Tag: cve-2025-48595

soc

CVE-2026-15748: Critical Forminator WordPress Flaw Enables Unauthenticated RCE

A critical security vulnerability in the popular Forminator Forms plugin for WordPress can allow unauthenticated attackers to upload executable PHP files and potentially take complete control of vulnerable websites. Tracked as CVE-2026-15748, the arbitrary file upload flaw carries a CVSS score of 9.8 and affects Forminator versions up to and including 1.56.1. Forminator is a […]

Mehr lesen →
soc

CVE-2026-20349: Actively Exploited Cisco ASA and FTD Flaw Enables Remote DoS

Cisco has disclosed a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software that is already being exploited in the wild. Tracked as CVE-2026-20349, the flaw carries a CVSS score of 8.6 and allows an unauthenticated remote attacker to force an affected firewall to reload, resulting in a […]

Mehr lesen →
soc

CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints

N-able has released an emergency hotfix for an actively exploited authentication bypass in N-central, a remote monitoring and management platform widely used by managed service providers and internal IT teams. The flaw allows a remote, unauthenticated attacker to obtain administrative access to vulnerable N-central servers and use the platform’s legitimate management capabilities to reach downstream […]

Mehr lesen →