Google has released an emergency Chrome security update addressing a high-severity zero-day vulnerability that is already being exploited in the wild. Tracked as CVE-2026-85046 and rated 8.8 on the CVSS scale, the flaw is a type confusion issue in V8, the JavaScript and WebAssembly engine used by Google Chrome. Successful exploitation can allow a remote […]
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
SonicWall has released emergency security updates for two vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances after confirming that both flaws have been exploited in the wild. Tracked as CVE-2026-83548 and CVE-2026-83549, the issues affect the Appliance Work Place and Appliance Management Console components and may be chained to move from unauthenticated external […]
JFrog Artifactory CVE-2026-Adresse geschuetztA critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is under active exploitation, posing an immediate threat to self-managed software
PaperCut is responding to active attacks targeting its NG and MF print management platforms through a pair of zero-day vulnerabilities that can be chained to achieve unauthenticated remote code execution. One of the flaws, tracked as CVE-2026-81578, is a high-severity authentication bypass that enables a remote attacker to modify sensitive PaperCut configuration without first logging […]
PaperCut RCE Chain: CVE-2026-Adresse geschuetztPaperCut disclosed two vulnerabilities in PaperCut NG and PaperCut MF that can be chained into a pre-authentication Remote Code Execution (RCE) path against vulnerable Applica
PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578. The post More Details Emerge on Exploited PaperCut Vulnerabilities appeared first on SecurityWeek.
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.