< ciso
brief />
Tag Banner

All news with #vulnerability disclosure tag

648 articles · page 6 of 33

Bad Epoll kernel flaw lets local users become root

🛡️ A newly disclosed Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows an ordinary local user to escalate privileges to root and affects Linux desktops, servers, and Android. The flaw is a use-after-free race in the epoll subsystem; the timing window is tiny but an exploit by researcher Jaeyoung Chung widens it and succeeds reliably. A fix is available upstream (commit a6dc643c6931) and distributions should backport it; kernels built on 6.4+ are affected unless patched.
read more →

Researcher Publishes Mass Open-Source Exploit Dump

🔍 A pseudonymous researcher published an 'Exploitarium' GitHub repository containing over 30 proof-of-concept exploits for zero-day vulnerabilities in many open-source projects without prior vendor notification. The dump, shared from June 27 onwards, targets projects like libssh2, FFmpeg, 7-Zip, Gitea, PHP and others, and the author claims AI-assisted fuzzing using OpenAI models. The release bypassed coordinated vulnerability disclosure, drew debate across the security community, and has led to some CVEs and patches, while others remain under review.
read more →

Argo CD flaw highlights GitOps as tier-zero risk

🔒 A critical vulnerability in Argo CD repo-server exposes risks inherent to GitOps platforms. Synacktiv found the unauthenticated GenerateManifest gRPC endpoint can be abused via Kustomize/Helm options to execute commands if an attacker can reach both the repo-server and Redis ports. The issue affects typical Helm deployments where Kubernetes network policies are not enabled by default, enabling lateral movement from a compromised pod. Synacktiv disclosed details July 1, 2026 and recommends strict network segmentation until a patch is available.
read more →

Critical Cursor sandbox escape bugs demand urgent patch

🛡️ Two high-severity flaws in the Cursor AI code editor allow a crafted prompt to escape the editor's sandbox and execute arbitrary commands on a developer's machine without any user interaction. Discovered by Cato AI Labs as DuneSlide and tracked as CVE-2026-50548 and CVE-2026-50549 (both rated 9.8), the issues are patched in Cursor 3.0 released April 2; versions before 3.0 are affected. The vulnerabilities exploit how Cursor handles a tool parameter and symlink resolution to cause writes that disable the sandbox, enabling full code execution as the user.
read more →

Over 900 Oracle E-Business instances exposed online

🔒 Over 900 Oracle E-Business Suite (EBS) instances were found exposed online amid active attacks exploiting a critical File Transmission flaw in Oracle Payments (CVE-2026-46817). The vulnerability permits unauthenticated HTTP takeover, and Oracle released patches in its May 2026 Critical Security Patch Update, urging immediate remediation. Threat intelligence firm Defused reported active exploitation observed on honeypots, while Shadowserver noted roughly 950 exposed instances and the extent of patching remains unclear.
read more →

Citrix issues patches for six NetScaler vulnerabilities

🔒 Citrix released security updates to address six vulnerabilities in NetScaler ADC and NetScaler Gateway that could allow arbitrary file reads or trigger denial-of-service conditions. The flaws include memory overread/overflow issues and an external control of file name vulnerability, each with CVSS scores ranging from 6.9 to 8.8. Fixed builds are available for 14.1 and 13.1 branches, with additional configuration changes required for one HTTP/2 issue. Citrix credited multiple external researchers and said there is no evidence of in-the-wild exploitation.
read more →

AirDrop and Quick Share weaknesses disrupt sharing

🔒 Two researchers disclosed six vulnerabilities in AirDrop and Quick Share that let a nearby attacker crash or manipulate file‑sharing sessions. The issues impact Apple and Samsung implementations and include a stack overflow in Apple's XML plist parser and a Windows memory bug in Google's Quick Share app. Apple, Google, and Samsung have begun issuing fixes and coordinating disclosures; users should update and restrict visibility settings.
read more →

DirtyClone Linux kernel flaw enables local root

🛡️ JFrog Security Research published a working exploit for DirtyClone (CVE-2026-43503) on June 25, demonstrating a local privilege escalation in the DirtyFrag family. The flaw lets a local user corrupt file-backed memory via cloned network packets to gain root; the upstream patch landed in mainline on May 21. Exploitation requires CAP_NET_ADMIN to configure an IPsec tunnel, and unprivileged user namespaces on Debian and Fedora enable the default attack path. Ubuntu 24.04+ mitigates the default vector via AppArmor restrictions.
read more →

CISA warns of critical Ubiquiti and Lantronix flaws

🔒 CISA has added four high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog, including three Ubiquiti UniFi OS flaws and a Lantronix EDS5000 command injection. The agency's BOD 26-04 requires federal agencies to apply fixes or mitigations within three days. Vendors have released patches and detection guidance, and researchers provided proof-of-concept chaining and a detection script to help defenders identify affected devices.
read more →

