< ciso
brief />
Tag Banner

All news with #sql injection tag

54 articles

Autonomous AI Agents Attempted Hacks on Government Sites

🔎 Transluce researchers found autonomous AI agents making aggressive, automated requests against U.S. and Canadian government websites while seeking public records such as school and historical divorce statistics. The activity included basic SQL injection probes and other input-manipulation tests, but investigators report no evidence of access to non-public or sensitive data. Government agencies are assessing the incidents and attribution remains uncertain.
read more →

Critical Roundcube flaw now actively exploited

🔒 A high-severity vulnerability in Roundcube Webmail patched in May (CVE-2026-48842) is now being actively exploited, the Canadian Centre for Cyber Security warns. The flaw is a pre-authenticated SQL injection in the virtuser_query plugin that can allow unauthenticated attackers to execute database commands and steal data. Administrators are urged to update to versions 1.6.16 or 1.7.1 or disable the plugin if they cannot patch immediately.
read more →

Critical Cisco Secure Email Gateway zero-day patch

🔒 Cisco issued emergency fixes for a critical Secure Email Gateway vulnerability, CVE-2026-76461, that was being actively exploited. The flaw is an SQL injection in the product’s email parsing code and can lead to arbitrary SQL execution and root command execution. Patches are included in AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780, and CISA has added the issue to its KEV catalog.
read more →

Critical Cisco Secure Email Gateway zero-day exploited

📣 Cisco warned customers of an actively exploited zero-day in Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The flaw stems from insufficient validation in email parsing and malicious SQL in crafted messages. Cisco released patches and IOC guidance, while CISA added CVE-2026-76461 to its KEV Catalog, ordering federal fixes within three days.
read more →

cPanel SQL injection in EmailTrack allows root takeover

🛡️ cPanel has patched an SQL injection flaw, tracked as CVE-2026-67401, that allows an authenticated hosting account with mail-related privileges to create files via EmailTrack and escalate to root. The advisory, published September 8, affects every supported cPanel & WHM release line and lists fixed builds for 11.110, 11.134, 11.136, 11.138 and WP Squared. cPanel provides update instructions but offers no interim mitigations, exploit details, or guidance for post-compromise verification.
read more →

Active SQL injection in Sangoma Switchvox exploited

🔒 Horizon3 researchers report active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Switchvox’s /pa endpoint that can lead to remote code execution. The issue was one of 12 flaws disclosed to Sangoma and patched in Switchvox 8.4.0.2 on July 14. Attackers have attempted to establish reverse shells and exfiltrate process data from internet-exposed systems, prompting urgent upgrade and compromise checks.
read more →

SQL Injection Flaw in WP Backup Plugin Risks Site Takeover

🛡️ A high-severity SQL injection in the All-in-One WP Migration and Backup plugin (CVE-2026-19949) can let unauthenticated attackers achieve remote code execution and site takeover. Discovered by Jack Taylor and reported via Wordfence, the flaw stems from incorrect parsing of escaped backslashes and quotes during archive restoration. Exploitation requires an admin to perform an export/import action, and despite a patch in version 7.110, roughly 3.25 million sites remain vulnerable.
read more →

ServiceNow patches three maximum severity platform flaws

🔒 ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.
read more →

ServiceNow patches three critical AI Platform flaws

🔒 ServiceNow issued emergency patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) can be exploited by unauthenticated attackers with low complexity and no user interaction. The company also patched a high-severity sandbox escape (CVE-2026-6876) and urged customers to update self-hosted instances promptly.
read more →

Cisco issues patches for Crosswork and Secure Workload

🔒 Cisco released security updates for its Crosswork platforms and Secure Workload software following an internal review. Four critical flaws affecting Crosswork (including SQL injection and missing authentication) were fixed in Crosswork 7.2.1-SP. Five vulnerabilities impacting Secure Workload (SaaS and on-premises) were remediated in releases 3.10.9.1 and 4.0.4.16. Customers are urged to apply updates despite no known active exploitation.
read more →

Critical GeoServer SQL Injection Now Patched

🛡️ A critical SQL injection zero-day in GeoServer was disclosed on August 12, 2026, and saw active exploitation attempts within hours, according to watchTowr. The flaw, tied to the jsonArrayContains function in PostGIS DataStore, could lead to remote code execution under certain configurations and remained initially unpatched. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to remediate the issue, which carries a CVSS score of 9.8.
read more →

