< ciso
brief />
Tag Banner

All news with #vulnerability disclosure tag

648 articles · page 4 of 33

AI-assisted exploit yields local Linux root escalation

🔒 STAR Labs published a local privilege-escalation exploit for CentOS Stream 9 that abuses a use-after-free race in the kernel traffic-control subsystem (CVE-2026-53264, CVSS 7.8). Researcher Lee Jia Jie says AI aided discovery and exploit development; the exploit requires specific kernel options, unprivileged user namespaces, and a kernel-specific ROP chain. Upstream fixes landed June 1, 2026 and have been backported to multiple stable branches, but distribution coverage remains uneven.
read more →

Public exploit targets vBulletin template engine

🔒 SSD Secure Disclosure published a proof-of-concept on July 27 showing an unauthenticated request can reach PHP's eval() in vBulletin templates and execute code on unpatched forums. vBulletin released fixes (6.2.2 and patches for branches) on July 1, and Cloud instances are reported patched, but self-hosted sites running affected versions remain at risk. The disclosed exploit contained a trivial one-character typo that prevents it running unchanged; the underlying vulnerability, identified as CVE-2026-61511 by SSD, enables pre-auth remote code execution via ajax/render/pagenav template rendering.
read more →

Certighost flaw in AD CS lets attackers spoof DCs

🛡️ Researchers disclosed "Certighost," a vulnerability in Microsoft Active Directory Certificate Services (AD CS) that lets a low‑privilege domain user trick the CA into issuing certificates impersonating a Domain Controller. The issue abuses a directory-object resolution fallback called a "chase," where attacker-controlled identity data supplied via attributes like cdc can be used by the CA during issuance. Microsoft patched the flaw in its July 2026 updates and researchers provided a temporary policy-based mitigation for environments that cannot immediately install the patch.
read more →

GitLab RCE exploit published for unpatched instances

🛡️ Security researcher depthfirst published a working exploit on July 24 for a GitLab flaw patched by GitLab on June 10, enabling command execution as the git user on self-managed 18.11.3 servers that haven't updated. The chain abuses two memory-corruption bugs in the Oj Ruby JSON parser via GitLab's notebook diff renderer, allowing authenticated users who can push a project to leak a heap pointer and trigger a payload without admin or CI access. GitLab listed the Oj 3.17.3 bump under bug fixes rather than as a security fix, leaving operators unaware of the urgency; no CVE or CVSS score has been published yet.
read more →

Critical AgentForger Flaw in ChatGPT Workspace Agents

🛡️ Cybersecurity researchers disclosed a critical vulnerability, codenamed AgentForger, in OpenAI's ChatGPT Workspace Agents that allowed a single phishing link to create, authorize, and deploy an autonomous AI agent inside a victim's organization. The flaw—an instance of cross-site request forgery—let an attacker embed an executable prompt in a URL that auto-executes when clicked by an authenticated user with Workspace Agents and connectors. OpenAI patched the issue on June 8, 2026, and has deprecated the Agent Builder, urging a migration to the Agents SDK.
read more →

NodeBB fixes eight AI-discovered security flaws

🔒 Aikido Security's AI pentest agents found eight high-severity vulnerabilities in NodeBB, affecting every version before 4.14.0; NodeBB has issued patches and administrators should upgrade to 4.14.2. The issues ranged from a settings-based elevation that opened the admin dashboard to ordinary members, to unauthenticated access to private messages and categories, to a page-rendering flaw enabling injected links that execute code. Five flaws lived in federation code connecting forums to the fediverse, and several fixes were deployed piecemeal between May and July, with 4.14.0 rebuilding page text handling.
read more →

RefluXFS Linux flaw allows local persistent root

🛡️Qualys disclosed RefluXFS (CVE-2026-64600), a Linux kernel race in XFS reflink handling that lets an unprivileged local user overwrite root-owned files and achieve persistent root access. The bug dates to Linux 4.11 (2017) and affects systems with reflink-enabled XFS filesystems; default installs of several RHEL-derived distributions, Fedora Server, and Amazon Linux can be vulnerable. A patch was merged July 16 and vendors began shipping backports; apply updates and reboot to ensure protection.
read more →

Oracle July 2026 Critical Patch Update Overview

🛡️ Oracle’s July 2026 Critical Patch Update is its largest ever, delivering 1,449 fixes across 32 product families, including Database, Fusion Middleware, Java SE, and GoldenGate. Fusion Middleware saw 355 vulnerabilities, 219 exploitable remotely without authentication, and ten scored a CVSS 10.0. Database Server received critical fixes including CVE-2026-61211 (CVSS 9.9) in DBMS_CLOUD and an Oracle Net Services flaw, with additional OpenSSL-related patches. Experts urge rapid triage based on exposure and business impact as the sheer volume outpaces typical patching workflows.
read more →

Ubuntu snap-confine local root escalation advisory

🛡️ Cybersecurity researchers disclosed a high-severity local privilege escalation in snap-confine (CVE-2026-8933, CVSS 7.8) affecting default Ubuntu Desktop installs of 24.04, 25.10, and 26.04. The flaw arises from a race condition introduced during sandbox initialization that lets an unprivileged user exploit temporary /tmp artifacts and symlinks to gain root. Vendors advise applying the latest snapd updates immediately to mitigate the risk.
read more →

Adobe Acrobat Chrome Extension UXSS Flaw Exposes Data

🛡️ Researchers disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) affecting versions up to 26.5.2.2. Tracked as CVE-2026-48294 and dubbed HermeticReader by Guardio Labs, the UXSS-class issue (CVSS 7.4) allowed cross-origin read access to session-bound data after simple user interaction. Exploitation required visiting a crafted page that triggers the extension's vulnerable code path, enabling attackers to extract WhatsApp Web content without credentials or malware.
read more →

Active exploitation of Windmill path traversal bug

🛡️ A high-severity path traversal flaw in open-source developer platform Windmill (CVE-2026-29059, CVSS 7.5) has been observed exploited in the wild to read arbitrary files via the get_log_file endpoint. The issue allowed attackers to access sensitive files such as /etc/passwd and, where configured, the SUPERADMIN_SECRET value, enabling superadmin access. Windmill patched the vulnerability in version 1.603.3 by adding filename sanitization; about 170 vulnerable systems across 24 countries were identified.
read more →

Ubuntu snap-confine local root escalation CVE

🔒 A high-severity vulnerability in Ubuntu's snap-confine component (CVE-2026-8933) lets any local user gain full root on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. Qualys TRU published research on July 21 showing two race conditions introduced after a hardening change to set-capabilities; attackers can exploit a brief ownership window via FUSE mounts and symlinks, then bypass AppArmor to execute commands as root. Canonical has issued patches and admins are urged to update snapd immediately.
read more →

Apple fixes Hide My Email unmasking vulnerability

🔒 Apple patched a vulnerability in its Hide My Email service that could reveal users' real email addresses when forwarded messages were rejected as spam. The fix was deployed on July 3, 2026, after the flaw was disclosed to Apple by Tyler Murphy of EasyOptOuts on June 13, 2025. The issue allowed real addresses to appear in mail transfer logs and affected addresses created before July 7, 2026. Apple now says the problem is resolved, even as a class action alleges misleading privacy claims.
read more →

Critical nginx heap overflow allows remote crashes

🛡️ F5 released patches for a critical nginx heap buffer overflow (CVE-2026-42533) that can crash or restart worker processes and, in some environments, enable remote code execution. Fixed versions are nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1; systems on earlier releases should upgrade. The flaw occurs in the nginx script engine when a regex-based map's output variable is used in a string expression after an earlier regex capture, causing a two-pass evaluation mismatch that leads to overruns. F5 scores the flaw 9.2 (CVSS v4) and notes exposure depends on configuration rather than version alone.
read more →

7‑Zip patch fixes XZ decompression RCE risk

🛡️ 7‑Zip 26.02 addresses a remote code execution vulnerability in XZ decompression that could allow attackers to run arbitrary code when users open specially crafted archives. The flaw, reported by researcher Landon Peng and noted by the Zero Day Initiative, appears to stem from insufficient checks on available output buffer space during XZ decompression. The update adds bounds checks to prevent heap-based buffer overflow. Users must update manually from 7-zip.org because the application lacks automatic updates.
read more →

OnlyFans creators help CISOs curb site abuse

🔒 Security researchers report that OnlyFans creators are using DMCA takedown rights and search engine mechanisms to disrupt scam networks that host stolen adult content on compromised government and university websites. These operations — called SEO parasites — route traffic from hijacked entry pages to monetized scam or malware sites. The takedowns not only remove illicit content from search results but also prompt site owners to investigate and remediate vulnerabilities.
read more →

Claude Chrome extension flaw lets malicious extensions act

🛡️ A vulnerability in Anthropic's Claude for Chrome extension can let a malicious extension simulate clicks to trigger nine predefined AI workflows. The issue, found by Ax Sharma of Manifold Security, stems from the extension failing to verify the browser's Event.isTrusted flag before executing tasks tied to page click handlers. A malicious extension with permissions on claude.ai could inject elements and fire synthetic clicks to abuse Claude's authenticated access to services like Gmail, Docs, Calendar, and Salesforce. Anthropic acknowledged the report and classified a related skipPermissions parameter as informational.
read more →

n8n token-exchange identity binding flaw fixed

🔒 n8n's Enterprise token-exchange feature matched incoming JWTs to local users using only the sub claim and ignored the iss value, allowing a valid token from one issuer to authenticate as a user belonging to another issuer. The bug (CVE-2026-59208) was fixed on June 24 and credited to GitHub user bearsyankees. It only affects Enterprise instances with token exchange enabled and trusting multiple issuers; the recommended mitigations are upgrade to 2.27.4/2.28.1+ or restrict trusted issuers.
read more →

CISA Guidance Urges Formal Coordinated Disclosure

🔒 CISA and four international cybersecurity agencies have issued joint guidance urging software vendors and online service providers to establish coordinated vulnerability disclosure (CVD) programs. The guidance outlines how to publish clear disclosure policies, maintain communication with researchers, and handle reports for software, hardware, and network products. It supports CISA’s Secure by Design initiative and emphasizes prioritization, exploitability-based assessment, and validating compensating controls when patches are unavailable.
read more →

Microsoft‑signed UEFI shims allow Secure Boot bypass

🛡️ ESET found 11 Microsoft-signed UEFI shim bootloaders (version 0.9 or earlier) contain vulnerabilities that enable Secure Boot bypass across many systems. These shims trust outdated second-stage loaders like older GRUB 2 builds, allowing unsigned kernels or bootkits to load even with Secure Boot enabled. Microsoft issued dbx revocations on June 9; Windows will update automatically and Linux users should fetch revocations via the Linux Vendor Firmware Service. ESET cautions defenders to follow protection guidance rather than rely on IoCs.
read more →