#vulnerabilities
75 stories taggedvulnerabilities.

Elementor Flaw Lets Attackers Hijack WordPress Sites With a Single Admin Click
A cross-site request forgery bug in the popular page-builder plugin can create rogue admin accounts if a logged-in administrator visits a booby-trapped page.

Microsoft's September 2026 Windows 11 update fixes 1,000 flaws and finally lets you move the taskbar
KB5124008 and KB5122880 ship a massive security backlog alongside a taskbar you can drag to any screen edge.

Microsoft ships final Windows 10 security rollup KB5122878 to ESU customers
The September 2026 update lands alongside a record Patch Tuesday fixing 966 flaws, and reaches only machines enrolled in Extended Security Updates or running the Enterprise LTSC editions.

Ivanti Fixes Critical Security Holes in Three Business Software Products
Six flaws in Ivanti Neurons for ITSM could let attackers run malicious code on affected systems from anywhere on the internet. Two other products, Sentry and EPMM, received fixes for authentication bypass bugs.

Fortinet Fixes Two Critical Security Flaws That Let Attackers Bypass Logins Entirely
One bug hides secret keys inside web code anyone can read. Another turns a Chrome extension into a traffic spy. Neither needed a password.

Russian-Speaking Attacker Turned AI Agents Loose on PaperCut, Hit 395 Organisations in Days
Hundreds of AI agents built exploits, picked targets and broke into schools and businesses across 48 countries. One US high school went from first contact to full takeover in seven minutes.

Chrome and Firefox Fix 115 Security Flaws in Back-to-Back Updates
Google and Mozilla have each pushed out new browser versions carrying fixes for dozens of vulnerabilities, three of them rated critical in Chrome. Neither company has seen any of the flaws used in real attacks, but the advice is the same: update now.

N-able rushes emergency fix for critical flaw in tool used to run thousands of company networks
A maximum-severity bug in N-able's N-central platform lets attackers run their own code on unpatched servers. Nearly 1,500 sit exposed on the public internet.

Cisco patches critical Nexus 9000 bug that lets attackers run code as root
A flaw tracked as CVE-2026-20212 scores 9.8 out of 10. Cisco also shipped a bundled fix for seven separate IOS XR bugs, two of them equally severe, with no workaround available.

Poisoned Git Configs Trick Claude, Codex and Cursor Into Running Attacker Code
Manifold Security found eight flaws in seven command-line AI coding assistants that let a booby-trapped repository run commands on a developer's machine without asking permission.

Rockwell Automation Fixes More Than a Dozen Security Flaws Across Its Industrial Software
The manufacturing technology company has issued patches for vulnerabilities in products used to control factory equipment worldwide, including RSLinx Classic and FactoryTalk.

Hackers Are Breaking Into Switchvox Phone Systems Through a Critical Flaw
A severe bug in Sangoma's business phone platform lets attackers run code on servers without a password. Exploitation is already happening.

CISA Warns of 13 Critical Flaws in Ebyte NA111-M Gateways, No Patch in Sight
The Chinese vendor stopped responding to coordination requests, leaving industrial network gateways exposed to remote takeover.

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers
A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

Ubiquiti Patches Three Critical Bugs in UniFi Cameras, Phones and Router OS
Flaws in UniFi Protect, UniFi Talk and UniFi OS score the highest possible severity and can be triggered over the network without a login.