Cyber Security

Articles on SystemTek’s website that relate to cyber security.

NewsSecurity Vulnerabilities

TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability (CVE-2025-71414)

– This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent.

Read More
NewsSecurity Vulnerabilities

OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability (CVE-2026-19590)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex.

Read More
NewsSecurity Vulnerabilities

Critical AVideo Vulnerability Could Expose Password Hashes and Session Tokens (CVE-2026-86190)

– A newly disclosed security vulnerability in WWBN AVideo, an open-source video-sharing platform, could allow unauthenticated attackers to access sensitive information belonging to users and potentially hijack active sessions.

Read More
NewsSecurity Vulnerabilities

Grav CMS Vulnerability CVE-2026-86197 Could Allow Page Editors to Inject Malicious Scripts

– Tracked as CVE-2026-86197, the vulnerability is a cross-site scripting (XSS) flaw affecting Grav versions before 2.0.20. Security researchers have rated it Medium severity, with a CVSS 3.1 score of 5.4.

Read More
NewsSecurity Vulnerabilities

Critical SadTalker Vulnerability Could Allow Attackers to Execute Commands on Servers (CVE-2026-85696)

– A newly disclosed critical security vulnerability in the open-source SadTalker project could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers.

Read More
NewsSecurity Vulnerabilities

Cisco IP Phones Hit by High-Severity Denial-of-Service Vulnerability (CVE-2026-20281)

– Cisco has disclosed a high-severity vulnerability affecting a range of its IP and video phones that could allow an unauthenticated remote attacker to cause the devices to become unavailable.

Read More
NewsSecurity Vulnerabilities

Critical Citrix NetScaler Vulnerabilities Could Expose Systems to Attack (CVE-2026-19489 and CVE-2026-19490)

– The vulnerabilities, tracked as CVE-2026-19489 and CVE-2026-19490, affect NetScaler ADC and NetScaler Gateway, products widely used to provide application delivery, remote access and VPN services.

Read More
NewsSecurity Vulnerabilities

Critical Team Password Manager Vulnerability Allows Account Takeover (CVE-2026-84699)

– A critical security vulnerability in Team Password Manager could allow unauthenticated attackers to take control of user accounts through the application’s password reset process.

Read More
NewsSecurity Vulnerabilities

Critical AshSqlite Vulnerability Could Expose Hidden JSON Data (CVE-2026-77846)

– A newly disclosed vulnerability in AshSqlite could allow attackers to access sensitive information hidden inside JSON data, potentially exposing fields that an application was never intended to make publicly available.

Read More
NewsSecurity Vulnerabilities

Chinese-Made ZBT Routers Found Containing Two Hidden Backdoors

– Security researchers have uncovered two previously undocumented backdoors hidden inside the firmware of a range of Chinese-made ZBT routers, potentially allowing unauthenticated attackers to gain root-level access to affected devices.

Read More