Vulnerabilities — Page 23

Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
Full-frame photoreal editorial shot of an open industrial control cabinet inside a substation, showing a ruggedised ethernet switch with blue and green status L
Vulnerabilities

Siemens tells industrial customers to patch RUGGEDCOM switches now, cites dozens of flaws in SINEC OS

The German engineering giant has shipped version 4.0 of its ruggedised network operating system to close a long list of bugs, including one rated 9.8 out of 10.

3 min read
Photoreal editorial shot of a dense server rack in a cool-lit data centre, rows of blinking green and amber status LEDs, one rack panel showing a faint red warn
Vulnerabilities

16-Year-Old Linux Bug Lets Attackers Escape Virtual Machines on Intel and AMD

Researcher Hyunwoo Kim's 'Januscape' flaw (CVE-2026-53359) sat in KVM for over a decade and threatens shared cloud servers at Google Cloud, AWS and beyond.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

A 16-Year-Old Linux Flaw Lets Attackers Break Out of Virtual Machines

A newly disclosed bug in the Linux kernel has sat unnoticed since 2009, and it lets criminals escape the virtual walls that are supposed to keep cloud servers separate and safe.

3 min read
Full-frame photoreal editorial image of a dimly lit server room with a single rack door left ajar, blue and amber indicator lights glowing on network appliances
Vulnerabilities

BeyondTrust patches two critical bugs that let attackers walk past the login screen

The remote-access vendor rushed out fixes for four flaws in its Remote Support and Privileged Remote Access products, two of which allow unauthenticated attackers to reach powerful admin accounts under certain configurations.

3 min read
Full-frame photoreal editorial shot of a small black consumer Wi-Fi router on a plain desk, indicator lights glowing amber, softly lit from one side, moody shad
Vulnerabilities

Hidden Admin Backdoor Found in Tenda Router Firmware, CERT/CC Warns

A flaw tracked as CVE-2026-11405 lets anyone skip the password check and take over affected Tenda routers through the web interface.

3 min read
Full-frame photoreal editorial shot of a dimly lit server room with a single rack unit highlighted by a red status LED, blurred network cables in the foreground
Vulnerabilities

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools

The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

A New Citrix NetScaler Flaw Is Already Being Exploited, And It Looks Familiar

A security hole in widely used Citrix network equipment is leaking corporate secrets from memory. Attackers moved within 24 hours of the patch dropping.

3 min read
Full-frame 16:9 photoreal editorial shot of a dense server rack in a dim data centre, cool blue LEDs reflecting off polished floor tiles, one open chassis expos
Vulnerabilities

A 16-Year-Old Flaw in Linux's Virtual Machine Engine Lets Guests Break Into Their Host

Januscape (CVE-2026-53359) sits in shared code used on both Intel and AMD servers, and a public demo already crashes the host machine.

4 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, one server bay glowing with a warning-red status LED while others sh
Vulnerabilities

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns

A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw

A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

3 min read
Full-frame 16:9 photoreal editorial shot of a darkened desk with a gaming laptop open, screen glowing with a generic browser window and a translucent overlay su
Vulnerabilities

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On

Researchers rebuilt a signed-in user's Gmail address from one page visit. Opera has patched the flaw.

3 min read
Full-frame close-up, 16:9, of a small circuit board with a USB stick partially inserted, warm amber and cool blue lighting, shallow depth of field, faint solder
Vulnerabilities

Seven flaws in a tiny bit of code could shake millions of gadgets

runZero found bugs in FatFs, the filesystem library hiding inside cameras, drones and hardware crypto wallets. Patches are already trickling out, but the fix will take years.

3 min read
Photoreal, news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Adobe Is Doubling Its Patch Releases — Here's Why That Matters

Starting in July, Adobe will push security fixes twice a month instead of once. Blame faster vulnerability discovery, AI-assisted research, and a threat pace that monthly updates can no longer keep up with.

3 min read
A close-up of a modern data center with server racks, highlighting a Citrix NetScaler appliance in a corporate IT environment
Vulnerabilities

Citrix NetScaler Vulnerability Sparks Exploitation Attempts

Citrix patches a high-severity flaw in NetScaler appliances as exploitation attempts are reported within 24 hours.

2 min read
© 2026 Threat Vectr