CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal BleepingComputer Exploited in the wild SharePoint Server rce Microsoft

CISA warns admins to patch actively exploited SharePoint flaws

Read full story

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting three critical vulnerabilities in on-premises SharePoint Server deployments. These flaws—CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164—affect all supported self-hosted versions, including the latest Subscription Edition. Attackers are leveraging these issues to bypass authentication, execute arbitrary code remotely, and maintain persistence by deploying malware. CISA urges administrators to apply available patches immediately and implement additional hardening measures to reduce risk.

Earlier39 stories
Jul 15
SecurityWeek PoC Firefox web-app2 min read

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates

Google and Mozilla have issued urgent updates for Chrome 150 and Firefox 152 to address multiple high- and critical-severity vulnerabilities. Firefox 152.0.6 resolves two critical flaws—CVE-2026-15718 and CVE-2026-15719—with proof-of-concept exploits already made public. Chrome’s update addresses 15 total issues, including two critical use-after-free bugs in Ozone. Both companies urge users to upgrade immediately to avoid potential exploitation.

Jul 15
The Hacker News Exploited Secure Mobile Access (SMA) 1000 series appliances zero-day3 min read

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has confirmed that two unpatched vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances are being actively exploited. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, allow attackers to perform SSRF attacks and execute arbitrary commands with administrative privileges. These issues have already been targeted in real-world attacks, prompting urgent calls for users to update their systems. SonicWall recommends applying version 12.4.3-03453 or later to mitigate risks.

Jul 15
SecurityWeek Exploited SMA1000 secure remote access appliances zero-day2 min read

SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits

SonicWall has issued an urgent warning that two zero-day vulnerabilities are being actively exploited against its SMA1000 secure remote access appliances. The flaws, CVE-2026-15409 and CVE-2026-15410, affect specific versions and could allow attackers to perform SSRF attacks or execute arbitrary commands. Customers are advised to apply the latest hotfixes immediately to mitigate risk.

Jul 14
Ars Technica (Security) Research Windows zero-day8 min read

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now

Researchers at ESET have uncovered a critical flaw in Microsoft’s Secure Boot implementation, which has been vulnerable to bypass for over a decade due to unrevoked firmware 'shims' signed by the company. These shims, originally designed to support Linux and utility software, remain trusted despite known vulnerabilities and can be exploited to install malicious firmware on both Windows and Linux devices. The issue affects UEFI-based systems and highlights weaknesses in how Secure Boot is managed. Microsoft addressed the problem in its June 2026 update, but users are advised to verify their revocation status using tools like uefi-dbx-audit.

Jul 14
Dark Reading Exploited Active Directory Federation Services patch-tuesday7 min read

Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes

Microsoft issued its largest-ever Patch Tuesday update on July 14, 2026, addressing 622 unique CVEs across multiple products. Three of these are zero-day vulnerabilities currently being exploited in the wild, with two already under active attack. Among the top priorities are CVE-2026-56155 and CVE-2026-56164, both marked as exploited by CISA and affecting Active Directory Federation Services and SharePoint Server. Experts warn that the sheer volume of flaws—many with high CVSS scores—poses a major challenge for organizations to triage and patch effectively.

Jul 14
BleepingComputer Exploited SMA1000 Appliance zero-day3 min read

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall has issued a warning that two critical vulnerabilities in its SMA1000 Appliance are currently being exploited in real-world attacks. The flaws, identified as CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), enable remote attackers to perform server-side request forgery and execute arbitrary commands after authentication. These issues affect specific SMA1000 models running outdated firmware versions. SonicWall urges users to apply the latest hotfixes immediately to prevent potential breaches. CISA has also listed these vulnerabilities in its KEV catalog due to their active exploitation.

Jul 14
Qualys Security Blog Patch Windows patch-tuesday23 min read

Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review

Microsoft and Adobe have jointly released a major round of security patches as part of their July 2026 Patch Tuesday update cycle. These updates resolve over 570 vulnerabilities across a wide array of products, including Windows, Microsoft Edge, Microsoft Defender, Microsoft Exchange Server, and various Adobe applications like Animate, ColdFusion, and Illustrator. Among the patched issues are three zero-days, two of which were actively exploited in attacks. The scale and severity of these fixes underscore the importance of timely patching to prevent potential exploitation.

Jul 14
Cisco Talos Exploited Active Directory Federation Services (AD FS) rce13 min read

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

On July 14, 2026, Microsoft issued its monthly security update, addressing 622 vulnerabilities across multiple products, with 57 classified as 'critical.' Among these, two have already been exploited in the wild. The most notable include CVE-2026-56155, an elevation of privilege flaw in Active Directory Federation Services (AD FS), and CVE-2026-56164, a spoofing vulnerability in SharePoint Server. The update covers a wide range of services and applications, such as Windows DHCP Server, Microsoft Office, and Minecraft Bedrock Dedicated Server. Cisco Talos has also published new Snort rules to detect exploitation attempts.

