Tag: cve-2026-21262

soc

CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data

Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information. Although the flaw has a CVSS score of […]

Mehr lesen →
soc

CVE-2026-64600: RefluXFS Linux Kernel Flaw Can Lead to Root Privilege Escalation

Linux local privilege escalation bugs remain especially dangerous when they turn an ordinary user foothold into full root access. CVE-2026-64600, also referred to as the RefluXFS vulnerability and the RefluXFS Linux Kernel Vulnerability, is a race condition in the Linux kernel’s XFS copy-on-write path that allows an unprivileged local attacker to overwrite protected files on […]

Mehr lesen →
soc

CVE-2026-56164 and CVE-2026-56155: Two Exploited Microsoft Zero-Days Put SharePoint and AD FS at Risk

Microsoft’s July 2026 Patch Tuesday drew immediate attention not just because of its record scale, but because two actively exploited zero-days hit some of the most sensitive parts of enterprise infrastructure. CVE-2026-56164 targets on-premises SharePoint Server and is remotely exploitable in low-complexity attacks, while CVE-2026-56155 targets Active Directory Federation Services and allows privilege escalation from […]

Mehr lesen →
soc

CVE-2026-15410 and CVE-2026-15409: SonicWall SMA 1000 Zero-Days Exploited in the Wild

SonicWall has patched two actively exploited zero-days affecting SMA 1000 Series secure remote access appliances. The issues are CVE-2026-15409, a critical unauthenticated SSRF flaw in the Workplace interface, and CVE-2026-15410, a post-authentication code injection flaw in the Appliance Management Console that can lead to arbitrary OS command execution as administrator under certain conditions. Public reporting […]

Mehr lesen →
soc

CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE

CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Splunk Enterprise admins should prioritize patching CVE-2026-20253, a critical vulnerability that allows a network-reachable, unauthenticated attacker to create or truncate arbitrary files on the Splunk server. Under certain conditions, this can be chained into remote code execution (RCE), making exposure the main risk driver. CISA has […]

Mehr lesen →
soc

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root CVE-2026-20262 is a zero-day vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that lets an authenticated attacker with low privileges (at least write access) write files to unintended locations on the server. The flaw sits in the web UI / API file upload flow, where […]

Mehr lesen →
soc

CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation

CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation Oracle has disclosed CVE-2026-35273, a critical Remote Code Execution (RCE) zero-day vulnerability in Oracle PeopleSoft Enterprise PeopleTools, affecting the Updates Environment Management component (often referenced as Environment Management / EMHub). Multiple reports cite active exploitation in the wild, with activity attributed to ShinyHunters. This post covers […]

Mehr lesen →