Wednesday, September 16, 2026
Follow on LinkedIn

Vulnerability

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites. The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress...

Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild

CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user. The vulnerability affects Zimbra installations in...

Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers. Tracked as CVE-2026-32475, the vulnerability affects Elementor Pro versions up to and including 4.2.1 and...

Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks

GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical unauthenticated code injection vulnerability affecting self-managed GitLab Community Edition and Enterprise Edition instances. The flaw, rated 9.4 out of 10, can allow...

Critical N-able Passportal Flaw Lets Malicious Websites Steal Entire Password Vault and 2FA Codes

A critical vulnerability in N-able Passportal’s Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization’s entire password vault, including live two-factor authentication codes. Tracked as CVE-2026-15580, the issue received a CVSS...

Critical Spring Security Flaw Lets Attackers Gain Admin Access to LDAP Servers

A critical vulnerability in Spring Security’s embedded UnboundID LDAP server can allow remote attackers to gain administrative access to exposed in-memory LDAP directories. Tracked as CVE-2026-59270, the issue affects applications that use Spring Security’s UnboundIdContainer, either directly or through Spring Boot's...

Hackers Exploit TrueConf Servers to Push Malware Through Legitimate Video Conference Downloads

Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were secretly bundled with PhantomCore malware, a tool associated with the Head Mare APT group. The malicious installers were distributed directly from a TrueConf server...

Critical Zimbra RCE Vulnerability Actively Exploited in the Wild

CERT Polska has warned that threat actors are actively exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite. Tracked as CVE-2026-73570, the flaw allows unauthenticated attackers to run arbitrary operating system commands as the zimbra user on affected...

Critical Cursor 0-day Vulnerability Enables Arbitrary Code Execution Attacks

A binary planting vulnerability in the Cursor IDE that lets a malicious git.exe file, placed at the root of a repository, run automatically the moment a developer opens that project on Windows. The attack requires no prompt injection, no agent,...

Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks

A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of vulnerable websites. The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and...

Latest News

Latest News