< ciso
brief />
Tag Banner

All news with #active exploitation tag

915 articles · page 16 of 46

Critical Cisco SD‑WAN Manager zero‑day enables root

🔒 Cisco warned of a high‑severity, unpatched zero‑day (CVE-2026-20245) in the Catalyst SD‑WAN Manager actively exploited to escalate to root. The flaw affects all deployment types and results from insufficient validation of user‑supplied input, allowing local attackers with netadmin privileges to perform command injection by uploading crafted files. Cisco noted limited cases of configuration changes pushed to edge devices and advised contacting TAC and producing admin‑tech logs for investigation. Patches are not yet available; customers were urged to install fixes for related CVE-2026-20182.
read more →

Critical RCE in Everest Forms Pro Actively Exploited

🛡️ A critical remote code execution flaw in Everest Forms Pro for WordPress has been actively exploited to hijack sites. Wordfence analysis shows the vulnerability (CVE-2026-3300, CVSS 9.8) allows unauthenticated attackers to run PHP via the plugin's Calculation add-on when "Complex Calculation" is enabled. The bug affects all versions through 1.9.12 and was patched in 1.9.13; administrators are urged to update immediately. Wordfence telemetry recorded tens of thousands of blocked exploit attempts and identified indicators such as a rogue admin named "diksimarina" and a recurring source IP.
read more →

CISA alerts on active Android and Linux kernel exploits

🔒 CISA warns that threat actors are actively exploiting high-severity vulnerabilities in the Android Framework and the Linux kernel, now added to its Known Exploited Vulnerabilities catalog. Google confirms CVE-2025-48595 affects Android 14–16 and may be under limited targeted exploitation, addressed by June 2026 patches. The kernel flaw CVE-2022-0492 impacts multiple branches and can enable container escapes via cgroups v1, with fixes available in specified kernel releases. Federal agencies must remediate or mitigate by the June 5 deadline under BOD 22-01.
read more →

Two-year-old Oracle WebLogic flaw now actively exploited

🔒 US federal agencies were ordered to patch a two-year-old high-severity Oracle WebLogic Server vulnerability, CVE-2024-21182, after its addition to CISA’s Known Exploited Vulnerabilities catalog. The flaw affects supported versions 12.2.1.4.0 and 14.1.1.0.0 and was patched by Oracle in the July 2024 CPU. Security experts note that inclusion in the KEV indicates active weaponization and highlight persistent slow patching across organizations as a key risk.
read more →

Critical Kirki Flaw Lets Attackers Hijack WordPress

🔒 Defiant's Wordfence observed active exploitation of a critical privilege escalation bug (CVE-2026-8206) in the Kirki - Freeform Page Builder plugin, used on over 500,000 sites. The flaw, introduced in version 6.0.0 and present through 6.0.6, exposes a password reset endpoint that sends reset links to attacker-supplied emails, enabling account takeover. Vendor patched the issue in v6.0.7; site owners must update or disable the plugin immediately.
read more →

Critical HP Poly VoIP Flaw Enables Remote Root Access

🔒 HP has released patches for a critical buffer overflow in multiple IP conference phones in its Poly Voice line that can allow unauthenticated attackers to gain root on affected devices. The issue, tracked as CVE-2026-0826 and rated 9.2 CVSS, stems from SDP parsing when the ICE feature is enabled; administrators are advised to disable ICE if not needed. Rapid7 researchers released a Metasploit exploit demonstrating the vulnerability, and HP has issued UCS updates to remediate the affected VVX and Trio models.
read more →

Gamaredon leverages WinRAR flaw to deliver modular malware

🛡️ Gamaredon exploited CVE-2025-8088 in WinRAR to deploy an HTML Application payload named GammaPhish, which fetches a VBScript downloader called GammaLoad. Observed in January 2026 by Sekoia, the chain delivers multiple strains including a worm (GammaWorm) that persists via scheduled tasks and hides payloads using NTFS ADS, and a stealer (GammaSteel) that exfiltrates files to AWS S3 or fallback servers. The campaign targets Ukrainian entities and demonstrates a modular, highly obfuscated architecture likely to be reused.
read more →

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Oracle WebLogic vulnerability, CVE-2024-21182 (CVSS 7.5), to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. The flaw permits unauthenticated network attackers to compromise servers via T3 and IIOP protocols and was patched by Oracle in July 2024. Federal agencies are urged to apply fixes by June 4, 2026, to protect critical data and systems.
read more →

Microsoft threatens researcher after Windows exploits

🔒 An anonymous researcher known as “Nightmare Eclipse” has published several significant exploits targeting Microsoft Windows, including a vulnerability that defeats BitLocker. Microsoft has responded with threats of legal action, prompting public debate and recriminations between the company and security community. The situation has raised concerns about disclosure practices, researcher protections, and the balance between security research and corporate legal responses.
read more →

Weekly recap: PAN-OS, Gogs, GlassWorm takedown

🔔 This week's briefing highlights active exploitation of a PAN-OS GlobalProtect authentication bypass (CVE-2026-0257), a critical unauthenticated RCE in Gogs, and the coordinated takedown of GlassWorm C2 infrastructure. Other notable items include a long-standing Linux LPE (CIFSwitch) patched upstream, CERT-In urging rapid patching timelines, and several AI-enabled and supply-chain aided campaigns increasing attacker speed and reach.
read more →