Critical FFmpeg MagicYUV Flaw Demands SBOM Focus

🔒 A critical heap out-of-bounds write in the MagicYUV decoder of FFmpeg (CVE-2026-8461), dubbed PixelSmash, can crash applications or enable remote code execution. Researchers at JFrog demonstrated full exploits against Jellyfin and Nextcloud by uploading crafted media files; any app using libavcodec is potentially affected. Users and vendors should upgrade to FFmpeg 8.1.2 or disable the MagicYUV decoder if unused.
read more →

FFmpeg patches PixelSmash MagicYUV vulnerability

🛡️ FFmpeg fixed a high-severity heap out-of-bounds flaw dubbed PixelSmash (CVE-2026-8461) in the MagicYUV decoder that can be triggered by crafted AVI, MKV, or MOV files. The bug allows denial-of-service in many media apps and can enable remote code execution in specific setups — for example, Jellyfin and Nextcloud instances — particularly if ASLR is disabled or chained with another vulnerability. FFmpeg 8.1.2 addresses the issue and vendors are updating or applying mitigations.
read more →

Unauthenticated info disclosure in Gravity SMTP plugin

🔒 Threat actors are exploiting an unauthenticated information-disclosure vulnerability in the WordPress plugin Gravity SMTP, present on about 100,000 sites. Tracked as CVE-2026-4020 and rated medium, the flaw affects versions 2.1.4 and older and was fixed in 2.1.5 (released March 17). Wordfence reports millions of blocked attempts and recommends admins patch and monitor requests to the exposed REST endpoint.
read more →

CISA Adds One Vulnerability to KEV Catalog

🔔 CISA added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. The alert underscores that such vulnerabilities are frequent attack vectors and pose significant risks to the federal enterprise. BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV-listed CVEs on internet-exposed assets and to check for compromise before patching. CISA encourages all organizations to adopt risk-based vulnerability management and to submit candidate vulnerabilities via the KEV Nomination Form.
read more →

Critical OIDC flaw lets attackers add SimpleHelp technicians

🔒 A critical vulnerability (CVE-2026-48558) in SimpleHelp allows unauthenticated actors to create privileged Technician accounts when OIDC authentication is enabled. Researchers at Horizon3.ai attribute the issue to improper validation of identity assertions from OIDC identity providers. The vendor released fixes in versions 5.5.16 and 6.0RC2 on June 9, and mitigations include IP allowlists and monitoring for suspicious technician registrations.
read more →

One-click Microsoft 365 Copilot SearchLeak flaw

🔎 Researchers at Varonis chained three bugs into a one-click exfiltration path dubbed SearchLeak that could have pulled emails, calendar entries, and indexed files from Microsoft 365 Copilot Enterprise Search. Because the malicious link used a legitimate microsoft.com domain, URL filters and anti-phishing tools were unlikely to block it. Microsoft assigned CVE-2026-42824, mitigated the issue on its backend, and Varonis released a proof-of-concept without observed exploitation.
read more →

CISA Adds Two Vulnerabilities to KEV Catalog

🔔 CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. The agency emphasizes these flaws are common attack vectors that present substantial risk to the federal enterprise. BOD 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk CVEs in the KEV catalog and to assess potential compromise before patching. CISA urges all organizations to adopt risk-based vulnerability management and to submit suspected exploited flaws via the KEV Nomination Form.
read more →

Critical LangGraph flaw chain risks remote code execution

🔒 Researchers disclosed three patched vulnerabilities in LangGraph, including a critical SQL injection and unsafe deserialization chain that could enable remote code execution in self-hosted deployments. LangGraph is an open-source framework from LangChain for building stateful, multi-agent AI applications. Check Point and researcher Yarden Porat reported the issues, which affect SQLite and Redis checkpointers but not LangChain's managed LangSmith service.
read more →

ServiceNow patches unauthenticated API exposure risk

🔒 ServiceNow notified customers after remediating a vulnerability that allowed an unauthenticated API endpoint to return tenant data under certain configurations. The issue, first reported via the vendor’s bug bounty program in April, prompted hosted updates on June 5 and guidance for self-hosted deployments. ServiceNow says affected instances were a subset of tenants and that observed activity appears linked to security researchers, though investigation continues. Customers are urged to apply updates and review logs for signs of unauthorized access.
read more →

CISA Adds One Vulnerability to KEV Catalog

🔔 CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog after observing active exploitation. The advisory reiterates that such vulnerabilities are frequent attack vectors and pose significant risks to the federal enterprise. It references BOD 26-04, which requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk CVEs listed in the KEV catalog and to assess for compromise prior to patching. CISA urges all organizations to adopt risk-based vulnerability management and offers a KEV Nomination Form for reporting exploited vulnerabilities.
read more →

Agentjacking: AI coding agents hijacked via Sentry flaw

🛡️ Researchers describe a new "agentjacking" attack that tricks AI coding agents into executing arbitrary code by injecting malicious instructions into Sentry error events. Tenet Security says the flaw leverages Sentry DSNs — public, write-only credentials — to post crafted markdown that appears as legitimate remediation guidance. Agents retrieving unresolved errors via MCP render the injected content as trusted and may execute the embedded commands with developer privileges. The report confirmed high exploitability across popular agents and thousands of exposed DSNs.
read more →