Jul 14
The Hacker News Exploited SharePoint Server patch-tuesday8 min read

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft issued its largest-ever Patch Tuesday update, addressing 622 vulnerabilities, including two zero-day flaws currently being exploited in the wild. The most urgent fixes address CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Both allow privilege escalation and are already being used by attackers. These bugs were reported by incident response teams, indicating real-world exploitation. While neither is a high-severity remote code execution flaw, their impact on core enterprise infrastructure makes them critical to patch immediately.

Jul 14
Krebs on Security Exploited Windows patch-tuesday5 min read

Microsoft Patches a Record 570 Security Flaws

Microsoft has issued a record-breaking 570 security patches this month, addressing critical vulnerabilities in Windows, Active Directory Federation Services, SharePoint, BitLocker, and Copilot. Among these are three actively exploited zero-day flaws, including two elevation of privilege bugs such as CVE-2026-56155 and CVE-2026-56164. Nearly 60 of the patched issues were deemed 'critical' due to their potential for remote code execution or system takeover without user interaction. The surge in patch counts is attributed to AI-driven vulnerability discovery, prompting concerns about the need for updated exploitability assessments that account for AI's accelerating threat landscape.

Jul 14
SANS Internet Storm Center Exploited Windows privilege-escalation60 min read

Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here

Microsoft's July 2026 Patch Tuesday release covers a massive 622 vulnerabilities, with 62 classified as critical. Among these, two have already been exploited in the wild, while another has been publicly disclosed. The update affects multiple products including Windows, Azure, .NET, SharePoint, Edge, Active Directory, and DHCP Server. Notably, CVE-2026-56155 and CVE-2026-56164 are already being exploited, though they are rated as important or moderate in severity. Additionally, CVE-2026-54128, a critical remote code execution flaw in the Windows DHCP Client, could be leveraged via malicious networks, making it particularly relevant for public Wi-Fi environments. With such a high volume of patches, organizations are reminded that their patching process does not necessarily need to become significantly longer—many products remain consistent in scope despite the increased number of fixes.

Jul 14
SecurityWeek Exploited Active Directory zero-day3 min read

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft has issued a record number of security patches—622 total—during its July 2026 Patch Tuesday update cycle. Among these, two critical zero-day vulnerabilities were confirmed to be exploited in the wild. These include CVE-2026-56155 affecting Active Directory Federation Services and CVE-2026-56164 impacting SharePoint Server, both enabling privilege escalation attacks. Other notable issues addressed involve Windows VMSwitch, Remote Desktop Protocol, and Exchange Server. This extensive patch release highlights the growing pace of vulnerability discovery, driven in part by AI tools like Microsoft's MDASH.

Jul 14
The Hacker News Patch NetWeaver Application Server ABAP data-breach4 min read

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP has issued security updates for multiple high-severity vulnerabilities discovered in its products during the July 2026 patch cycle. Among them is CVE-2026-44747, a critical out-of-bounds write flaw in the SAP NetWeaver Application Server ABAP with a CVSS score of 9.9. This flaw could allow an authenticated attacker to manipulate memory and potentially gain unauthorized access to or modify sensitive data. Two additional critical issues were also resolved: a request smuggling vulnerability in SAP Approuter (CVE-2026-27690) and a default credentials issue in SAP Commerce Cloud (CVE-2026-44761). While no active exploitation has been reported, SAP urges users to apply the latest patches immediately to mitigate potential risks.

Jul 14
BleepingComputer Exploited .NET zero-day83 min read

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Microsoft has issued its July 2026 Patch Tuesday update, addressing a record-breaking 570 security vulnerabilities across multiple products, including three zero-day flaws—two of which are being actively exploited in attacks. The patched software includes .NET, Office, Windows, Edge, Azure services, Exchange Server, and SQL Server. Among the critical issues is a remotely exploitable flaw in SharePoint Server and an elevation-of-privilege vulnerability in Active Directory Federation Services. Organizations are strongly advised to apply these updates immediately to mitigate potential exploitation risks.

Jul 14
Help Net Security Exploited Secure Mobile Access (SMA) 1000 Series appliances zero-day3 min read

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)

SonicWall has addressed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) impacting its Secure Mobile Access (SMA) 1000 Series appliances. These flaws were being used together in real-world attacks, allowing unauthenticated attackers to trigger SSRF and authenticated users to execute arbitrary code. Customers are advised to apply the latest firmware updates and check for signs of compromise. SonicWall also recommends additional post-patch actions like password resets and TOTP token regeneration.

