
ConnectWise issues mitigation for unpatched ScreenConnect flaw
ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.

ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.

Cloudflare's early-access Vulnerability Discovery and Remediation service uses OpenAI models to detect and prioritize code vulnerabilities based on production exposure, proposing tailored patches and WAF rules for customer review.

Hewlett Packard Enterprise has released a security update for ArubaOS-CX to address a critical remote code execution vulnerability, mitigating potential network compromise risks.

Hackers are exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and gain remote code execution on affected systems.

Security teams detected active exploitation of CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, shortly after the vendor released a fix. Attackers are generating administrative credentials and probing internal topologies on internet-facing systems.

Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability, leaving all user mailboxes open to hijacking.

Security researchers have identified a new technique used by the Chinese state-linked Fire Ant hacking group to turn Cisco IOS XR routers into covert data exfiltration channels via undocumented GRE tunnels.

PaperCut has released a second emergency security update for its NG and MF software after researchers discovered ways to bypass the initial patch for two actively exploited vulnerabilities.

cPanel released patches for a critical vulnerability allowing authenticated users with domain permissions to execute arbitrary code as root, affecting all supported versions of its control panel software.

PaperCut has issued an urgent warning after attackers exploited an unpatched vulnerability in its NG and MF print management platforms, with no fix yet available.

CISA has ordered federal agencies to patch a critical Citrix NetScaler remote code execution vulnerability being actively exploited in attacks, with a deadline of this Saturday.

Attackers are actively targeting WordPress sites using the miniOrange SAML 2.0 Single Sign On plugin, exploiting two critical authentication bypass vulnerabilities to forge SAML responses and log in as administrators.

Microsoft has released a fix for a critical vulnerability in Entra ID after confirming in-the-wild exploitation. The flaw allows attackers to bypass authentication controls in the identity and access management service.

CERT Polska reports active exploitation of a critical remote-code-execution vulnerability in Zimbra Collaboration Suite, urging immediate patching for affected versions.

Cloudflare disclosed a remote Spectre attack on its Workers platform that reliably leaked 12 bits per second with 99% accuracy, prompting runtime and isolation improvements. The exploit evaded existing defenses by exploiting long-lived execution contexts and noisy timers.

CVE-2026-47876 allows a guest VM with VMXNET3 adapter to execute code on the ESX host. Patches require host restarts, while one vCenter directory-traversal flaw is already exploited in 47 countries.

Microsoft’s August security update addresses 421 vulnerabilities, including a zero-day in the Windows Ancillary Function Driver for WinSock exploited by North Korea’s Lazarus Group since early June. The campaign targeted defense contractors via fake job offers and malicious PDF viewers, deploying a new rootkit and backdoor.

The Sandworm group has been distributing a backdoored WireGuard VPN client to system administrators since at least May, using fake job offers as the initial vector.

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware groups are exploiting a remote code execution vulnerability in Microsoft SharePoint, which has been under active attack since early July.

The U.S. Cybersecurity and Infrastructure Security Agency has added two recently patched SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming ransomware gangs are actively exploiting them.