cPanel has disclosed CVE-2026-67401, a critical SQL injection flaw in EmailTrack that could let authenticated attackers gain root-level control of vulnerable servers.
cPanel disclosed the security issue on September 8, 2026. According to cPanel, an attacker must already possess a...
Fortinet has disclosed a new high-severity vulnerability affecting its FortiSandbox platform, warning that unauthenticated attackers could exploit weaknesses in the product's web interface to siphon off sensitive information without ever needing valid credentials.
The flaw, tracked as CVE-2026-26084, stems...
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks.
CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used...
ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions.
The issue impacts both cloud-hosted and on-premises ScreenConnect deployments, and the company has released interim mitigation guidance while...
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks.
The new...
Security researchers have uncovered a significant vulnerability chain in Telerik UI for ASP.NET AJAX, allowing unauthenticated attackers to execute remote code in vulnerable enterprise web applications.
The issue primarily affects Telerik's RadAsyncUpload component, a widely used file-upload control in ASP.NET...
Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks.
The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content. The...
A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics.
The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on...
Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of...
A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local...