Tag

#vulnerability

96 stories taggedvulnerability.

Forum administrator dashboard showing active exploit code being shared publicly, vulnerability scanning results displayed with critical severity markers for unp
Vulnerabilities

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped

A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

4 min read
Full-frame edge-to-edge photoreal shot of a dimly lit enterprise server rack with a single network orchestrator appliance glowing amber, blurred fiber patch cab
Vulnerabilities

Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited

A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server room with rows of dark network racks and cool blue status lights, a single rack door sta
Vulnerabilities

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.

A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

3 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit corporate server room, rows of dark rack-mounted network firewall appliances with glowing amber
Vulnerabilities

Check Point patches critical login flaw that hands attackers root on firewall management servers

CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server rack in a modern data center, blue and amber indicator lights reflecting on glass p
Vulnerabilities

Attackers Are Breaking Into Orkes Conductor Servers Through a Critical Pre-Login Flaw

Fortinet says opportunistic scanning has begun against Orkes Conductor installations vulnerable to CVE-2026-58138, a pre-authentication remote code execution bug patched in version 3.30.2.

3 min read
A smartphone screen showing an incoming call notification on the lock screen, with a subtle unauthorized account access indicator appearing simultaneously in th
Vulnerabilities

WeChat Flaw Allows Account Takeover Through Incoming Calls

Calif researchers built a worm that hijacks WeChat accounts via an incoming call. The target's phone doesn't need to be touched.

2 min read
A network monitoring dashboard displaying thousands of exposed business servers connected to the internet, with critical alerts flowing across multiple screens
Vulnerabilities

SAP patches critical 'OVERPASS' flaw that hands attackers full control of business servers

A buffer overflow in the SAP Kernel, plus a second critical bug in NetWeaver Message Server, could let unauthenticated attackers run commands on more than 10,000 exposed systems.

4 min read
A home office desk with a self-hosted server hardware device and Bitcoin wallet interface displayed on screen, with illustrated network pathways showing exposur
Vulnerabilities

Bitcoin wallet flaw in Alby Hub could have let attackers drain funds

A critical bug in the self-hosted Lightning wallet exposed users who opened their Hub to the internet, though the vendor says there is no sign it was used in the wild.

3 min read
A cybersecurity operations center with Cisco Secure Firewall Management Center interface displayed on a large screen, a perfect 10
Vulnerabilities

Cisco firewall manager flaw rated 10 out of 10 is under active attack

A perfect-score bug in Cisco's Secure Firewall Management Center lets attackers take full control without a password. Evidence suggests exploitation started weeks before Cisco confirmed it.

4 min read
A corporate network security gateway or firewall device being examined, with critical vulnerability alerts displayed on adjoining monitors showing password bypa
Vulnerabilities

Check Point Fixes Two Critical VPN Flaws That Could Let Hackers In Without a Password

Both bugs score 9.8 out of 10 and affect the firewall gear that guards corporate networks.

3 min read
A server room with one machine marked with warning tape, its directory structure displayed on an adjacent monitor showing file path traversal routes exposed
Vulnerabilities

GitLab Rushes Out Fixes for Two Critical Server Flaws, One Lets Strangers Read Private Files

A path traversal bug and a second critical flaw in GitLab's enterprise product prompted an urgent patch call for self-hosted installations.

3 min read
Print servers in a network rack with update notifications displaying across connected workstations, version numbers changing from patches to full releases
Vulnerabilities

PaperCut Rolls Out Full Fix for Two Print-Server Flaws Already Under Attack

The vendor replaced its earlier emergency patches with proper maintenance releases across three supported branches.

3 min read
An email security appliance device with its status lights glowing, a terminal window open in front showing command execution with root permissions, and network
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in Cisco's Email Security Appliance

A zero-day vulnerability in Cisco Secure Email Gateway lets an unauthenticated attacker run any command they like as the most powerful user on the system. No login required.

3 min read
A web hosting control panel open on a monitor showing multiple website directories, with one highlighted folder containing a lock icon being bypassed, the backg
Vulnerabilities

LiteSpeed Flaw Lets a Single Hosting Account Take Over a Shared Server

cPanel warns that a critical bug in LiteSpeed Web Server Enterprise gives a low-privilege user a path to full root control, putting every website on the same machine at risk.

3 min read
An engineering workstation with CAD software open, a browser address bar highlighted showing a suspicious login URL, and user session indicators active on the d
Vulnerabilities

Siemens patches Teamcenter login flaw that could hijack engineer sessions

A reflected cross-site scripting bug in the /auth/ endpoint lets a crafted link run attacker code inside a logged-in user's browser. Siemens has shipped fixes across four release trains.

4 min read
© 2026 Threat Vectr