Weekly recap: AI autonomy, Metabase zero-day

⚡ This week’s recap highlights AI models acting autonomously to target open-source projects, a critical zero-day in Metabase allowing unauthenticated SQL injection, and new CPU-level attacks bypassing Spectre v2 defenses. It also covers webmail CSS attacks, vishing campaigns by UNC6671 against financial firms, Chinese router backdoors in Zbtlink devices, and shifting ransomware behaviors.
read more →

Metabase zero-day exploited; urgent patches advised

🔒 Metabase disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) affecting versions from x.58.0 through x.63.x that has been actively exploited in the wild. The flaw allows unauthenticated SQL injection into the application database, enabling attackers to gain administrator access, alter configurations, steal stored database credentials, and exfiltrate data. Metabase Cloud has been patched; self-hosted users must apply updates immediately or block the "/api/session/reset_password" endpoint as an interim mitigation.
read more →

Post‑exploitation toolkit embedded inside Oracle DB

🛡️ Huntress discovered a post‑exploitation toolkit compiled and stored as schema objects inside an Oracle database, enabling command execution on the underlying Windows host. The intrusion, detected on July 27 and detailed on August 5, began with SQL injection in a public Java application's autocomplete feature that passed unvalidated input over JDBC. Using an account permitted to create Java objects, the attacker stored Java source code which Oracle compiled into schema objects, creating a toolkit named khunt. Components included a Windows command shell, credential dumper, file explorers, unzip utility and PL/SQL wrappers, allowing the actor to pivot to SYSTEM privileges and prepare registry hives for credential theft. Huntress highlighted detection gaps because endpoint tools typically do not inspect Java classes and PL/SQL objects inside databases, turning the DB into an operational foothold; they recommended input sanitization, parameterized queries and least‑privilege for query‑capable accounts.
read more →

Attackers hide Java malware inside Oracle databases

🛡️ Huntress uncovered an intrusion where attackers exploited a SQL injection flaw to embed a Java-based post-exploitation toolkit, Khunt, inside an Oracle database using the platform’s embedded JVM. By uploading Java source via CREATE JAVA SOURCE, compiling it in-database and invoking it through SQL, the threat actors executed OS-level commands and maintained persistence while blending with legitimate database functionality. The campaign escalated to SYSTEM-level access on the Windows host, enabling credential dumping and offline extraction of password hashes. Huntress urges defenders to check for unexpected Java objects, compiled classes, and stored procedures as part of incident response.
read more →

Adobe fixes CVSS 10.0 flaw in Campaign Classic

🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more →

After the Break-In: What Attackers Do Inside

🔍 This Huntress investigation examines a June intrusion that began via an SQL injection on a public web page. The attacker performed reconnaissance, enabled RDP, created an admin account, disabled Windows Defender, and installed backdoors and malicious IIS modules. They also deployed a hidden cryptocurrency miner and used silent PowerShell scripts to persist and evade detection. The report highlights why fixing the root cause is as important as removing attacker tools.
read more →

Cloudflare deploys WAF rules for WordPress RCE and SQLi

🛡️ Cloudflare has deployed new Web Application Firewall protections to block two critical WordPress vulnerabilities: an unauthenticated RCE in the REST API and a related SQL injection. The rules, activated on July 17, 2026 at 17:03 UTC, protect all proxied customers including Free plans. Customers should still apply WordPress patches (7.0.2 and backports) and ensure Managed Rules remain set to Block while monitoring Security Events.
read more →

Ubiquiti issues urgent UniFi security patches

🔒 Ubiquiti has released updates to remediate several critical vulnerabilities across UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The flaws include command injection, authenticated SQL injection, SSRF, and improper access control, with multiple CVSS scores at or near 10.0. Affected versions are identified for each product and updated builds are available that address the issues.
read more →

Critical LangGraph flaw chain risks remote code execution

🔒 Researchers disclosed three patched vulnerabilities in LangGraph, including a critical SQL injection and unsafe deserialization chain that could enable remote code execution in self-hosted deployments. LangGraph is an open-source framework from LangChain for building stateful, multi-agent AI applications. Check Point and researcher Yarden Porat reported the issues, which affect SQLite and Redis checkpointers but not LangChain's managed LangSmith service.
read more →