CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek.
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.
The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek.