Vulnerabilities — Page 2

WordPress backup plugin hole leaves 3.25 million sites open to hijack
A flaw in All-in-One WP Migration and Backup lets unauthenticated attackers plant SQL that fires when an admin restores a backup, handing over full control of the site.

CISA flags seven actively exploited flaws, including two in SonicWall SMA1000 boxes
The US cyber agency's Known Exploited Vulnerabilities catalog picks up bugs in Sangoma, JFrog, LiteLLM, Kestra, Starlette and a pair in SonicWall's remote access appliances.

Rockwell Automation Fixes More Than a Dozen Security Flaws Across Its Industrial Software
The manufacturing technology company has issued patches for vulnerabilities in products used to control factory equipment worldwide, including RSLinx Classic and FactoryTalk.

Hackers Are Already Breaking Into Software Stores Using a Flaw Disclosed Three Days Ago
A critical security hole in JFrog Artifactory, a platform used by thousands of companies to store and ship software, is being actively exploited just 72 hours after its public disclosure.

Hackers Are Exploiting a Critical JFrog Artifactory Flaw to Seize Admin Control
A severe authentication bypass in JFrog Artifactory is being actively exploited. Attackers can gain full administrator access without a password, then quietly alter the software that companies build and ship to customers.

Working Exploit Published for Cleo Harmony Flaw That Ransomware Gangs Already Love
A newly discovered flaw in the Cleo Harmony file-transfer application lets attackers break in and take control without a password. A working exploit is already public, and Cl0p used a different Cleo bug to hit major organisations just months ago.

SonicWall Patches Two VPN Zero-Days Already Being Used by Hackers
A perfect-10 flaw in SonicWall's SMA 1000 remote-access boxes lets attackers slip past the login screen, and it's being paired with a second bug in real attacks.

Two Bugs in GeoNetwork Let Attackers Take Over Government Map Portals
A chain of flaws in the open-source software behind many public geoportals allowed strangers on the internet to run their own code on the server. Fixes landed in July 2026.

Hackers Are Breaking Into Switchvox Phone Systems Through a Critical Flaw
A severe bug in Sangoma's business phone platform lets attackers run code on servers without a password. Exploitation is already happening.

22,000 Microsoft Exchange servers still open to mailbox takeover flaw
A patched but widely ignored bug lets attackers read, send and download every user's email. Exploit code is already circulating.

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow
A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

Hackers Are Already Exploiting a Critical Flaw in JFrog Artifactory
A severe authentication weakness in a tool used by software teams worldwide was patched on August 28. Within days, attackers had found a way to use it to give themselves full administrator access.

WatchGuard Patches Five Critical Flaws That Could Let Attackers Seize Control Remotely
Security appliance maker WatchGuard has fixed more than two dozen vulnerabilities in its firewall software and management tools, including five rated near-perfect in severity.

Researcher Drops 'HardBreacher' Exploit for Kaspersky Security Software
A bug-hunter who has repeatedly embarrassed Microsoft now has Kaspersky in the crosshairs, releasing a proof-of-concept exploit that can hand an attacker near-total control of a Windows machine running Kaspersky Endpoint Security.

Hackers Are Actively Exploiting a Near-Perfect-Score Flaw in Ruby on Rails
A critical vulnerability in the popular web framework lets criminals read files off a server and, in some cases, run their own code on it, and patches are not fully closing the door.