#vulnerability
96 stories taggedvulnerability.

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped
A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited
A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.
A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

Check Point patches critical login flaw that hands attackers root on firewall management servers
CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

Attackers Are Breaking Into Orkes Conductor Servers Through a Critical Pre-Login Flaw
Fortinet says opportunistic scanning has begun against Orkes Conductor installations vulnerable to CVE-2026-58138, a pre-authentication remote code execution bug patched in version 3.30.2.

WeChat Flaw Allows Account Takeover Through Incoming Calls
Calif researchers built a worm that hijacks WeChat accounts via an incoming call. The target's phone doesn't need to be touched.

SAP patches critical 'OVERPASS' flaw that hands attackers full control of business servers
A buffer overflow in the SAP Kernel, plus a second critical bug in NetWeaver Message Server, could let unauthenticated attackers run commands on more than 10,000 exposed systems.

Bitcoin wallet flaw in Alby Hub could have let attackers drain funds
A critical bug in the self-hosted Lightning wallet exposed users who opened their Hub to the internet, though the vendor says there is no sign it was used in the wild.

Cisco firewall manager flaw rated 10 out of 10 is under active attack
A perfect-score bug in Cisco's Secure Firewall Management Center lets attackers take full control without a password. Evidence suggests exploitation started weeks before Cisco confirmed it.

Check Point Fixes Two Critical VPN Flaws That Could Let Hackers In Without a Password
Both bugs score 9.8 out of 10 and affect the firewall gear that guards corporate networks.

GitLab Rushes Out Fixes for Two Critical Server Flaws, One Lets Strangers Read Private Files
A path traversal bug and a second critical flaw in GitLab's enterprise product prompted an urgent patch call for self-hosted installations.

PaperCut Rolls Out Full Fix for Two Print-Server Flaws Already Under Attack
The vendor replaced its earlier emergency patches with proper maintenance releases across three supported branches.

Hackers Are Actively Exploiting a Critical Flaw in Cisco's Email Security Appliance
A zero-day vulnerability in Cisco Secure Email Gateway lets an unauthenticated attacker run any command they like as the most powerful user on the system. No login required.

LiteSpeed Flaw Lets a Single Hosting Account Take Over a Shared Server
cPanel warns that a critical bug in LiteSpeed Web Server Enterprise gives a low-privilege user a path to full root control, putting every website on the same machine at risk.

Siemens patches Teamcenter login flaw that could hijack engineer sessions
A reflected cross-site scripting bug in the /auth/ endpoint lets a crafted link run attacker code inside a logged-in user's browser. Siemens has shipped fixes across four release trains.