Vulnerabilities — Page 16

Full-frame close-up of a green circuit board with a prominent black microchip in sharp focus, tiny surface-mount components blurred around it, cool blue LED glo
Vulnerabilities

Oracle's Largest Patch Update Fixes Hundreds of Vulnerabilities

Oracle releases its biggest Critical Patch Update yet, addressing severe vulnerabilities in multiple products.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit server room aisle, rows of network switches and firewall appliances with amber and green status
Vulnerabilities

Eclypsium launches InfraTrust to flag the infrastructure flaws no one is patching

A new knowledge base and monthly report from firmware security firm Eclypsium aims to tell defenders which router, firewall and server bugs to fix first.

3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages

A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

3 min read
Photoreal editorial image of a dimly lit server rack in a data centre, one blue status LED glowing, a faint reflection of scrolling log text on the glass door,
Vulnerabilities

Windmill Path Traversal Flaw Under Active Attack, VulnCheck Warns

CVE-2026-29059 lets unauthenticated attackers read files from servers running the open-source developer platform. Patch guidance and exploitation details below.

3 min read
Full-frame edge-to-edge photoreal editorial image of a laptop screen at a slight angle showing an abstract green messaging interface being overlaid by a translu
Vulnerabilities

Adobe's Acrobat Chrome extension leaked WhatsApp Web chats to any website you visited

Researchers at Guardio Labs found a chain of flaws, tracked as CVE-2026-48294, that let any web page silently read messages, contacts and chat lists from WhatsApp Web. Adobe patched the extension within two days.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data centre, with amber warning lights glowing on network switches, a soft red
Vulnerabilities

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild

CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

4 min read
Photoreal news-editorial image, full-frame edge-to-edge 16:9 composition
Vulnerabilities

Oracle Patches 1,434 Flaws in One Go. AI Probably Found Most of Them.

Oracle's July 2026 quarterly security update is the largest in the company's history, covering hundreds of products used by hospitals, banks, retailers, and governments worldwide.

3 min read
Photoreal editorial shot of a modern smartphone screen showing a generic mail app inbox with a blurred alias-style email address at the top, sitting on a matte
Vulnerabilities

Apple Patches Year-Old Hide My Email Bug That Leaked Real Addresses

A flaw in Apple's email-cloaking feature let real addresses appear in mail logs. The fix took over a year to ship.

3 min read
Full-frame close-up photograph of an industrial smart plug device mounted on a metal DIN rail inside a factory electrical cabinet, cool blue LED status light gl
Vulnerabilities

Siemens Rushes Fix for Smart Plug Riddled With Eight Serious Flaws

The SIDIS Secured SmartPlug carried a critical 9.8-rated bug plus seven more in bundled open-source libraries. Siemens says update to V7.26.0310.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server room with a single rack bathed in blue and red light, a laptop open on a nearby cart sho
Vulnerabilities

Hackers Race to Break Into WordPress Sites Through 'wp2shell' Flaws

Two critical bugs in WordPress core let attackers install backdoors without a password. Automatic updates are out, but roughly one in five sites is still exposed.

4 min read
Photoreal editorial shot of a dimly lit corporate server room, rows of rack-mounted servers glowing with amber and blue status lights, one rack door slightly aj
Vulnerabilities

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked

CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room with a single rack door open, blue and amber status lights reflecting off poli
Vulnerabilities

The Patch Race Is Now a Patch Sprint, and Defenders Are Losing

When vendors ship a security fix, attackers reverse-engineer it within hours. The window to update has shrunk from weeks to a working day.

3 min read
A close-up photorealistic view of a fractured dark blue computer chip on a black reflective surface, with hairline cracks glowing faint red from underneath, sha
Vulnerabilities

Meta Paid a Researcher $78,000 to Find a Flaw That Exposed Support Chats and Personal Data

An independent security researcher discovered a hole in Meta's internal support system that could have let anyone read private conversations between users and Meta support staff. Meta patched it quietly. Then came the cheque.

3 min read
Full-frame photoreal editorial shot of a darkened server room with a single glowing amber warning light reflected on rows of rack-mounted hardware, faint blue s
Vulnerabilities

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password

The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

3 min read
Photoreal news-editorial image of a rack-mounted network load balancer appliance in a dim data center aisle, cooling fans glowing amber, cables hanging from the
Vulnerabilities

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server

The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

3 min read
© 2026 Threat Vectr