#vulnerability
96 stories taggedvulnerability · page 6 of 7.

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access
Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools
The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin
A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns
A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw
A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. Unpatched Linux servers are now a much easier target.

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On
One page visit was enough to rebuild a signed-in user's Gmail address. Opera has patched the flaw.

Cisco admits hackers are breaking into its phone system software — here's what that means
A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now
CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit
CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is confirmed now.

CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation
A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos
A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, Novee Security says.

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain
CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications
A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin
A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin media servers under specific conditions, with denial-of-service exposure for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

Squidbleed: A 1997 FTP Parsing Bug Is Still Leaking Cleartext HTTP in Squid Proxies
A heap over-read disclosed by Calif.io exposes other users' requests, credentials and session tokens included, to anyone permitted to send traffic through the same proxy.