< ciso
brief />
Tag Banner

All news with #active exploitation tag

912 articles · page 3 of 46

CISA Alerts: Active Exploits in WSO2, Adobe, SharePoint

⚠️ CISA warns that multiple critical and high-severity vulnerabilities in WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS are being actively exploited. Two critical flaws—CVE-2026-5430 in WSO2 and CVE-2026-71362 in Adobe Commerce—were added to the Known Exploited Vulnerabilities catalog with federal mitigation deadlines. Agencies must patch or mitigate by the specified dates, and organizations are urged to prioritize these fixes.
read more →

Critical WordPress RCE CVE-2026-87902 Patch Alert

⚠️ A critical Remote Code Execution vulnerability, CVE-2026-87902, affects WordPress versions 4.7.0 through 7.1.1 and allows arbitrary PHP file inclusion leading to potential code execution. WordPress released patches on September 22 (latest recommended version 7.1.2 or newer), but exploit attempts were observed within hours. Site owners should update immediately and follow recommended hardening measures to complement the patch.
read more →

ShinyHunters renews PeopleSoft exploit campaign

🔍 Mandiant and Google Threat Intelligence Group (GTIG) report that UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft by URL-encoding the vulnerable /PSEMHUB/ path to bypass WAF rules. The actor deployed web shells and a trojanized binary (Ple64.exe) loading the SIDEEYE backdoor, expanding targeting across education, technology, healthcare, government and more. Immediate patching, WAF normalization, and mitigation guidance are recommended.
read more →

WordPress critical RCE flaw patched; rapid attacks follow

🔒 WordPress released a security update fixing a critical remote code execution vulnerability (CVE-2026-87902) that allows unauthenticated attackers to include and execute readable local PHP files outside active theme directories. The flaw, reported by researcher Robert Ressl, has been backported to versions as far back as 4.7 and has already seen exploitation in the wild. Security firms observed reconnaissance within hours and active payload delivery within a day, prompting urgent calls for fast, verified patch rollouts and increased visibility of forgotten WordPress instances.
read more →

Critical VeloCloud Orchestrator vulnerability impacts on-prem

🔒 Arista warned of a critical flaw in on-premises VeloCloud Orchestrator that allows remote attackers to access privileged internal functionality and potentially compromise the VSO host. The issue, tracked as CVE-2026-93952 with a CVSS score of 10.0, is actively exploited and affects multiple VCO release trains, though fixes are available only for some versions. Arista recommends immediate upgrades where patches exist and, for those that cannot upgrade, restricting web interface access and monitoring for suspicious indicators of compromise.
read more →

Critical Roundcube flaw now actively exploited

🔒 A high-severity vulnerability in Roundcube Webmail patched in May (CVE-2026-48842) is now being actively exploited, the Canadian Centre for Cyber Security warns. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that can allow unauthenticated attackers to execute database commands and steal data. Administrators are urged to update to versions 1.6.16 or 1.7.1 or disable the plugin if they cannot patch immediately.
read more →

Check Point warns of Security Gateway VPN RCE exploit

🔒 Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling of its Security Gateway product, and warned of active abuse of CVE-2026-93616 affecting the Management web service. The company reported attacks beginning September 12, 2026, originating from anonymization services, and advised administrators to apply LivePatch Take 26 or specified Jumbo Hotfixes, update Spark firewalls, and follow temporary VPN rule restrictions if updates are not possible.
read more →

Critical WordPress flaw exploited for remote code execution

🔍 Threat actors have progressed from scanning for CVE-2026-87902 to actively exploiting the vulnerability to write files that execute shell commands when accessed. Patchstack observed initial reconnaissance less than five hours after WordPress 7.1.2 was released, with malicious activity increasing tenfold as attackers began delivering payloads. The flaw, discovered by Robert Ressl, is an unauthenticated path traversal that can lead to RCE under specific theme and server conditions. Administrators are urged to update to WordPress 7.1.2 and review logs for indicators of compromise.
read more →

InfraTrust report: Management systems under attack

🛡️ The September InfraTrust Pulse warns attackers are increasingly targeting infrastructure management systems across vendors, with many critical flaws exploited before or soon after disclosure. Between Aug 25 and Sep 17, InfraTrust tracked 158 advisories covering 1,699 vulnerabilities, including 42 critical and several with CVSS 10.0. The report highlights chained exploits against Cisco FMC and ISE, active exploitation of SonicWall and Check Point flaws, and supply-chain and firmware weaknesses.
read more →

Arista issues patch for actively exploited VCO zero‑day

🔒 Arista Networks has released patches for a critical zero-day (CVE-2026-93952) actively exploited in VeloCloud Orchestrator (VCO) On‑Prem deployments. The flaw, caused by improper input validation when certificate-based Edge-to‑VCO authentication is configured, allows remote attackers to access privileged host functionality without credentials or user interaction. Arista and CISA have both flagged the issue and recommended immediate mitigation and log review.
read more →

