Vulnerabilities — Page 4

CISA Warns of 13 Critical Flaws in Ebyte NA111-M Gateways, No Patch in Sight
The Chinese vendor stopped responding to coordination requests, leaving industrial network gateways exposed to remote takeover.

Mitsubishi Electric factory gear can be knocked offline by a single crafted network packet
A flaw tracked as CVE-2025-3511 lets a remote attacker freeze dozens of Mitsubishi factory automation products with one malformed UDP message, forcing a manual reset to recover.

Microsoft Blocks a Rogue RGB Driver That Was Crashing Windows 11 Gaming PCs
A tiny driver bundled with RGB lighting peripherals was knocking Windows 11 machines offline mid-game. Microsoft is now shipping a block for it.

CISA Gives Federal Agencies Four Days to Patch Exploited Citrix NetScaler Flaw
A memory bug first sold as a denial-of-service problem now lets attackers take full control of unpatched NetScaler boxes, and someone is already spraying the internet for them.

CISA Flags Six Actively Exploited Bugs, Including a Citrix NetScaler Flaw
The U.S. cyber agency ordered federal agencies to patch fast, after evidence hackers are already breaking into Citrix, Linux and Microsoft SQL Server systems.

Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks
A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

NVIDIA workstation GPUs fall to GPUThor attack that beats built-in error correction
University of Toronto researchers show a Rowhammer variant can crash Ampere-class NVIDIA cards or hand an attacker root, and NVIDIA has issued guidance.

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers
A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

CISA: Most Breaches Still Start With Old, Unpatched Bugs
A new review from the US cyber agency finds attackers rarely need clever tricks. They scan for known, exposed flaws that companies never got around to fixing.

Ubiquiti Patches Three Critical Bugs in UniFi Cameras, Phones and Router OS
Flaws in UniFi Protect, UniFi Talk and UniFi OS score the highest possible severity and can be triggered over the network without a login.

Two unpatched flaws in Kaltura's video player let attackers read files and run code
CERT/CC has gone public with a pair of bugs in Kaltura's mwEmbed library. Both trace back to the same old web-security sin: trusting user-supplied serialized data.

Adobe and Nvidia Fix Dozens of Security Flaws, Including Critical Bugs That Could Let Attackers Take Control
Both companies released patches on the same Tuesday, covering vulnerabilities across AI tools, design software, and marketing platforms. Some flaws are rated critical, meaning attackers could run their own code on affected machines.

Microsoft says the patching window is shrinking fast. Here is what that means for ordinary people.
Software flaws are being turned into working attacks within hours of being made public. Microsoft says companies can no longer patch their way out of the problem fast enough, and is pushing a new defensive approach to buy time.

Chrome 152 Patches 327 Security Flaws, Most Found by Google's Own AI
Google's latest browser update is its biggest in recent memory, fixing hundreds of vulnerabilities at once, with artificial intelligence doing the heavy lifting on discovery.

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.