vulnerability

Critical WatchGuard API Vulnerabilities Enables Command Execution Attacks

WatchGuard has disclosed three security vulnerabilities affecting WatchGuard AP devices, including two critical flaws that could allow attackers to gain…

1 week ago

16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records

A 16-year-old security researcher known as Faav uncovered an authentication flaw in Microsoft’s internal Titan analytics service that potentially exposed…

2 weeks ago

WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments

WordPress administrators are being urged to patch a high-severity core vulnerability that can turn an anonymous comment into server-side command…

2 weeks ago

Cloudflare Containers Vulnerability Could Leak Data Between Customer Workloads

Cloudflare has patched a cross-tenant data exposure vulnerability in its Containers platform across its global, multi-tenant cloud computing infrastructure that…

2 weeks ago

New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts

cPanel has patched three newly disclosed security vulnerabilities that threaten tenant isolation on shared-hosting servers, including a permissions flaw that…

2 weeks ago

Critical SolarWinds Flaws Let Attackers Remotely Execute Code on Observability Servers

SolarWinds released Observability Self-Hosted 2026.2.3 to fix two serious vulnerabilities that could let unauthenticated attackers remotely execute code on affected…

2 weeks ago

Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In

WordPress has released version 7.1.2 to address a critical security vulnerability that could allow unauthenticated attackers to execute code on…

2 weeks ago

Hackers Exploiting F5 BIG-IP OAuth Server 0-day Flaw to Gain Remote Code Execution

F5 has warned that hackers are actively exploiting a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) deployments to…

2 weeks ago

D-Link Router Hit by CVSS 10.0 Flaw Exploitable Remotely Without Authentication

D-Link Systems has disclosed that it is investigating a critical security vulnerability in its DIR-822A router, tracked as CVE-2026-86296. The…

2 weeks ago

Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges

Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI…

3 weeks ago