Exploit for unpatched Ubuntu kernel container escape

🔍 A use-after-free bug in the Linux kernel's AF_UNIX socket garbage collector (CVE-2026-80521) can be abused to escape containers and gain host root, DepthFirst reported on September 22. The flaw was fixed upstream on August 6, but Ubuntu has not yet shipped patches for 26.04, 24.04, or 22.04 LTS; DepthFirst released exploit code targeting Ubuntu 26.04. The vulnerability is reachable from containers because AF_UNIX is allowed by default in common Docker and Kubernetes seccomp profiles, and no distro workaround has been published.
read more →

Microsoft disruption exposes AI-driven phishing-as-a-service

🔎 Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.
read more →

Check Point warns of critical management server flaw

🔒 Check Point disclosed a critical management server vulnerability, CVE-2026-93616, exploited in targeted attacks on July 23 that allows unauthenticated web service access to run scripts. A patch was released on September 22 for affected Security Management Server versions; administrators should verify releases and install the fix in support article sk1000171. Separately, attempts to exploit a VPN certificate flaw, CVE-2026-85102, have targeted Spark firewalls since September 12 despite fixes issued on September 9. Check Point published mitigation and hunting guidance including indicators of compromise for both issues.
read more →

Critical Bifrost AI gateway flaw allows remote code

🛡️ A critical vulnerability in Bifrost, an open-source AI gateway, lets unauthenticated attackers execute arbitrary commands on the gateway server via a single HTTP request when management authentication is disabled. Tracked as CVE-2026-90898 (CVSS 9.8), the flaw affects HTTP transports before transports/v2.1.0 and is exploitable by registering a stdio-type MCP client through the management API; a fix is available in v2.1.0. Operators should upgrade, enable management auth, and rotate exposed keys if the management API was reachable.
read more →

Check Point issues hotfix for critical management server zero‑day

🛡️ Check Point Software issued emergency hotfixes for a critical Security Management Server vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts via a path traversal flaw tracked as CVE-2026-93616. The company confirmed active exploitation against a small number of customers and published indicators of compromise and temporary mitigations for those who cannot immediately patch. The fix is included in the R82.20 Security Hotfix and applies to Management, Log, Multi‑Domain, and SmartEvent products.
read more →

Active exploitation of two high‑severity Check Point flaws

🔒 Check Point Research reports active exploitation of two critical vulnerabilities affecting Security Gateway and Security Management. CVE-2026-85102 (RCE during VPN certificate handling) had patches available since September 9 and is being actively probed; unpatched Spark customers are at risk. CVE-2026-93616 is a newly observed pre-authentication path traversal zero-day in Management; a fix is available now. Customers should install vendor fixes immediately and follow published mitigation and hunting guidance.
read more →

D-Link warns of critical zero-day in DIR-822A routers

🔒 D-Link disclosed a max-severity zero-day affecting DIR-822A routers that stems from a stack-based buffer overflow in the DHCP server component and can be exploited without authentication. Attackers on the same local network can send crafted DHCP packets to crash the DHCP daemon or achieve remote code execution. The vendor noted a public proof-of-concept exploit and is investigating a second public PoC for an L2TP parser out-of-bounds write.
read more →

Critical CVE-2026-93952 in VeloCloud Orchestrator

🛡️ Arista disclosed CVE-2026-93952, a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) that can allow a remote attacker with no login to privilege internal functions on orchestrators configured for certificate-based Edge authentication. Fixed releases are available for the 5.2 and 6.4 trains and for Hosted and Dedicated VCOs; 6.1 and 7.0 fixes are pending. Arista rated the flaw CVSS 3.1 10.0 and said it was discovered externally and is actively exploited.
read more →

WordPress Comment2Shell vulnerability patched

🛡️ WordPress fixed a critical flaw, CVE-2026-93485 dubbed Comment2Shell, on September 17 in version 7.1.1 after a researcher showed how a crafted comment could plant a hidden script that executes when a page is viewed. The bug allowed that script to act with the viewer's privileges and, if an administrator viewed the page, to leverage the admin session to upload a plugin web shell. Site owners are urged to update immediately or temporarily disable comments and consider WAF or security plugin mitigations.
read more →

Zyxel and Veeam Flaws Under Active Exploitation

🛡️ CISA added a now-patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273, CVSS 8.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The stack-based buffer overflow in the device CGI could permit unauthenticated LAN attackers to execute OS commands; multiple GS1900 firmware versions have fixes. Simultaneously, Arctic Wolf reported active exploitation of a local privilege escalation in Veeam Agent for Windows (CVE-2026-32996, CVSS 7.3) allowing local users to attain SYSTEM privileges via a cached elevated session UID.
read more →