#vulnerability
81 stories taggedvulnerability · page 5 of 6.

CISA Flags Joomla Content Editor Bug as Actively Exploited; CVSS 10.0
CVE-2026-48907 in Widget Factory's JCE extension hands attackers arbitrary file actions on unpatched Joomla sites. Federal agencies get the standard three weeks.

Cisco's SD-WAN Manager Has a Write-to-Root Problem — and Attackers Found It First
CVE-2026-20262 lets an authenticated attacker overwrite arbitrary files on Cisco Catalyst SD-WAN Manager, with a clear path to root. No workaround exists. Exploitation is already underway.

Langflow's Unauthenticated File-Write Flaw Is Being Exploited — Patch Dropped 73 Days Ago
CVE-2026-5027 lets attackers write files to arbitrary paths on exposed servers, and because Langflow ships with login disabled by default, exploitation requires exactly zero credentials.

Splunk Patches CVE-2026-20253, a 9.8-Rated Unauthenticated RCE in Enterprise
The advisory covers Splunk Enterprise builds below 10.2.4 and 10.0.7, with fixed versions now available.

Oracle Patches PeopleSoft Flaw Tied to ShinyHunters Activity, Stays Quiet on Zero-Day Status
CVE-2026-35273 has a fix. Whether attackers got there first is a question Oracle isn't answering.

ServiceNow Patches Auth Bug After Attackers Pivot Deeper Into Hosted Instances
An unauthenticated flaw let intruders escalate access inside customer tenants before ServiceNow shipped a hosted-side fix.

Veeam Patches 9.4-Severity RCE in Backup & Replication; Domain Auth Required
CVE-2026-44963 lets any authenticated domain user run code on the backup server. Veeam shipped fixes Tuesday.

Public PoC Lands for Cisco Unified CM Root-Write Bug CVE-2026-20230
An unauthenticated SSRF in Cisco Unified Communications Manager opens a path to root. Cisco's PSIRT hasn't observed in-the-wild use — yet.

Diverging Paths to Cybersecurity: Tools vs. Operational Control
New reports debate whether inadequate tools or operational lapses are to blame for cybersecurity issues.

Exploit Code Goes Public for Critical Flowise One-Click RCE Flaw
A published proof-of-concept puts every self-hosted Flowise deployment at risk of full remote code execution — no authentication required from the attacker, just a malicious chatflow import.

CIFSwitch: Linux Kernel Key-Handling Bug Hands Out Root Across Major Distros
A local privilege escalation in the kernel's CIFS authentication path lets an unprivileged user forge key descriptions and walk away with root.

Critical Argument Injection Flaw in Gogs Remains Unpatched
Authenticated users can exploit a critical flaw in Gogs, posing security risks for internal Git deployments.

Authenticated RCE in Gogs Hits CVSS 9.4 — and There's No CVE Yet
A critical flaw in the self-hosted Git service lets any logged-in account execute arbitrary code on the server. The auth bar is low. The blast radius isn't.

FortiClient EMS Flaw Sees Fresh Exploitation After April Hotfix
Attackers are still hitting a critical FortiClient EMS vulnerability that Fortinet patched — and flagged as actively exploited — months ago.

Gitea Patches Unauthenticated Container Image Disclosure Flaw in 1.26.2
CVE-2026-27771 allowed anonymous pulls of private container images from all Gitea deployments prior to version 1.26.2, according to maintainers.