Tag

#vulnerability

81 stories taggedvulnerability · page 4 of 6.

Full-frame photoreal editorial shot of a dimly lit server room aisle with rows of glowing amber and blue rack lights, one open cabinet door revealing exposed ca
Identity & Access

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin

A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, one server bay glowing with a warning-red status LED while others sh
Vulnerabilities

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns

A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw

A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. That raises the urgency for every organisation running Linux servers to patch now.

3 min read
Full-frame 16:9 photoreal editorial shot of a darkened desk with a gaming laptop open, screen glowing with a generic browser window and a translucent overlay su
Vulnerabilities

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On

Researchers rebuilt a signed-in user's Gmail address from one page visit. Opera has patched the flaw.

3 min read
Photoreal editorial image, full frame 16:9, of a modern office desk IP phone glowing softly in a dim server-room setting, with faint blue network cable light tr
Vulnerabilities

Cisco admits hackers are breaking into its phone system software — here's what that means

A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

4 min read
Vulnerabilities

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now

CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

3 min read
Vulnerabilities

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit

CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is happening now.

2 min read
Vulnerabilities

CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation

A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

2 min read
Vulnerabilities

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos

A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, researchers say.

2 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

2 min read
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

2 min read
Vulnerabilities

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin

A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin under specific conditions, with denial-of-service fallout for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

3 min read
Vulnerabilities

Squidbleed: A 1997 FTP Parsing Bug Is Still Leaking Cleartext HTTP in Squid Proxies

A heap over-read disclosed by Calif.io exposes other users' requests — credentials and session tokens included — to anyone permitted to send traffic through the same proxy.

3 min read
Threat Intelligence

FortiBleed Campaign Hits 86,644 FortiGate Boxes; CISA Pushes Customers to Lock Down

Russian-speaking operators are working through internet-exposed Fortinet appliances at scale. CISA wants admins moving now.

2 min read
Vulnerabilities

June Patch Tuesday Breaks OLE Automation, Leaves Word and Excel Silent on Failure

A Windows update shipped June 9 quietly severed the OLE bridge between Office apps and dozens of third-party tools. No error message. Just nothing.

2 min read
© 2026 Threat Vectr