Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability

New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers. cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a...

FortiSandbox Vulnerability Allows Attackers to Access Sensitive Information via Crafted HTTP Requests

Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit weaknesses in the product's web interface to siphon off sensitive information without ever needing valid credentials. The flaw, tracked as CVE-2026-26084, stems...

CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks

CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks. CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used...

ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps

ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. The issue impacts both cloud-hosted and on-premises ScreenConnect deployments, and the company has released interim mitigation guidance while...

Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass

Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks. The new...

Telerik Flaw Chain Lets Unauthenticated Attackers Turn Padding Oracle Into Remote Code Execution

Security researchers have uncovered a significant vulnerability chain in Telerik UI for ASP.NET AJAX, allowing unauthenticated attackers to execute remote code in vulnerable enterprise web applications. The issue primarily affects Telerik's RadAsyncUpload component, a widely used file-upload control in ASP.NET...

Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild

Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks. The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content. The...

Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks

A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics. The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on...

Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code

Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of...

Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability

A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local...

Latest News

Latest News