Attackers Pounce on Critical Artifactory Flaw Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems.
CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems.
A critical security vulnerability in the popular Forminator Forms plugin for WordPress can allow unauthenticated attackers to upload executable PHP files and potentially take complete control of vulnerable websites. Tracked as CVE-2026-15748, the arbitrary file upload flaw carries a CVSS score of 9.8 and affects Forminator versions up to and including 1.56.1. Forminator is a […]
Cisco has disclosed a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software that is already being exploited in the wild. Tracked as CVE-2026-20349, the flaw carries a CVSS score of 8.6 and allows an unauthenticated remote attacker to force an affected firewall to reload, resulting in a […]
Cisco ASA and FTD CVE-2026-Adresse geschuetztCisco has confirmed active exploitation of CVE-2026-20349 , a High-severity denial-of-service (DoS) vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Fir
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.
XSS2Shell (CVE-2026-64638): Patch WordPress Now A new WordPress Core vulnerability chain called XSS2Shell turns a login page XSS bug into a much more serious risk for exposed WordPress sites. The issue is tracked as CVE-
N-able has released an emergency hotfix for an actively exploited authentication bypass in N-central, a remote monitoring and management platform widely used by managed service providers and internal IT teams. The flaw allows a remote, unauthenticated attacker to obtain administrative access to vulnerable N-central servers and use the platform’s legitimate management capabilities to reach downstream […]
CVE-2026-48449: Adobe Campaign Classic RCE Adobe Campaign Classic is affected by CVE-2026-48449, a critical incorrect authorization vulnerability allowing Remote Code Execution (RCE) . With a maximum severity score, this
CVE-2026-50522 PoC Fuels SharePoint Attacks Attackers are exploiting CVE-2026-50522, a critical Microsoft SharePoint Server vulnerability, after public proof-of-concept (PoC) exploit code became available. The activity t