< ciso
brief />
Tag Banner

All news with #active exploitation tag

914 articles · page 4 of 46

WordPress Comment2Shell vulnerability patched

🛡️ WordPress fixed a critical flaw, CVE-2026-93485 dubbed Comment2Shell, on September 17 in version 7.1.1 after a researcher showed how a crafted comment could plant a hidden script that executes when a page is viewed. The bug allowed that script to act with the viewer's privileges and, if an administrator viewed the page, to leverage the admin session to upload a plugin web shell. Site owners are urged to update immediately or temporarily disable comments and consider WAF or security plugin mitigations.
read more →

Zyxel and Veeam Flaws Under Active Exploitation

🛡️ CISA added a now-patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273, CVSS 8.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The stack-based buffer overflow in the device CGI could permit unauthenticated LAN attackers to execute OS commands; multiple GS1900 firmware versions have fixes. Simultaneously, Arctic Wolf reported active exploitation of a local privilege escalation in Veeam Agent for Windows (CVE-2026-32996, CVSS 7.3) allowing local users to attain SYSTEM privileges via a cached elevated session UID.
read more →

WordPress Click2Shell flaw enables remote PHP execution

🛡️ A newly disclosed WordPress CSRF vulnerability named Click2Shell allows pre-authenticated remote code execution by forcing the installation of a theme from the WordPress.org catalog and running arbitrary PHP. The issue, fixed in WordPress 7.1.1, was reported by researcher Paulos Yibelo of pwn.ai and relies on a buggy interpretation of a theme-preview URL combined with JavaScript in the admin browser. An attacker needs no account but requires a logged-in administrator to visit a crafted link, enabling server-side code execution and potential data or file theft. Patchstack notes only administrators can trigger the chain and advises updating or enabling DISALLOW_FILE_MODS as a temporary mitigation.
read more →

Critical Pre‑Auth RCE in Orkes Conductor Actively Exploited

🛡️ Fortinet and other telemetries report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution flaw in Orkes Conductor. The vulnerability affects versions 3.21.21 through 3.30.1 and allows attackers to execute arbitrary OS commands by submitting crafted workflow definitions containing JavaScript or Python expressions to the workflow API. Exploits leverage unsandboxed GraalVM evaluators with unrestricted host access, and multiple vendors have observed in-the-wild attempts. Users are urged to upgrade to Conductor 3.30.2 or later and apply network mitigations if immediate patching is not possible.
read more →

CISA Adds Three Linux Kernel Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The flaws include high-severity issues in the TLS receive path, ebtables SNAT ARP rewrite, and an AF_ALG socket race condition, with CVSS scores of 9.8, 8.8, and 7.8 respectively. Red Hat updated advisories on September 19, 2026, urging immediate remediation, and FCEB agencies are recommended to patch by September 21, 2026 under BOD 26-04.
read more →

WordPress Click2Shell forced theme install patched

🔒 WordPress issued an urgent security patch (7.1.1) to address a vulnerability dubbed Click2Shell discovered by pwn.ai, which can cause a crafted link opened by a logged-in administrator to install an official WordPress.org theme without clicking Install. The core bug alone installs a legitimate theme, but chained with a separate theme flaw it can lead to remote code execution. Site operators should update immediately; affected branches back to 4.7 received fixes.
read more →

Critical Check Point Management Server Flaw Alert

🔒 A critical stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers can allow unauthenticated attackers to execute code as root over the network. Check Point issued a LivePatch fix and says it has no evidence of exploitation; customers with automatic updates enabled may already be protected. Administrators should apply sk1000155, confirm LivePatch installation, and limit Trusted Clients to known hosts while avoiding direct Internet exposure.
read more →

Cisco warns of active exploit for ISE API flaw

🔒 Cisco has warned of active exploitation of a critical vulnerability, CVE-2026-76460, in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw, rated 10.0 CVSS, stems from insufficient control on an API endpoint and can allow attackers to bypass the web-based management interface. Cisco released software updates and recommends using iACLs and log reviews while urging customers to upgrade immediately.
read more →

Cisco alerts on exploited ISE authentication bypass zero-day

🔒 Cisco has issued urgent updates for a maximum-severity Identity Services Engine vulnerability being actively exploited in the wild. The flaw (CVE-2026-76460) allows remote attackers to bypass authentication via a vulnerable API in Cisco ISE and ISE-PIC, enabling unauthorized access to the web-based management interface. Cisco PSIRT recommends immediate upgrades to fixed releases, and no workarounds are available.
read more →

Cisco warns of critical ISE authentication zero-day

🛡️ Cisco has disclosed a maximum-severity zero-day, CVE-2026-76460 (CVSS 10.0), in Identity Services Engine (ISE) and ISE-PIC that allows unauthenticated remote attackers to bypass authentication by exploiting an API endpoint. Cisco reports active exploitation and urges customers to upgrade to fixed patches for supported versions. There are no workarounds; recommended mitigations include iACLs and log review for suspicious usernames using the provided detection command.
read more →

