-
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code execution on exposed on-premises servers. The flaws, tracked as CVE-2026-55040 and CVE-2026-63520, affec…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context. This vulnerability, tracked as CVE-2026-59568,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vul…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These vulnerabilities could enable attackers to execute arbitrary operating system commands with root privileges. T…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind DN, granting them the ability to read or modify dat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has disclosed a critical remote code execution vulnerability in Microsoft Entra ID, identified as CVE-2026-69836. This flaw could enable unauthorized attackers to execute arbitrary code remotely. Released on August 20, 2026, it carries a maxi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unaut…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, ac…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Researchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform. This vulnerability, tracked as CVE-2026-73570, is an unauthenticate…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


