Tag

#vulnerability

96 stories taggedvulnerability · page 6 of 7.

Full-frame close-up of a dark server room aisle, rows of black rack-mounted machines with faint green and amber status LEDs, one open server tray showing a bare
Vulnerabilities

GhostLock: A 15-Year-Old Linux Bug Hands Any User Root Access

Researchers say CVE-2026-43499 has sat in the Linux kernel since 2011 and needs nothing more than a normal login to seize full control.

3 min read
Full-frame photoreal editorial shot of a dimly lit server room with a single rack unit highlighted by a red status LED, blurred network cables in the foreground
Vulnerabilities

BeyondTrust Rushes Fixes for Two Critical Flaws That Let Attackers Walk Into Remote Support Tools

The company's Remote Support and Privileged Remote Access products carry pre-authentication bugs rated 9.2 on the severity scale, meaning attackers need no password to break in.

3 min read
Full-frame photoreal editorial shot of a dimly lit server room aisle with rows of glowing amber and blue rack lights, one open cabinet door revealing exposed ca
Identity & Access

Hackers Race to Exploit Gitea Flaw That Lets Anyone Log In as Admin

A missing check in Gitea's Docker images let attackers claim any username by adding a single header. Sysdig says probing began within days of the patch.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, one server bay glowing with a warning-red status LED while others sh
Vulnerabilities

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns

A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

3 min read
A close-up, editorial-style photograph of a rack of illuminated server hardware in a dark data centre, cooling fans visible, status LEDs casting blue and amber
Vulnerabilities

A Working Attack Script Is Now Public for the Linux 'Bad Epoll' Root Access Flaw

A proof-of-concept, meaning a ready-made demonstration script that shows exactly how to exploit a flaw, has been released for a serious Linux vulnerability. Unpatched Linux servers are now a much easier target.

3 min read
Full-frame 16:9 photoreal editorial shot of a darkened desk with a gaming laptop open, screen glowing with a generic browser window and a translucent overlay su
Vulnerabilities

Opera GX Bug Let Any Website Silently Install a Data-Stealing Add-On

One page visit was enough to rebuild a signed-in user's Gmail address. Opera has patched the flaw.

3 min read
Photoreal editorial image, full frame 16:9, of a modern office desk IP phone glowing softly in a dim server-room setting, with faint blue network cable light tr
Vulnerabilities

Cisco admits hackers are breaking into its phone system software — here's what that means

A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

4 min read
Vulnerabilities

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now

CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

3 min read
Vulnerabilities

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit

CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is confirmed now.

3 min read
Vulnerabilities

CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation

A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

2 min read
Vulnerabilities

Cordyceps Flaw Class Hands Attackers the Keys to 300+ GitHub Repos

A newly catalogued CI/CD weakness lets attackers hijack workflows at Microsoft, Google and Apache projects, Novee Security says.

3 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

3 min read
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

3 min read
Vulnerabilities

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin

A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin media servers under specific conditions, with denial-of-service exposure for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

3 min read
Vulnerabilities

Squidbleed: A 1997 FTP Parsing Bug Is Still Leaking Cleartext HTTP in Squid Proxies

A heap over-read disclosed by Calif.io exposes other users' requests, credentials and session tokens included, to anyone permitted to send traffic through the same proxy.

3 min read
© 2026 Threat Vectr