Critical Issabel Framework JWT RCE Under Active Exploitation

🔒 A critical vuln, CVE-2026-89026, in the Issabel Framework allows unauthenticated remote attackers to execute OS commands by exploiting a hard-coded HS256 JWT signing key. The flaw enables forged bearer tokens to call the '/pbxapi/manager/originate' endpoint, triggering Asterisk to run arbitrary commands as the Asterisk user. A patch released on August 1, 2026, replaces the embedded key with a key in /etc/issabel.conf. Shadowserver reported active exploitation starting September 9, 2026; users should apply the update immediately.
read more →

Critical RCE in WooCommerce Wholesale Lead Capture

🛡️ Wordfence reports attackers uploading PHP webshells via a critical flaw in the premium WooCommerce Wholesale Lead Capture plugin. The vulnerability (CVE-2026-27540) was patched in version 2.0.3.2 on February 20, but exploitation attempts—over 100,000 blocked—continued months later. Site owners should update immediately, scan uploads directories, and check access logs for the vulnerable AJAX action.
read more →

Google patches Pixel modem flaw amid active exploitation

🔐 Google disclosed a high-severity privilege escalation flaw in its Pixel Cellular Modem, tracked as CVE-2026-58704 (CVSS 8.0), which may be under limited targeted exploitation. The NIST description notes a logic error enabling permission bypass and remote (proximal/adjacent) escalation without user interaction. September Pixel updates include fixes for this issue plus 109 other vulnerabilities; users should apply security patches dated 2026-09-05 or later via Settings > Security & privacy.
read more →

Acronis Patch Urged After cPanel Plugin Exploit

🔒 Acronis has disclosed a high-severity local privilege escalation flaw in its Backup plugin for cPanel and WHM, tracked as CVE-2026-87886 (CVSS 7.8), and confirmed it has been exploited in the wild. The issue stems from insecure file permissions and affects older builds of the cPanel & WHM (Linux) plugin and the Plesk extension; fixes are included in 1.9.3 HF3 for cPanel and in updated Plesk builds. Acronis urges immediate installation of the update; limited targeted attacks have been observed, though attribution and detailed attack objectives remain unknown.
read more →

Google issues September 2026 Pixel security updates

🔒 Google released September 2026 security patches for Pixel devices addressing 110 vulnerabilities, including one zero-day actively exploited in targeted attacks. The high-severity issue, CVE-2026-58704, is a modem component authorization flaw that can allow adjacent-network attackers with basic privileges to escalate privileges without user interaction. Pixel users should install the update via Settings and restart devices to complete the patch.
read more →

Critical RCE Flaw Exploited in WooCommerce Plugin

🔒 Wordfence has observed active exploitation of a critical vulnerability (CVE-2026-27540) in the premium WordPress plugin WooCommerce Wholesale Lead Capture, enabling unauthenticated attackers to upload arbitrary files and achieve remote code execution. The flaw affects versions up to 2.0.3.1 and has prompted over 100,000 blocked exploit attempts since June 2026. Site owners should inspect for unexpected .php files and suspicious admin-ajax requests referencing the "wwlc_file_upload_handler" action.
read more →

Critical WSO2 JWT Flaw Under Active Exploitation

⚠️ WSO2 users face active exploitation of CVE-2026-5430, a critical JWT signature verification flaw that enables account takeover. Affected products include API Manager, API Control Plane, Traffic Manager, and Universal Gateway across several 4.x releases; fixes and update levels have been published. WatchTowr reports in-the-wild attempts capturing forged admin JWTs on September 13, 2026, and urges immediate patching to prevent unauthorized access and lateral movement.
read more →

Critical WooCommerce Plugin Flaw Enables PHP Webshells

🔒 Hackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin (CVE-2026-27540) to upload PHP webshells and execute code on affected WordPress sites. The unauthenticated arbitrary file-upload flaw affects versions 2.0.3.1 and older and was fixed in version 2.0.3.2 released February 20. Wordfence blocked over 100,000 related attacks and urges administrators to update, scan for unexpected PHP files, check logs for wwlc_file_upload_handler requests, and restore from clean backups if compromised.
read more →

Exposed Vite servers probed for cloud credentials

🔎 Attackers have begun probing exposed Vite development servers for sensitive data, including AWS and Azure credentials, environment files, and infrastructure state. F5 Labs observed over 32,000 scan attempts in August exploiting a file-access bypass (CVE-2026-39364) that defeats Vite's deny-list protections when specific query parameters are used. F5 urges patching Vite, rotating secrets, and ensuring development servers are not bound to external interfaces.
read more →

Critical Cisco Secure Email Gateway zero-day exploited

📣 Cisco warned customers of an actively exploited zero-day in Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The flaw stems from insufficient validation in email parsing and malicious SQL in crafted messages. Cisco released patches and IOC guidance, while CISA added CVE-2026-76461 to its KEV Catalog, ordering federal fixes within three days.
read more →