Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability

Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability

Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry. The first issue, tracked as CVE-2026-0768,...

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges. WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin...

Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability

A public proof-of-concept exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability linked to an authentication capture-and-replay weakness. While Microsoft classifies the issue as an elevation-of-privilege flaw, the published research describes an attack chain that can lead to...

Composer Flaw Lets Malicious Dependencies Expose SSH Keys and Sensitive Files

A newly disclosed security flaw in Composer, the widely used dependency manager for PHP, could allow a malicious or compromised package to alter permissions on files located outside its own installation directory. The issue, tracked as CVE-2026-59944, can expose sensitive...

Critical Microsoft Flaw Lets Hackers Remotely Control Android Devices Without a Login

A critical vulnerability in Microsoft’s open-source UFO automation framework, tracked as CVE-2026-73296 with a CVSS score of 9.4, could allow remote attackers to view and control Android devices without authentication or user interaction. The flaw, tracked as CVE-2026-73296, has a...

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw in real-world attacks. The issue affects the Linux kernel’s IPv6...

PaperCut NG/MF Vulnerability Actively Exploited in Attack – All Versions Impacted

PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used PaperCut NG and PaperCut MF print management software, prompting the company to rush out an emergency patch just hours after issuing its first warning. The...

TP-Link Kasa Smart Home Devices Vulnerability Allows Attackers to Disrupt Device Functionality

TP-Link has disclosed a high-severity vulnerability affecting multiple Kasa smart home devices that could allow attackers on the same local network to intercept, replay, or forge device-control commands. Tracked as CVE-2026-76784, the flaw can lead to unauthorized changes to device...

Multiple TeamViewer Vulnerabilities Enable Remote Code Execution Attacks

TeamViewer patched high-severity CVE-2026-16444, allowing authenticated remote-session attackers to write files to unintended locations and potentially execute code with user privileges. The issue is detailed in TeamViewer security bulletin TV-2026-1008, published on August 26, 2026. It affects TeamViewer Remote, TeamViewer...

Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers

The Apache Software Foundation has patched a dozen security vulnerabilities in Apache Tomcat, the widely deployed open-source Java servlet container, with fixes rolled into version 11.0.25. The flaws, disclosed on August 25, 2026, range from low-severity authentication quirks to important-rated...

Latest News

Latest News