Cyber Security

Articles on SystemTek’s website that relate to cyber security.

NewsSecurity Vulnerabilities

Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability (CVE-2026-50325)

– This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows.

Read More
NewsSecurity Vulnerabilities

ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability (CVE-2026-8921)

– This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager.

Read More
NewsSecurity Vulnerabilities

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2026-14266)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.

Read More
NewsSecurity Vulnerabilities

Cisco Identity Services Engine Path Traversal Vulnerability (CVE-2026-20146)

– A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files.

Read More
Uncategorized

JetBrains YouTrack Authentication Bypass via Direct Database Access Leading to Administrative Access Vulnerability (CVE-2026-62422)

CVE number = CVE-2026-62422 In JetBrains YouTrack before versions 2026.1.13757,2025.3.148033,2025.2.148048,2025.1.148120,2024.3.148430,2024.2.148429 Authentication bypass via direct database access leading to administrative access

Read More
NewsSecurity News

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

– Organisations in critical infrastructure sectors are being supported to better understand and defend against malicious activity, as the UK and international partners today call out techniques used by Russian Intelligence Services

Read More
NewsSecurity Vulnerabilities

JuiceFS – Authentication Bypass via pprof and metrics Endpoints (CVE-2026-59092)

– JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux.

Read More
NewsSecurity Vulnerabilities

Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion (CVE-2026-59234)

– Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3.

Read More
NewsSecurity News

Cyber Criminal Group TeamPCP

– The Federal Bureau of Investigation (FBI) has released an alert to highlight the tactics, techniques, and
procedures (TTPs) and indicators of compromise (IOCs) associated with the cyber criminal group
TeamPCP.

Read More
NewsSecurity VulnerabilitiesUncategorized

Cisco Catalyst Center Arbitrary File Read Vulnerability (CVE-2026-20191)

– A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.

Read More