< ciso
brief />
Tag Banner

All news with #active exploitation tag

776 articles

Microsoft patches critical Entra ID deserialization flaw

πŸ” Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more β†’

GitLab critical code injection exploited rapidly

πŸ›‘οΈ A critical GitLab vulnerability, CVE-2026-19478 (CVSS 9.4), enables unauthenticated code injection allowing modification or deletion of public projects under certain conditions. Affected CE and EE versions include 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab released fixes in patched releases, while watchTowr reports rapid in-the-wild exploitation and reproduction using probes targeting GraphQL directives.
read more β†’

Citrix issues critical patches for NetScaler gateways

πŸ”’ Citrix has released critical updates for customer-managed NetScaler ADC and NetScaler Gateway to address two serious vulnerabilities: a memory overflow that can cause unpredictable behavior or denial of service, and an authentication bypass that permits pre-authentication access. Supported on-premises builds and certain deployments are affected while Citrix-managed services have been updated; cloud marketplace images may still need manual replacement. Security experts urge immediate emergency patching, credential rotation, session termination, and active hunting due to the high risk of rapid weaponization against internet-facing gateways.
read more β†’

AI-Generated Exploits Target Siemens PLCs, Risking ICS Safety

πŸ›‘οΈ U.S. agencies warned of an active threat using AI-generated exploit scripts to target Siemens S7 Series PLCs and other industrial controllers, posing risks to Critical Manufacturing, Energy, Water, and related sectors. The campaign leverages internet scanning services to find exposed devices and uses custom Python tools integrating snap7.dll or python-snap7 to mimic legitimate monitoring utilities. Agencies urge patching, network isolation, strong access controls, and enhanced ICS monitoring to mitigate potential disruption, data compromise, and safety incidents.
read more β†’

Critical Elementor Pro flaw allows remote code execution

πŸ”’ A critical vulnerability in Elementor Pro allows attackers to upload executable files leading to remote code execution on affected WordPress sites. Identified as CVE-2026-32475, the bug stems from inconsistent handling of empty filename entries between the validation and processing loops in the File Upload module. Exploitation requires a published Elementor form with a File Upload field and multiple file upload enabled; administrators should update immediately and inspect uploads directories for rogue PHP files.
read more β†’

Active exploitation of Zimbra SNMP RCE disclosed

πŸ›‘οΈ A critical Zimbra Collaboration flaw (CVE-2026-73570, CVSS 8.9) allowing command injection and remote code execution is being actively exploited, CERT Polska warns. The issue affects ZCS versions prior to 10.1.20 when the optional zimbra-snmp package and SNMP notifications are enabled; it was patched in 10.1.20. Administrators are urged to inspect /var/log/zimbra.log for suspicious restarts and check recent files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
read more β†’

CISA Alerts: Active Exploitation of MLflow SSRF Bug

πŸ”’ The Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical MLflow vulnerability (CVE-2026-64849) that enables a DNS-rebinding SSRF bypass in MLflow's outbound webhook delivery. The flaw, patched in MLflow 3.15.0, allows unauthenticated attackers to make the tracking server issue requests to internal and cloud-metadata endpoints and read responses, risking theft of cloud credentials. CISA added the issue to its KEV catalog and ordered federal agencies to remediate under BOD 26-04, urging all defenders to prioritize patching.
read more β†’

Critical Zimbra RCE Flaw Actively Exploited Now

πŸ›‘οΈ CERT Polska warns that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570). The flaw, patched in Zimbra 10.1.20 on July 20, enables unauthenticated remote code execution via command injection in the SNMP notification processing when SNMP notifications are enabled. Shadowserver reports over 12,100 Zimbra servers exposed online, and administrators are urged to check logs and specific directories for signs of compromise. Zimbra has been a frequent target of APT groups in past campaigns.
read more β†’

Critical AIT‑GUI Flaw Allows Remote Command Execution

πŸ”’ A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more β†’

CISA: Windows Task Host Flaw Now Exploited by Ransomware

πŸ”’ CISA confirmed ransomware gangs are exploiting a high-severity Windows Task Host privilege escalation flaw, tracked as CVE-2025-60710, which Microsoft patched in November 2025. The vulnerability affects Windows 11 and Windows Server 2025 and allows local attackers with basic permissions to escalate to SYSTEM. Although Microsoft has not detailed active attacks, CISA added the flaw to its Known Exploited Vulnerabilities list and urged federal agencies to apply mitigations promptly.
read more β†’

