Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability News

Chaotic Eclipse Claims Avast Antivirus 0-Day Vulnerability – PoC Released

Researcher Chaotic Eclipse has claimed to have discovered a zero-day privilege-escalation vulnerability affecting Avast Antivirus and released a public proof-of-concept repository named PrettyPrague. The researcher behind the project, using the GitHub handle MSNightmare, says the issue can be exploited on...

3 High-Severity HP Easy Start Flaws Let Attackers Escalate Privileges on macOS

Three high-severity vulnerabilities in HP Easy Start for macOS could allow attackers to interfere with printer-software installation workflows and potentially gain elevated privileges. The flaws affect versions earlier than 2.16.7.260722, and HP has released a patched version to address...

Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host

Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario...

WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection Attacks

A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take over vulnerable WordPress sites. The flaw, tracked as CVE-2026-19949, affects more than 5 million active installations and has been fixed in version...

CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added two SonicWall SMA1000 appliance vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming that attackers are exploiting the flaws in real-world attacks. The entries were added on September 2, 2026, with federal...

Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability

A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local...

GitSpawn Flaws Let Malicious Repositories Execute Code in Claude Code, Codex, Cursor, and Grok

A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer's machine the moment it is opened with an AI coding agent, no prompt typed, no approval clicked, and in some...

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly. FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise...

Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM versions before 1.83.0 and allows authenticated users to access the...

Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems

HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary commands, and fully compromise affected systems. The flaws affect HPE...

Latest News

Latest News