Security Vulnerabilities

The latest Security Vulnerabilities

NewsSecurity Vulnerabilities

Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-43673)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

WordPress Gallery PhotoBlocks Plugin Cross Site Scripting vulnerability (CVE-2026-66448)

– This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

Read More
NewsSecurity Vulnerabilities

Zohocorp Unauthenticated Remote Code Execution Vulnerability (CVE-2026-6516) 

– Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Read More
NewsSecurity Vulnerabilities

Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability (CVE-2026-50325)

– This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows.

Read More
NewsSecurity Vulnerabilities

ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability (CVE-2026-8921)

– This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager.

Read More
NewsSecurity Vulnerabilities

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2026-14266)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.

Read More
NewsSecurity Vulnerabilities

Cisco Identity Services Engine Path Traversal Vulnerability (CVE-2026-20146)

– A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files.

Read More
NewsSecurity Vulnerabilities

JuiceFS – Authentication Bypass via pprof and metrics Endpoints (CVE-2026-59092)

– JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux.

Read More
NewsSecurity Vulnerabilities

Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion (CVE-2026-59234)

– Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3.

Read More
NewsSecurity VulnerabilitiesUncategorized

Cisco Catalyst Center Arbitrary File Read Vulnerability (CVE-2026-20191)

– A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.

Read More