Critical Windows Netlogon RCE Flaw Now Exploited

🔒 The Centre for Cybersecurity Belgium (CCB) warned that threat actors are exploiting a recently patched critical Windows Netlogon vulnerability (CVE-2026-41089). Microsoft patched the stack-based buffer overflow during May 2026 Patch Tuesday, which can allow unauthenticated remote code execution on domain controllers. The CCB urged administrators to apply updates immediately, noting a CVSS score of 9.8, while Microsoft has not yet confirmed active exploitation.
read more →

Critical WP Maps Pro Flaw Enables Site Takeover

🛡️ WP Maps Pro, a popular WordPress plugin, contains a critical privilege escalation vulnerability (CVE-2026-8732) that allows unauthenticated attackers to create administrator accounts and take over sites. The flaw affects all versions up to 6.1.0 and was fixed in 6.1.1. Security researcher David Brown reported the issue, and Wordfence has observed active exploitation attempts. Site owners must update immediately to mitigate ongoing attacks.
read more →

Palo Alto fixes auth-bypass in GlobalProtect VPN

🔒 Palo Alto Networks patched CVE-2026-0257, an authentication bypass on the GlobalProtect portal and gateway, after attackers began exploiting the flaw. Initially rated medium, the issue was raised to high severity following multiple exploitation attempts on unpatched PAN-OS devices. Rapid7 observed forged-cookie probes and VPN IP assignment to internal networks, prompting urgent patching guidance. CISA added the vulnerability to its KEV Catalog and federal agencies must remediate by June 1.
read more →

Critical WP Maps Pro Bug Lets Attackers Create Admins

🔒 A critical vulnerability in WP Maps Pro (CVE-2026-8732) allowed unauthenticated attackers to create administrator accounts via a flawed "temporary access" AJAX endpoint. Discovered by researcher David Brown, the issue affected versions 6.1.0 and older and relied on a publicly exposed nonce in frontend JavaScript, making protections ineffective. Defiant observed active exploitation attempts and blocked thousands of requests, and the vendor released WP Maps Pro 6.1.1 to address the flaw. Site owners are urged to update immediately to prevent account takeover and persistent backdoors.
read more →

PAN-OS GlobalProtect Authentication Bypass Exploited

🔒 Palo Alto Networks disclosed a medium-severity authentication bypass (CVE-2026-0257, CVSS 7.8) affecting PAN-OS and Prisma Access GlobalProtect portals and gateways when authentication override cookies and a specific certificate configuration are used. The vendor warned on May 13, 2026, and updated on May 29 after confirming limited in-the-wild exploit attempts targeting unpatched devices. Rapid7 reported successful exploitation beginning May 17 with a second wave on May 21, in some cases granting VPN IP assignment and internal network access. Temporary mitigations include disabling authentication override or generating a dedicated certificate for the override feature.
read more →

Unpatched critical Gogs vulnerability highlights open-source risks

🔒 A critical argument-injection vulnerability in the self-hosted Git service Gogs allows any authenticated user to execute code remotely by submitting a pull request with a malicious branch name. Discovered by a Rapid7 researcher, the flaw remains unpatched after months and the Gogs maintainer did not respond to disclosure requests. Rapid7 warns default configurations permit easy account and repo creation, enabling exploitation without admin privileges. Organizations using Gogs should restrict network access and disable self-registration until a fix is available.
read more →

FortiClient EMS exploit delivers credential stealer

🛡️ Arctic Wolf researchers observed threat actors exploiting a critical FortiClient EMS vulnerability (CVE-2026-35616) in May 2026 to push a credential-stealing payload disguised as an endpoint update. The attackers abused EMS management pathways to run malicious PowerShell commands via FortiClient components, modifying configurations to deploy a .cmd script and Base64-encoded PowerShell that downloads and exfiltrates data. Fortinet patched the flaw in FortiClient EMS 7.4.7 and later; attackers targeted managed endpoints and used fortitray.exe to launch the attack.
read more →

CISA orders rapid patch for exploited cPanel plugin

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a critical, actively exploited privilege escalation flaw in the LiteSpeed cPanel user-end plugin, tracked as CVE-2026-48172. LiteSpeed released urgent updates to fix the issue in the lsws.redisAble function and advised administrators to check logs and block suspicious IPs. CISA added the flaw to its known exploited vulnerabilities catalog and required patches by May 29 under BOD 22-01.
read more →

ABB Terra AC Heap Overflow Risks and Fixes

🔒 ABB reported a heap-based buffer overflow in select Terra AC EV chargers that can be triggered via crafted OCPP messages. Exploitation may allow heap pollution, denial-of-service, altered firmware behavior, or possible remote code execution; the vendor has released patched firmware versions. ABB strongly recommends avoiding unencrypted HTTP for OCPP connections and applying updates promptly to mitigate remote exploitation risks.
read more →

ABB B&R Automation Runtime SDM Denial of Service

🔒 An Improper Resource Locking vulnerability in the System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network attacker to delete data and cause denial of service. The vendor corrected the issue in Automation Runtime 6.3 and Q4.93 and notes SDM is disabled by default in AR 6. B&R recommends applying updates, restricting SDM access, using TLS/mutual TLS, and limiting webserver access to trusted IPs.
read more →