Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability News

Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass

Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks. The new...

OpenVPN Fixes 7 Security Flaws Affecting VPN Connections and Windows Systems

The OpenVPN project has shipped version 2.7.7, a security-focused release that patches seven distinct vulnerabilities spanning the software's core reliability layer and its Windows-specific service components. The update, released on September 3, 2026, addresses issues ranging from denial-of-service conditions to...

N-able Released Hotfix for RCE Vulnerability Affecting Platform

N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server. The update, identified as build 2026.3.1.14, was issued for on-premises N-central deployments. N-able...

Hackers Actively Exploiting PaperCut Servers Command Execution Vulnerabilities

Two critical vulnerabilities in PaperCut servers, CVE-2026-81578 and CVE-2026-82078, are being actively exploited, allowing attackers to execute commands, steal credentials, and potentially create privileged accounts within victim networks. Recent reports from Arctic Wolf Threat Intelligence indicate that these vulnerabilities are...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code on Database Servers

A newly disclosed PostgreSQL vulnerability, tracked as CVE-2026-6471 and nicknamed PostGREShell, could allow attackers with low-level replication access to execute arbitrary code on database servers. The flaw in PostgreSQL logical decoding existed for roughly 12 years and has now been...

ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System

ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every device it manages, without needing a password...

Hackers Exploiting MikroTik RouterOS Vulnerability in the Wild to Gain Complete Network Access

Attackers are actively exploiting an unauthenticated remote access flaw in MikroTik RouterOS, and network administrators worldwide are being urged to patch their devices immediately before compromise turns into a full network takeover. MikroTik confirmed on September 3, 2026, that it...

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security firm Sansec disclosed the...

Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws

Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed security issues affecting Plex Media Server versions 1.43.2 and earlier,...

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The flaws, tracked as CVE-2026-18167 and...

Latest News

Latest News