Vulnerabilities — Page 9

Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Windows 10 gets its August 2026 security patch: what KB5120249 actually fixes
Microsoft's monthly update lands with a backup fix and wider Secure Boot certificate rollout. Install it.

Microsoft's August Patch Tuesday: 400 fixes, three zero-days, and Lazarus back in the frame
Microsoft ships fixes for 400 flaws, including one AFD.sys hole North Korean hackers were already using to plant a kernel rootkit.

SharePoint Flaw Lets Attackers Log In as Anyone. Microsoft Patches CVE-2026-55040.
Researchers used an AI agent to help chain bugs in Microsoft SharePoint into an unauthenticated takeover. The flaw carries a CVSS score of 9.1 and affects three server editions still widely used across government and enterprise.

Adobe Patches Over 50 Flaws, Tells ColdFusion and Campaign Classic Users to Act Now
Several of Adobe's most widely used business tools carried perfect-ten severity scores this week. Two products have been flagged as likely targets, and Adobe is telling administrators to patch immediately.

Zoom Had a Flaw That Let Hackers Take Over Your Computer During a Meeting, Without You Clicking Anything
A vulnerability in Zoom's annotation feature gave attackers a direct path to run code on any participant's machine. Patches are out now.

SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug
A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

Malicious SIM cards can hijack the modems inside EV chargers and industrial gear, researchers find
A team at the University of Birmingham showed that a booby-trapped SIM can run attacker code on the cellular modules baked into cars, routers and chargers.

Ransomware crews are now breaking into SharePoint servers through a May flaw
CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

Plug-and-Play Trick Turns a Fake USB Stick Into Full Windows 11 Takeover
Researchers show how Windows' helpful habit of auto-installing driver software can be twisted into SYSTEM-level control, and it works over Remote Desktop too.

Hackers hijacked BdThemes WordPress plugins to quietly create secret admin accounts
A poisoned promotional feed pushed malicious code to admin dashboards, spawning hidden accounts on sites running Element Pack and other BdThemes plugins.

Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals
Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

Cisco Warns Windows Users of High-Severity ClamAV Flaws, Two With Working Attack Code Released
Seven vulnerabilities in the ClamAV antivirus engine affect Cisco's Secure Endpoint Connector software across Windows, macOS, and Linux. Patches land in August.

Russian hacktivists hijack TrueConf video servers to push booby-trapped installers
Kaspersky says the Head Mare group exploited two unpatched flaws in TrueConf conferencing servers to swap the real client installer for one carrying the PhantomCore backdoor.

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts
A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.