Vulnerabilities — Page 4

Full-frame 16:9 photoreal editorial shot of an electrical substation control cabinet at dusk, rows of protection relays with small status LEDs glowing amber and
Vulnerabilities

CISA Warns of 13 Critical Flaws in Ebyte NA111-M Gateways, No Patch in Sight

The Chinese vendor stopped responding to coordination requests, leaving industrial network gateways exposed to remote takeover.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of an underground fuel storage tank access port at a gas station forecourt at dusk, weathered concrete, e
Vulnerabilities

Mitsubishi Electric factory gear can be knocked offline by a single crafted network packet

A flaw tracked as CVE-2025-3511 lets a remote attacker freeze dozens of Mitsubishi factory automation products with one malformed UDP message, forcing a manual reset to recover.

4 min read
Full-frame close-up of a laptop motherboard during boot, faint blue glow from the UEFI firmware chip, soft shallow depth of field, dark technical mood, editoria
Vulnerabilities

Microsoft Blocks a Rogue RGB Driver That Was Crashing Windows 11 Gaming PCs

A tiny driver bundled with RGB lighting peripherals was knocking Windows 11 machines offline mid-game. Microsoft is now shipping a block for it.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit enterprise server rack with green status LEDs reflected on dark glass, faint amber warning
Vulnerabilities

CISA Gives Federal Agencies Four Days to Patch Exploited Citrix NetScaler Flaw

A memory bug first sold as a denial-of-service problem now lets attackers take full control of unpatched NetScaler boxes, and someone is already spraying the internet for them.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a server rack with a single network appliance highlighted by red status LEDs, blurred data center aisle in b
Vulnerabilities

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw

The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

3 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks

A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

NVIDIA workstation GPUs fall to GPUThor attack that beats built-in error correction

University of Toronto researchers show a Rowhammer variant can crash Ampere-class NVIDIA cards or hand an attacker root, and NVIDIA has issued guidance.

4 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, blue and amber status LEDs glowing, one server unit slightly pulled
Vulnerabilities

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers

A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

3 min read
Photoreal editorial image, 16:9 full-frame edge-to-edge composition
Vulnerabilities

CISA: Most Breaches Still Start With Old, Unpatched Bugs

A new review from the US cyber agency finds attackers rarely need clever tricks. They scan for known, exposed flaws that companies never got around to fixing.

3 min read
A modern white robot vacuum cleaner sitting on a wooden living room floor, its top cover removed to expose a green circuit board and a small memory chip, warm d
Vulnerabilities

Ubiquiti Patches Three Critical Bugs in UniFi Cameras, Phones and Router OS

Flaws in UniFi Protect, UniFi Talk and UniFi OS score the highest possible severity and can be triggered over the network without a login.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room aisle at night, rows of humming rack-mounted servers with soft blue and amber
Vulnerabilities

Two unpatched flaws in Kaltura's video player let attackers read files and run code

CERT/CC has gone public with a pair of bugs in Kaltura's mwEmbed library. Both trace back to the same old web-security sin: trusting user-supplied serialized data.

3 min read
Extreme close-up of a glowing server rack in a dark data centre, amber and blue indicator lights reflecting off brushed metal chassis, shallow depth of field dr
Vulnerabilities

Adobe and Nvidia Fix Dozens of Security Flaws, Including Critical Bugs That Could Let Attackers Take Control

Both companies released patches on the same Tuesday, covering vulnerabilities across AI tools, design software, and marketing platforms. Some flaws are rated critical, meaning attackers could run their own code on affected machines.

3 min read
Photoreal news-editorial style 16:9 image of a large server room with rows of illuminated rack-mounted servers casting cool blue and amber light across a polish
Vulnerabilities

Microsoft says the patching window is shrinking fast. Here is what that means for ordinary people.

Software flaws are being turned into working attacks within hours of being made public. Microsoft says companies can no longer patch their way out of the problem fast enough, and is pushing a new defensive approach to buy time.

4 min read
Close-up top-down view of a sleek aluminum laptop keyboard and trackpad on a matte desk surface, soft cool studio lighting casting subtle shadows, a faint abstr
Vulnerabilities

Chrome 152 Patches 327 Security Flaws, Most Found by Google's Own AI

Google's latest browser update is its biggest in recent memory, fixing hundreds of vulnerabilities at once, with artificial intelligence doing the heavy lifting on discovery.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands

A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

3 min read
© 2026 Threat Vectr