A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected websites.
The flaw, tracked as CVE-2026-19632, affects TranslatePress versions up to 3.3.1 and has been fixed in version 3.3.2. TranslatePress...
CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user.
The vulnerability affects Zimbra installations in...
A critical security flaw in the Elementor Pro WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable servers.
Tracked as CVE-2026-32475, the vulnerability affects Elementor Pro versions up to and including 4.2.1 and...
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478, a critical unauthenticated code injection vulnerability affecting self-managed GitLab Community Edition and Enterprise Edition instances.
The flaw, rated 9.4 out of 10, can allow...
A critical vulnerability in N-able Passportal’s Chrome and Microsoft Edge browser extensions could allow a malicious website or embedded iframe to steal an organization’s entire password vault, including live two-factor authentication codes.
Tracked as CVE-2026-15580, the issue received a CVSS...
A critical vulnerability in Spring Security’s embedded UnboundID LDAP server can allow remote attackers to gain administrative access to exposed in-memory LDAP directories.
Tracked as CVE-2026-59270, the issue affects applications that use Spring Security’s UnboundIdContainer, either directly or through Spring Boot's...
Kaspersky researchers investigating attacks on Russian organizations discovered that legitimate TrueConf video conferencing client installers were secretly bundled with PhantomCore malware, a tool associated with the Head Mare APT group.
The malicious installers were distributed directly from a TrueConf server...
CERT Polska has warned that threat actors are actively exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite.
Tracked as CVE-2026-73570, the flaw allows unauthenticated attackers to run arbitrary operating system commands as the zimbra user on affected...
A binary planting vulnerability in the Cursor IDE that lets a malicious git.exe file, placed at the root of a repository, run automatically the moment a developer opens that project on Windows.
The attack requires no prompt injection, no agent,...
A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of vulnerable websites.
The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and...