Vulnerability

Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability

Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public…

2 weeks ago

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network…

2 weeks ago

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability

A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness.…

2 weeks ago

Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files

A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised…

2 weeks ago

Critical Microsoft Flaw Lets Hackers Remotely Control Android Devices Without a Login

A critical vulnerability in Microsoft’s open-source UFO automation framework, tracked as CVE-2026-73296 with a CVSS score of 9.4, could allow…

2 weeks ago

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited…

3 weeks ago

PaperCut NG/MF Vulnerability Actively Exploited in Attack – All Versions Impacted

PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used PaperCut NG and PaperCut MF…

3 weeks ago

TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality

TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local…

3 weeks ago

Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks

TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user…

3 weeks ago

Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers

The Apache Software Foundation has patched a dozen security vulnerabilities in Apache Tomcat, the widely deployed open-source Java servlet container,…

3 weeks ago