Vulnerabilities

Magento Zero-Day 'StyleSmuggler' Lets Attackers Backdoor Online Stores
Sansec says exploitation of the unpatched Adobe Commerce flaw began September 4, with no vendor fix yet available.

Broadcom Patches Critical VMware Workstation Flaw That Lets Admins Escape to the Host
An integer-overflow bug rated 9.3 out of 10 lets a privileged user inside a virtual machine run code on the underlying computer.

Hackers Exploit PaperCut Bugs to Steal Logins From Schools and Universities
Researchers say attackers are chaining two fresh flaws in the popular print management software to break into education networks across the US and Europe.

Hackers Fire 440,000 Attacks at Two Popular WordPress Plugins
Flaws in Super Forms and Elementor Pro let attackers upload files and run code on unpatched sites, with mass exploitation already underway.

Google rushes out Chrome fix after hackers exploit V8 flaw in the wild
A type confusion bug in Chrome's JavaScript engine is already being used in real attacks. Update your browser now.

HPE patches critical flaw in Aruba network switches that lets attackers take over without a password
A buffer overflow in ArubaOS-CX, tracked as CVE-2026-73749, lets unauthenticated attackers run code on switches used by hospitals, universities and data centres.

Cisco patches critical Nexus 9000 bug that lets attackers run code as root
A flaw tracked as CVE-2026-20212 scores 9.8 out of 10. Cisco also shipped a bundled fix for seven separate IOS XR bugs, two of them equally severe, with no workaround available.

Schneider Electric patches weak-randomness flaw across dozens of grid control products
A session-management bug rated 8.3 affects protection relays, gateways and SCADA software used in power, water and chemical plants worldwide.

OPC Foundation patches installer flaw that let a bystander hijack setup on industrial servers
A medium-severity bug in the OPC UA Local Discovery Server installer briefly exposes a high-privilege console anyone at the keyboard could grab.

Microsoft confirms mouse bug in Windows 11 preview update only hits non-English PCs
The KB5120998 optional update quietly resets cursor settings, and Microsoft now says the fault lies in code paths used outside English locales.

Attackers Race to Exploit Elementor Pro Flaw, 190,000 Attempts Logged in Four Days
A file-upload bug in the popular WordPress plugin lets criminals plant a PHP backdoor and run commands on the server. Patch shipped August 19; attacks began the same day.

A Ten-Year-Old PostgreSQL Flaw Let a Backup Account Become a Backdoor
A security gap in widely used database software, hidden since 2014, could let a low-level account take over an entire server. Patches are out. Here is what you need to know.

Plex tells users to update now as it patches unspecified security flaws
The media server company emailed customers directly, a rare step, and is holding back details until CVE numbers are assigned.

Microsoft Teams and new Outlook crash on ARM Windows laptops after August updates
Surface Pro 11 and Surface Laptop 7 owners running Windows 11 24H2 hit launch failures after installing the August 2026 security updates.

Researcher publishes FalconFlank zero-day targeting CrowdStrike Falcon Sensor
A privilege escalation flaw abuses Falcon's own Office macro cleanup routine to hand attackers SYSTEM-level access on Windows machines.