#vulnerability
81 stories taggedvulnerability · page 3 of 6.

US government orders emergency patch for critical Oracle finance software flaw
CISA gave federal agencies until Saturday to fix CVE-2026-46817, an Oracle E-Business Suite bug already under attack.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.

Old, Forgotten Boot Programs Left a Back Door Open Below Your Operating System
Security researchers found 11 outdated Linux boot components that Microsoft had quietly kept trusting for years. Any attacker with a copy could have slipped past a core security feature before Windows or Linux even started loading.

Zoom patches critical Windows flaw that could hand attackers your account
A 9.8-severity bug in Zoom's Windows client lets remote attackers take over accounts with no login required.

One Click Was All It Took to Hijack Anthropic's Claude AI
A flaw in the Claude Desktop app let attackers silently feed malicious instructions to the AI and steal private files. The bug is fixed, but the attack method points to a new category of risk.

Progress ShareFile zero-day forced emergency server shutdowns; patch is out
A path traversal flaw in Storage Zone Controllers let admin users read and write files they shouldn't. Progress says no customer breach has been found.

RabbitMQ Bugs Could Have Handed Attackers the Keys to Corporate Messaging
Two access control flaws in the widely used RabbitMQ broker exposed OAuth secrets and let one tenant peek at another's data.

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code
A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

Progress tells ShareFile customers to pull the plug amid 'credible' threat
The maker of a widely used file-sharing tool is emailing on-premises customers to shut down their servers now, while it investigates what it calls a credible external threat.

Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer
A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.

Microsoft Patches 'RoguePlanet' Defender Flaw a Month After Public Disclosure
The privilege escalation bug in the Malware Protection Engine sat exposed for weeks before Redmond shipped a fix.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

A 16-Year-Old Linux Flaw Lets Attackers Break Out of Virtual Machines
A newly disclosed bug in the Linux kernel has sat unnoticed since 2009, and it lets criminals escape the virtual walls that are supposed to keep cloud servers separate and safe.

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools
The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.