Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.
The first issue, tracked as CVE-2026-0768,...
A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges.
WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin...
A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness.
While Microsoft classifies the issue as an elevation-of-privilege flaw, the published research describes an attack chain that can lead to...
A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter permissions on files located outside its own installation directory.
The issue, tracked as CVE-2026-59944, can expose sensitive...
A critical vulnerability in Microsoft’s open-source UFO automation framework, tracked as CVE-2026-73296 with a CVSS score of 9.4, could allow remote attackers to view and control Android devices without authentication or user interaction.
The flaw, tracked as CVE-2026-73296, has a...
The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks.
The issue affects the Linux kernel’s IPv6...
PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used PaperCut NG and PaperCut MF print management software, prompting the company to rush out an emergency patch just hours after issuing its first warning.
The...
TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands.
Tracked as CVE-2026-76784, the flaw can lead to unauthorized changes to device...
TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user privileges.
The issue is detailed in TeamViewer security bulletin TV-2026-1008, published on August 26, 2026. It affects TeamViewer Remote, TeamViewer...
The Apache Software Foundation has patched a dozen security vulnerabilities in Apache Tomcat, the widely deployed open-source Java servlet container, with fixes rolled into version 11.0.25.
The flaws, disclosed on August 25, 2026, range from low-severity authentication quirks to important-rated...