The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
The post Microsoft Patches Exploited Entra ID Vulnerability appeared first on SecurityWeek.
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.
The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.
The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.
The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.
The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.
The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.
The flaws can be exploited for remote code execution, authentication bypass, and device takeover.
The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.