Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Cisco Secure Workload Unauthorized API Access Vulnerability (CVE-2026-20223)

– A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role.

Read More
NewsSecurity Vulnerabilities

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability (CVE-2026-20182)

– A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Read More
NewsSecurity Vulnerabilities

Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability (CVE-2025-12659)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap.

Read More
NewsSecurity Vulnerabilities

Apple macOS CoreSymbolication Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2026-28918)

– This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability (CVE-2026-8109)

– This vulnerability allows remote attackers to disclose sensitive information on affected installations of Ivanti Endpoint Manager.

Read More
NewsSecurity Vulnerabilities

Proxmox extension allow unauthorized access to instances belonging to other tenants (CVE-2026-25199)

– Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants.

Read More
NewsSecurity Vulnerabilities

Critical Vulnerability in Palo Alto PAN-OS (CVE-2026-0300)

– Palo Alto has published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges.

Read More
NewsSecurity Vulnerabilities

Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability (CVE-2026-20172)

– A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks.

Read More
NewsSecurity Vulnerabilities

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

– Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.

Read More
NewsSecurity Vulnerabilities

Totolink N300RH Password buffer overflow vulnerability (CVE-2026-7747)

– A vulnerability, which was classified as critical, has been found in Totolink N300RH 3.2.4-B20220812.

Read More