Saturday, September 5, 2026
Follow on LinkedIn

Vulnerability

Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild

Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks. The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content. The...

Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks

A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics. The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on...

Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code

Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of...

Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability

A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local...

Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability

Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry. The first issue, tracked as CVE-2026-0768,...

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges. WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin...

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability

A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness. While Microsoft classifies the issue as an elevation-of-privilege flaw, the published research describes an attack chain that can lead to...

Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files

A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter permissions on files located outside its own installation directory. The issue, tracked as CVE-2026-59944, can expose sensitive...

Critical Microsoft Flaw Lets Hackers Remotely Control Android Devices Without a Login

A critical vulnerability in Microsoft’s open-source UFO automation framework, tracked as CVE-2026-73296 with a CVSS score of 9.4, could allow remote attackers to view and control Android devices without authentication or user interaction. The flaw, tracked as CVE-2026-73296, has a...

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks. The issue affects the Linux kernel’s IPv6...

Latest News

Latest News