Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

– Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device.

Read More
NewsSecurity Vulnerabilities

Samsung rlottie Numeric Truncation Remote Code Execution Vulnerability (CVE-2026-8916)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie.

Read More
NewsSecurity Vulnerabilities

NVIDIA Transformers4Rec Model.load Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2026-24162)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec.

Read More
NewsSecurity Vulnerabilities

Microsoft Edge Origin Validation Error Security Bypass Vulnerability (CVE-2026-45492)

– This vulnerability allows remote attackers to access restricted functionality on affected installations of Microsoft Edge.

Read More
NewsSecurity Vulnerabilities

ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability (CVE-2026-7480)

– This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager.

Read More
NewsSecurity Vulnerabilities

Cisco Webex Meetings Cross-Site Scripting Vulnerability (CVE-2026-20233)

– A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.

Read More
NewsSecurity Vulnerabilities

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability (CVE-2026-20230)

CVE number – CVE-2026-20230 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management

Read More
NewsSecurity Vulnerabilities

Exploitation of Critical SQL Injection Vulnerability in Drupal (CVE-2026-9082)

– A critical vulnerability in the Drupal content management system is being actively exploited, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalogue.

Read More
NewsSecurity Vulnerabilities

TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability (CVE-2026-34927)

– This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent.

Read More
NewsSecurity Vulnerabilities

LiteSpeed User-End cPanel Plugin privilege escalation vulnerability (CVE-2026-48172)

CVE number – CVE-2026-48172 LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the

Read More