
VMware vCenter flaw exploited by ransomware groups
The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.
13 stories tagged with this topic.

The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.

Attackers are exploiting two recently disclosed RouterOS flaws to compromise MikroTik routers with internet-exposed SSH services, security researchers report.

Hewlett Packard Enterprise has released a security update for ArubaOS-CX to address a critical remote code execution vulnerability, mitigating potential network compromise risks.

Hackers are exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and gain remote code execution on affected systems.

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware groups are exploiting a remote code execution vulnerability in Microsoft SharePoint, which has been under active attack since early July.

TP-Link patched 15 vulnerabilities in its Omada zero-touch provisioning system, allowing attackers to combine them with earlier flaws to gain remote code execution on enterprise networks.

JetBrains has released a security update for TeamCity On-Premises to address a critical authentication bypass vulnerability that could enable remote code execution. The flaw affects all versions prior to the patched release.

Hackers are exploiting a zero-day vulnerability in the FastJson Java library to execute remote code on US-based systems without authentication or elevated privileges.

CISA has added four critical vulnerabilities in Ubiquiti UniFi OS and Lantronix EDS5000 serial-to-Ethernet servers to its Known Exploited Vulnerabilities catalog, citing active exploitation. Federal agencies must apply patches or mitigations by 27 June 2026.

CISA has mandated federal agencies to patch a critical Splunk Enterprise vulnerability (CVE-2026-20253) by 21 June 2026, following evidence of in-the-wild attacks. The flaw allows unauthenticated file operations via a PostgreSQL sidecar endpoint.

CISA has ordered federal agencies to patch a maximum-severity vulnerability in the Widget Factory Joomla Content Editor (JCE) plugin, tracked as CVE-2026-48907, which is being actively exploited. The flaw allows unauthenticated attackers to execute code on Joomla sites using the plugin.

MariaDB has issued fixes for CVE-2026-49261, a CVSS 10.0 remote code execution vulnerability in the wsrep_notify_cmd feature used by Galera Cluster. Two additional CVSS 8.0 parameter-injection flaws were patched in the same May 27 release. Standalone MariaDB deployments are unaffected.

Mandiant and Google Threat Intelligence Group have attributed an active compromise campaign to ShinyHunters (UNC6240), exploiting CVE-2026-35273 in Oracle PeopleSoft before Oracle issued its advisory on June 10, 2026. Over 100 organizations were exposed, 68% of them academic institutions.