Threat actors are exploiting a newly found zero-day flaw in Magento Open Source and Adobe Commerce to install persistent backdoors and compromise online…
Tag: Vulnerability
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges
Critical Telerik UI For ASP.Net Ajax Vulnerability Chain: CVE-2026-13181 to CVE-2026-13184
HOC Shorts A high-severity vulnerability chain in Telerik UI for ASP.NET AJAX (RadAsyncUpload) allows unauthenticated attackers to decrypt…
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw…
IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch
Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million…
Critical MikroTik Vulnerability – Patch Now, (Sun, Sep 6th)
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already…
A New Magento Zero-Day Is Breaking Into Online Stores Right Now
Online stores running Magento Open Source and Adobe Commerce are being broken into through a security flaw that has no patch, no CVE number and, as of…
Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access
Attackers are actively exploiting an unauthenticated remote access flaw in MikroTik RouterOS, and network administrators worldwide are being urged to…
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of…
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s…
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415…
Switchvox Vulnerability Triggers Active Exploitation Risk
Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already…
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
Why Vulnerability Management Must Move Beyond CVSS
Learn why vulnerability management must move beyond CVSS to prioritize real risk using exploitability, asset context, attack paths, and AI-driven analysis.
Fable 5.1 released, USPS “untested” IT, Exchange hijack vulnerability
Anthropic announces safety changes and new models USPS installs “untested” IT systems for mail-in ballots Thousands of Exchange servers vulnerable to…
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Google patched CVE-2026-85046, the sixth Chrome zero-day exploited in the wild in 2026. Here’s how to update your browser and stay protected.
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A high-severity flaw in All-in-One WP Migration leaves 3.25 million WordPress sites exposed, with vulnerable versions potentially leading to site…
Critical Ruby on Rails Vulnerability Under Active Attack | CVE-2026-66066
Cyber threat actors have begun actively exploiting a critical-severity in Ruby on Rails vulnerability, months after security researchers…
VMware Workstation/Fusion Critical Vulnerability Patched
VMware has released security updates addressing a critical vulnerability in its Workstation and Fusion virtualization platforms.
5 Million WordPress Sites Exposed to SQL Injection Vulnerability
A severe security flaw in a famous WordPress migration plugin and backup could allow threat actors to take command of over millions of sites, experts have…
