Vulnerabilities — Page 12

Fifteen Flaws in TP-Link's Auto-Setup System Could Hand Hackers Control of an Entire Business Network
Security firm Forescout found serious weaknesses in the technology TP-Link uses to automatically configure routers, switches, and cameras. Some flaws can be chained together to let an outsider quietly seize control of every device on a network.

cPanel patches critical database flaw that let hosting customers run SQL as root
A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

Microsoft Paid Out $20 Million in Bug Bounty Rewards This Year
More than 560 security researchers from 64 countries were paid to find and report software flaws. Not everyone is happy about how the company handled the work.

CISA flags N-able N-central bug as actively exploited, orders federal fix
The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

Thermo Fisher patches DNA analysis flaw that could let evidence files be quietly altered
A vulnerability in Applied Biosystems human identification software could allow near-invisible edits to forensic DNA files before analysts ever see them.

N-able confirms hackers seized N-central servers through a login-bypass flaw
The remote-management platform's first patch didn't hold. A second fix, in build 2026.3.1.7, closes CVE-2026-18577.

Chrome Moves to Block Malware That Hijacks Your New Tab Page
Google is testing a defence that stops malicious software from posing as an IT administrator to lock unwanted extensions into consumer Chrome installs on Windows and macOS.

A Coldcard Firmware Bug From 2021 May Have Cost Bitcoin Holders $70 Million
Researchers say a four-year-old flaw in a popular hardware wallet let one attacker sweep nearly 1,200 addresses in under an hour.

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely
A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

Researchers Find 84 Flaws in the Guts of 4G and 5G Networks
A Singapore university team says weaknesses in mobile core software could let attackers knock users offline or hijack their sessions.

Google Patches 1,442 Chrome Flaws Across Three Releases, More Than the Prior 23 Combined
Chrome 149, 150 and 151 together resolved more security bugs than nearly two years of previous updates, with Google's own researchers flagging the bulk of the issues.

Schneider Electric patches a nasty file-parsing bug in its industrial control software
A booby-trapped design file could let attackers run code inside IGSS, the SCADA tool used to monitor factories, energy sites and manufacturing plants worldwide.

NASA's Core Flight System has a flaw that can crash spacecraft software
A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

Forgotten DNS Records Could Become a Nation-State Weapon, Researchers Warn
A technique called 'dangling DNS' has lurked in security circles for years. Researchers now say AI could automate it at a scale that threatens governments, banks and supply chains.