Cisco Patches 12 Critical SD-WAN and IOS XE Vulnerabilities
Cisco released patches for 12 critical vulnerabilities in Catalyst SD-WAN and IOS XE software impacting devices in all configurations.
Tag
29 results in the archive.
Cisco released patches for 12 critical vulnerabilities in Catalyst SD-WAN and IOS XE software impacting devices in all configurations.
HashiCorp, Veeam, and the Django Software Foundation released patches for 11 vulnerabilities, including a critical CVSS 10.0 cross-tenant bug affecting Terraform MCP Server, Veeam Service Provider Console, and Django software.
A critical vulnerability in cPanel (CVE-2026-58048) allowed authenticated hosting customers to execute SQL commands with root database privileges, risking full database control.
A high-severity vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers allows modification of DNA data output files, risking inaccurate test results in healthcare settings.
Adobe Campaign Classic includes a critical CVSS 10.0 vulnerability (CVE-2026-48449) that allows arbitrary code execution without user interaction.
A critical vulnerability in Azure Cosmos DB enabled attackers to escape the Gremlin query sandbox and gain full read/write access to multiple customer databases.
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote code execution, posing significant risk to enterprise environments.
A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary server files through malicious image uploads, risking exposure of sensitive data.
A critical vulnerability in the Ruflo open-source agent platform allows unauthenticated remote code execution and poisoning of AI memory, posing significant risks to AI model operations.
Broadcom published updates for critical VMware vulnerabilities in ESX, vCenter, Workstation, and Fusion enabling authentication bypass and VM escape with high severity.
A critical pre-authentication remote code execution vulnerability in vBulletin forum software has been patched following the public release of an exploit, enabling unauthenticated attackers to execute arbitrary PHP code.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
Multiple high-severity vulnerabilities in Weintek cMT3092X HMI may allow attackers to escalate privileges and steal credentials, impacting critical manufacturing environments.
CISA has directed federal agencies to urgently patch two actively exploited vulnerabilities in Fortinet FortiSandbox, highlighting critical risks to government and enterprise environments.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.
SonicWall disclosed two critical zero-day vulnerabilities in SMA1000 devices being exploited in active attacks, highlighting urgent risk to enterprise network security.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
OpenPLC v3 contains a critical authenticated arbitrary file write vulnerability that can lead to native code execution through compiling malicious files. This affects critical infrastructure sectors worldwide and requires urgent mitigation.
Researchers tested 281 popular free Android VPN apps and discovered many leak user traffic, transmit unencrypted data, and include tracking. These apps, collectively installed over 2.4 billion times, fail to meet basic privacy and security standards.
Ubiquiti released updates to fix critical vulnerabilities in UniFi Connect, Talk, Access, Protect, and OS. These flaws could allow privilege escalation and arbitrary command execution.
Threat actors are actively attempting to exploit a critical vulnerability in Gitea Docker images less than two weeks after it was patched. The flaw allows unauthenticated clients to escalate privileges by abusing the 'X-WEBAUTH-USER' header.
A critical use-after-free flaw in Linux's KVM hypervisor allows guest VMs on Intel and AMD systems to corrupt host kernel memory, potentially escaping the virtual environment. The vulnerability, known as Januscape (CVE-2026-53359), includes a public PoC that crashes hosts with a more impactful exploit reportedly in development.
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is now being actively exploited in cyberattacks, according to KEVIntel. This flaw demands immediate attention due to its maximum severity rating.
A new Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows unprivileged users to escalate to root, impacting Linux desktops, servers, and Android devices. A patch has already been released.
Security firm runZero disclosed seven vulnerabilities in FatFs, a widely used filesystem library in embedded devices including security cameras and drones. These flaws pose a risk due to FatFs's ubiquity in consumer and industrial firmware.