Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE A critical vulnerability chain tracked as CVE-2026-18431 affects the Avada WordPress theme and its required Fusion Builder plugin, now branded as Avada Builder .
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. […]
A critical remote code execution vulnerability in Gitea has moved from disclosure to active exploitation less than a month after a patch became available. Tracked as CVE-2026-60004 and rated 9.8 on the CVSS scale, the flaw allows an attacker with ordinary repository write access to plant an executable Git hook and run arbitrary shell commands […]
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […]
A practical accessory for iPhone owners who tend to lose wallets, keys, remotes.
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.
Cloud Software Group has released security updates for a critical authentication bypass vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-19490 and rated 9.3 on the CVSS v4.0 scale, the flaw can allow an unauthenticated remote attacker to circumvent authentication controls on vulnerable systems configured as gateways or AAA virtual servers. The Critical […]