Vulnerabilities — Page 3

Donation plugin flaw hands attackers full control of 100,000 WordPress sites
A maximum-severity bug in GiveWP lets anyone create an account and run commands on the server. The fix landed in version 4.16.7.2 on August 27.

PaperCut Rushes Out Second Fix as Attackers Chain Bugs to Run Code
A newly patched flaw in the widely used print management software is being actively exploited, and PaperCut has shipped emergency hardening on top of the original patch.

Bluetooth to Root: Researcher Finds Two Ways Into Unitree's G1 Humanoid
Two flaws in Unitree's flagship G1 EDU robot let an attacker take full control, and one of them starts with nothing more than a Bluetooth signal.

8,300 Gitea servers still exposed to a code injection bug attackers are already using
A flaw in Gitea's diffpatch endpoint lets low-privilege users run shell commands on the server. CISA gave federal agencies three days to patch. Most operators haven't.

ServiceNow patches three top-severity flaws in its AI platform
Three of the four bugs score a maximum 10.0 on the industry severity scale, and one can be triggered by an attacker who has not logged in.

ZBT Routers Found With Two Hidden Factory Backdoors Handing Attackers Full Control
Researchers at VulnCheck say firmware shipped by Shenzhen Zhibotong Electronics contains two undocumented implants that let anyone on the internet run commands as root.

Critical cPanel Bug Lets a Single Hosting Customer Seize an Entire Server
A flaw in domain parking, tracked as CVE-2026-65643, could hand root control of a shared hosting server to any customer with an account on it.

Windows 11 Preview Update Brings 35 Changes, Including a Movable Taskbar
Microsoft's optional August 2026 update lets users dock the taskbar to any screen edge and starts rolling out a new admin protection feature.

Why Security Teams Are Ditching the Quarterly Scan for Something That Never Stops
A growing number of organisations are replacing old-school vulnerability scanning with a continuous approach called CTEM. The idea sounds simple. The culture change is anything but.

Next.js Rushes Fixes for Two Critical Bugs That Let Attackers Run Code Without Logging In
Vercel patched flaws in the popular web framework that could be triggered by a booby-trapped image or a rigged URL on Windows servers.

PaperCut print servers under active attack via unpatched flaw
PaperCut says hackers are breaking into print management servers using a bug that affects every version of NG and MF. Emergency patches are out.

CISA Warns of 13 Critical Flaws in Ebyte NA111-M Gateways, No Patch in Sight
The Chinese vendor stopped responding to coordination requests, leaving industrial network gateways exposed to remote takeover.

Mitsubishi Electric factory gear can be knocked offline by a single crafted network packet
A flaw tracked as CVE-2025-3511 lets a remote attacker freeze dozens of Mitsubishi factory automation products with one malformed UDP message, forcing a manual reset to recover.

Microsoft Blocks a Rogue RGB Driver That Was Crashing Windows 11 Gaming PCs
A tiny driver bundled with RGB lighting peripherals was knocking Windows 11 machines offline mid-game. Microsoft is now shipping a block for it.

CISA Gives Federal Agencies Four Days to Patch Exploited Citrix NetScaler Flaw
A memory bug first sold as a denial-of-service problem now lets attackers take full control of unpatched NetScaler boxes, and someone is already spraying the internet for them.