CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.
The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.
The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
The post Silent Patches Don’t Stop Attackers – They Blind Defenders appeared first on SecurityWeek.
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek.
More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024.
The post 91 Vulnerabilities Patched in Spring Application Framework appeared first on SecurityWeek.
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification.
The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek.
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.
The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
The post Microsoft Patches Exploited Entra ID Vulnerability appeared first on SecurityWeek.
The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.
The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek.
Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.
The post Hackers Target Zimbra Servers in Active Exploitation Campaign appeared first on SecurityWeek.