CISA Adds Actively Exploited Critical Ray Flaw

πŸ›‘οΈ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Ray vulnerability (CVE-2025-62593) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw enables remote code execution via DNS rebinding attacks through browsers like Firefox and Safari and primarily affects developers running Ray in development or testing environments. Ray fixed the issue in version 2.52.0, and agencies are urged to remediate by August 20, 2026.
read more β†’

Critical WordPress plugin flaw exposes admin accounts

πŸ”’ More than 40,000 WordPress sites were exposed by an authentication bypass in the User Profile Builder plugin. Tracked as CVE-2026-15826 with a 9.8 CVSS score, versions up to 3.16.4 are affected. Wordfence identified a type confusion in the registration/auto-login flow that can convert a failed registration into user ID 1, enabling generation of an admin authentication token. The vendor released version 3.16.5 on July 16; site owners should update immediately.
read more β†’

Critical SAP Commerce Cloud RCE Vulnerability Alert

πŸ”” SAP Commerce Cloud is affected by a maximum-severity vulnerability, CVE-2026-58231, rated 10.0 for insufficient authorization and input validation. An unauthenticated attacker can abuse a default authentication client to send crafted input and trigger arbitrary code execution, risking confidentiality, integrity, and availability. Vendors urge immediate patching and recommend IP filter sets as a temporary mitigation.
read more β†’

macOS Screen Sharing flaw exploited to install miner

πŸ”’ The Netherlands' NCSC warns that a macOS Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited after public exploit code appeared. The flaw affects the built-in VNC-based Screen Sharing service (TCP 5900) and allows network attackers to authenticate without valid credentials. Apple fixed the issue in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9; affected users should update or disable Screen Sharing in System Settings.
read more β†’

Critical SAP Commerce Cloud RCE Now Being Exploited

πŸ›‘οΈ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more β†’

Multi‑agent AI attack breaches government networks

πŸ”’ Researchers report a multi-day, near-autonomous cyberattack using open-source AI agents that targeted government systems in Asia, compromising credentials and probing sensitive agencies. The campaign, observed in early July, used parallel agents to map networks, exploit APIs, and move laterally via single sign‑on integrations, producing large volumes of exfiltrated files and cracked credentials. Vendors and experts warn the incident underscores a widening gap between the falling cost of capable attacks and the higher cost of defense.
read more β†’

Adobe Commerce flaw exploited to hijack customer accounts

πŸ”’ Adobe patched a critical incorrect-authorization vulnerability (CVE-2026-71362) in its Commerce and Magento platforms after researchers observed exploitation attempts that can let attackers switch customer sessions and access private data. Sansec's Shield WAF reportedly blocked attacks and found the flaw required no account, admin rights, or user interaction. Administrators are urged to apply the August 2026 isolated patches after ensuring the correct -p release is installed.
read more β†’

PoC for SharePoint JWT Bypass Now Used in Attacks

πŸ”’ A Rapid7 proof-of-concept for a critical SharePoint JWT authentication bypass (CVE-2026-55040) is already being weaponized in attacks, researchers warn. Microsoft patched the flaw in its July 2026 updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 and cautioned that exploitation can disclose files and modify data. CISA has issued guidance urging teams to avoid exposing SharePoint servers and to apply hardening measures.
read more β†’

Cisco ASA and FTD HTTP DoS Flaw Exploited

πŸ›‘οΈ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more β†’

State‑Sponsored Job‑Offer Campaign Delivers Zero‑Day

πŸ“„ Check Point Research details Operation Dream Job, a renewed Lazarus campaign using fake recruiter outreach to deliver malicious PDFs and trojanized PDF viewers targeting defense and aerospace organizations. Attackers exploited a newly reported Windows zero‑day (CVE-2026-68820) to escalate privileges and deploy a stealthy rootkit, while backdoors like Troy and ForestTiger give long‑term access. The campaign abuses compromised websites and webmail servers as command-and-control relays to blend with normal traffic and evade detection.
read more β†’