Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerabilities

JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control

An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take administrative control of exposed servers. The flaws, tracked as CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, affect multiple Artifactory release branches and create a...

Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access

Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected systems. The flaws affect Dell Secure Connect Gateway 5.0 Appliance...

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise...

Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks

SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances. The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands. The...

Critical ServiceNow Flaws Let Attackers Execute Code and Access Data

ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges. The company published...

Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks

Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images. The first flaw, tracked as CVE-2026-75604, affects Next.js applications that use either the Pages Router or the App Router...

Splunk Patches Critical MCP Server RCE and 16 Other Security Flaws Across AI Toolkit, Kafka Apps

Splunk has released security updates for 17 vulnerabilities affecting several apps and add-ons, including Splunk MCP Server, Splunk AI Toolkit, and Splunk Connect for Kafka. The most severe issue, tracked as CVE-2026-76404, is a critical remote code execution vulnerability with...

Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts

Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could allow attackers to bypass authentication and take over user accounts. The findings highlight the persistent security risks created by XML...

BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges

BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper controls. Tracked as CVE-2026-40144 and CVE-2026-40145, the flaws affect all versions of...

Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS

Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution. The updates were released on August 17, 2026, and include macOS...

Latest News

Latest News