Tag: cve-2024-40766

soc

CVE-2026-76460: Critical Cisco ISE Zero-Day Authentication Bypass Exploited in the Wild

Cisco has released emergency security updates for a maximum-severity vulnerability affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) after confirming active exploitation in the wild. Tracked as CVE-2026-76460 and rated 10.0 on the CVSS scale, the flaw allows an unauthenticated remote attacker to bypass authentication and gain unauthorized access to a vulnerable […]

Mehr lesen →
soc

CVE-2026-27540 WooCommerce Flaw Exploited

CVE-2026-Adresse geschuetztCommerce Flaw Exploited Attackers are actively exploiting CVE-2026-27540 , a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPress. The flaw allows

Mehr lesen →
soc

CVE-2026-76461: Critical Cisco Secure Email Gateway Zero-Day Enables Root RCE

Cisco has patched CVE-2026-76461, a critical zero-day vulnerability in Secure Email Gateway appliances that is already being exploited in the wild. The flaw carries a CVSS score of 9.8 and enables an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system simply by sending a specially crafted email through […]

Mehr lesen →
soc

CVE-2026-44756: Critical SAP Kernel Flaw Enables Unauthenticated Remote Code Execution

SAP has addressed CVE-2026-44756, a maximum-severity memory corruption vulnerability in Extended Passport (EPP) Processing that could let a remote, unauthenticated attacker execute arbitrary operating system commands on vulnerable SAP systems. The issue, dubbed OVERPASS by Onapsis Research Labs, carries a CVSS score of 10.0 and resides in shared SAP kernel code used by multiple products […]

Mehr lesen →
soc

CVE-2026-67276: MikroTik RouterOS SSH Zero-Day Exploited in Router Takeover Attacks

MikroTik has released emergency RouterOS security updates after researchers confirmed that attackers are actively exploiting a high-severity SSH authentication bypass against internet-facing routers. Tracked as CVE-2026-67276 and rated 9.2 on the CVSS scale, the flaw allows an attacker to authenticate as an existing RouterOS user without possessing that user’s legitimate RSA private key. The vulnerability […]

Mehr lesen →