities could allow attackers to execute malicious scripts through cross-site scripting (XSS) attacks or cause a denial of service by sending crafted HTTP requests, leading to web server outages. Users are strongly advised to update to firmware version v2.002 to mitigate these risks. The vulnerabilities affect critical manufacturing systems worldwide, raising concerns about the security of industrial control systems. Organizations should act swiftly to ensure their systems are protected, following best practices for cybersecurity.

Read Original
Critical
IXON VPN Client

All CISA Advisories

A vulnerability in the IXON VPN Client, specifically versions earlier than 1.4.7, has been discovered that allows attackers to execute remote code with elevated privileges. This issue arises from improper handling of CRLF sequences, which can lead to command injection. The affected software is widely used across various critical sectors, including energy and information technology, and its exploitation could have severe implications for security. Users are urged to upgrade to version 1.4.7 or later to mitigate risks, as IXON has begun rejecting connections from older versions. Until the update is applied, users should consider uninstalling the VPN client if it is no longer needed.

Read Original
Page 1 of 41Next