Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.
Intel has informed customers about several high-severity vulnerabilities that can lead to privilege escalation and even code execution.
The post Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined appeared first on SecurityWeek.
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek.
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek.
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.
The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek.
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.