#vulnerability
96 stories taggedvulnerability · page 2 of 7.

Hackers Are Forging Admin Tokens to Take Over WSO2 API Manager
A critical signature-verification bug tracked as CVE-2026-5430 lets attackers forge login tokens and seize administrator accounts. Exploitation is already under way.

FreeIPA Bug Lets Unknown Users Mint Themselves Admin Accounts
A two-flaw chain in Red Hat's identity system lets an anonymous client create a Kerberos account and land in the administrators group with no credentials required.

ConnectWise ScreenConnect Hit by New File-Transfer Flaw, Patch Days Away
The remote-support tool used by IT teams worldwide has a bug that lets attackers move files through active sessions. A fix is expected this week.

OPC Foundation patches installer flaw that let a bystander hijack setup on industrial servers
A medium-severity bug in the OPC UA Local Discovery Server installer briefly exposes a high-privilege console anyone at the keyboard could grab.

A Ten-Year-Old PostgreSQL Flaw Let a Backup Account Become a Backdoor
A security gap in widely used database software, hidden since 2014, could let a low-level account take over an entire server. Patches are out. Here's what you need to know.

Plex tells users to update now as it patches unspecified security flaws
The media server company emailed customers directly, a rare step, and is holding back details until CVE numbers are assigned.

Working Exploit Published for Cleo Harmony Flaw That Ransomware Gangs Already Love
A newly discovered flaw in the Cleo Harmony file-transfer application lets attackers break in and take control without a password. A working exploit is already public, and Cl0p used a different Cleo bug to hit major organisations just months ago.

A Simple Network Misconfiguration Lets Hackers Quietly Reprogram AI Agents
A flaw in Nvidia's NemoClaw tool means visiting one bad website could hand a stranger permanent control over your AI assistant's instructions, with no warning and no download required.

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow
A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

Cosmos EVM Bug Drained Six Blockchains Over Five Days in August 2026
A critical balance-handling flaw in the shared Cosmos EVM module let attackers siphon funds from six chains between 20 and 25 August 2026, and the advisory landed without a CVE or CVSS score.

Chinese-Speaking Hackers Hit Philippine Nuclear Research Agency Through ownCloud Bug
CISA has flagged a critical flaw in the file-sharing tool ownCloud as actively exploited, after attackers used it to steal data from a nuclear research body in the Philippines.

Donation plugin flaw hands attackers full control of 100,000 WordPress sites
A maximum-severity bug in GiveWP lets anyone create an account and run commands on the server. The fix landed in version 4.16.7.2 on August 27.

8,300 Gitea servers still exposed to a code injection bug attackers are already using
A flaw in Gitea's diffpatch endpoint lets low-privilege users run shell commands on the server. CISA gave federal agencies three days to patch. Most operators haven't.

ServiceNow patches three top-severity flaws in its AI platform
Three of the four bugs score a maximum 10.0 on the industry severity scale, and one can be triggered by an attacker who has not logged in.

Critical cPanel Bug Lets a Single Hosting Customer Seize an Entire Server
A flaw in domain parking, tracked as CVE-2026-65643, could hand root control of a shared hosting server to any customer with an account on it.