vulnerability
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could allow remote …
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned. About CVE-2026-21589 CVE-2026-21589, a …
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code …
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow authenticated attackers to …
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has …
OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice …
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day exploits has now become …
GitHub’s AI agent found 24 Android app vulnerabilities
GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to …
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach …
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by …
AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the …
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management …
Featured news
Resources
Don't miss
- ASOS confirms data breach after “hacked” app alert reaches shoppers
- AI Agent Gateway: Open-source tool keeps credentials out of agent configs
- AI endpoint management: Visibility, compliance, and remediation
- Automation, AI agents or people? Sorting out who handles each security finding
- Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)