Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.
The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.
The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.
The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.
Administrators are advised to check their deployments for newly created user accounts they don’t recognize.
The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.
The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek.
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.
The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek.
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek.