A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an…
Tag: Vulnerability
Critical cPanel Flaw Lets Hosting Users Grab Database Root Access | CVE-2026-58048
A critical security vulnerability patched in cPanel could allow authenticated web hosting users to cross privilege boundaries and…
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply…
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a…
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks
A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and…
Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User
A critical privilege-escalation flaw in cPanel & WHM has been disclosed that could allow authenticated hosting users to execute arbitrary SQL commands…
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
N-able N-central Vulnerability Under Active Exploitation
Threat actors are actively exploiting an N-able N-central vulnerability that can grant unauthenticated administrative access.
DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data
Thermo Fisher Scientific has disclosed a high-severity security flaw affecting several of its Applied Biosystems Human Identification (HID) software…
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in…
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as…
Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild
Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud…
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution…
N‑able Patches Vulnerability Exploited to Hack N-central Servers
The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web…
Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
N-able has confirmed that a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform, is being actively exploited…
Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console
N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated…
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has…
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted…
Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability
Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed…
