Vulnerabilities — Page 23

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS
The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD
Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

A 16-Year-Old Linux Flaw Lets Attackers Break Out of Virtual Machines
A newly disclosed bug in the Linux kernel has sat unnoticed since 2009, and it lets criminals escape the virtual walls that are supposed to keep cloud servers separate and safe.

BeyondTrust patches two critical bugs that let attackers walk past the login screen
The remote-access vendor rushed out fixes for four flaws in its Remote Support and Privileged Remote Access products, two of which allow unauthenticated attackers to reach powerful admin accounts under certain configurations.

Hidden Admin Backdoor Found in Tenda Router Firmware, CERT/CC Warns
A flaw tracked as CVE-2026-11405 lets anyone skip the password check and take over affected Tenda routers through the web interface.

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools
The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.

A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar
A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

A 16-Year-Old Flaw in Linux's Virtual Machine Engine Lets Guests Break Into Their Host
Januscape (CVE-2026-53359) sits in shared code used on both Intel and AMD servers, and a public demo already crashes the host machine.

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns
A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw
A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On
Researchers rebuilt a signed-in user's Gmail address from one page visit. Opera has patched the flaw.

Seven flaws in a tiny bit of code could shake millions of gadgets
runZero found bugs in FatFs, the filesystem library hiding inside cameras, drones and hardware crypto wallets. Patches are already trickling out, but the fix will take years.

Adobe Is Doubling Its Patch Releases — Here's Why That Matters
Starting in July, Adobe will push security fixes twice a month instead of once. Blame faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with.

Citrix NetScaler Vulnerability Sparks Exploitation Attempts
Citrix patches a high-severity flaw in NetScaler appliances as exploitation attempts are reported within 24 hours.