Jul 14
SecurityWeek Patch ColdFusion rce3 min read

Adobe Patches Critical ColdFusion Vulnerabilities

Adobe has issued security updates for 12 products to resolve 88 vulnerabilities, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. Among the 13 issues fixed in ColdFusion, eight are rated critical and could allow attackers to execute arbitrary code or escalate privileges. These include path traversal, code injection, and SQL injection vulnerabilities. Adobe recommends applying the latest updates immediately, particularly for ColdFusion 2025 update 11 and ColdFusion 2023 update 22. The company also addressed multiple high-severity issues in other software such as Commerce, Experience Manager, and Creative Cloud applications.

Jul 14
SecurityWeek Patch VMware Avi Load Balancer cloud2 min read

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

Broadcom has issued new updates for the VMware Avi Load Balancer to address seven severe vulnerabilities, including a critical authentication bypass flaw and multiple high-severity issues that could lead to privilege escalation or remote code execution. The flaws were reported by researchers Filip Waeytens and Lang Khuong Duy, who identified risks such as unauthorized access, arbitrary code execution, and directory traversal attacks. While no active exploitation has been observed, experts recommend applying the latest patches due to the potential risk posed by these vulnerabilities.

Jul 14
The Hacker News PoC RabbitMQ network-edge4 min read

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Researchers have revealed two critical access control flaws in RabbitMQ that could allow attackers to steal OAuth client secrets and bypass tenant isolation. The vulnerabilities, tracked as CVE-2026-57219 and CVE-2026-57221, were present since early 2024 and affect multiple versions of the message broker. Attackers could exploit these issues to gain administrative control or access cross-tenant metadata without proper authorization. Patches are available in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15.

Jul 14
The Hacker News Advisory UEFI Shim Bootloader ics-ot-iot7 min read

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Researchers have identified 11 outdated, Microsoft-signed UEFI applications that could be exploited to bypass Secure Boot protections on modern systems. These vulnerabilities affect various Linux distributions and bootloaders from vendors including Red Hat, Oracle, and OpenSUSE. Attackers could leverage these flaws to execute arbitrary code during system startup, potentially deploying persistent malware like UEFI bootkits. The issues were addressed in Microsoft's June 2026 Patch Tuesday update and are tracked under CVE-2026-8863 and CVE-2026-10797.

Jul 14
BleepingComputer Patch NetWeaver Application Server ABAP rce3 min read

SAP warns of critical flaws in NetWeaver and Commerce Cloud

SAP has issued security updates addressing 16 vulnerabilities, including three critical flaws affecting its NetWeaver Application Server ABAP, Approuter, and Commerce Cloud. These include a memory corruption issue (CVE-2026-44747), an HTTP request smuggling flaw (CVE-2026-27690), and a vulnerability due to default credentials (CVE-2026-44761). While no active exploitation has been observed, these flaws could allow unauthorized access, data manipulation, or service disruption. Users are advised to apply the latest patches immediately.

Jul 14
SecurityWeek Patch NetWeaver Application Server ABAP rce3 min read

SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud

SAP has issued urgent security updates to fix several high-risk vulnerabilities affecting its core enterprise platforms. Among the most severe is CVE-2026-44747, a memory corruption flaw in NetWeaver Application Server ABAP with a CVSS score of 9.9. Attackers could exploit this to manipulate data or disrupt services. A separate HTTP request smuggling vulnerability (CVE-2026-27690) impacts Approuter, allowing unauthenticated attackers to send malicious requests. Additionally, a hardcoded credential issue in Commerce Cloud (CVE-2026-44761) could enable unauthorized access if default configurations are left unchanged. SAP urges users to apply the latest patches immediately.

Jul 14
SecurityWeek Exploited routers Berserk Bear2 min read

US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

Government agencies from the U.S., UK, and several European countries have issued a joint warning about ongoing cyberattacks by Russian state-backed threat actors targeting routers and other networking equipment used in critical infrastructure. Attackers like Berserk Bear, Energetic Bear, and others are exploiting known vulnerabilities such as CVE-2008-4128 and CVE-2018-0171 to gain unauthorized access and execute arbitrary commands on Cisco devices. These attacks primarily affect sectors including energy, finance, healthcare, and government. Defenders are urged to disable outdated SNMP versions, enforce secure password policies, and apply patches to mitigate risks.

Jul 14
Help Net Security Research UEFI Secure Boot shims patch-tuesday5 min read

No one knows how many old shims can still bypass UEFI Secure Boot

ESET researchers identified 11 outdated UEFI Secure Boot shims signed by Microsoft that could allow attackers to bypass secure boot protections. These shims, all at version 0.9 or lower, were revoked in Microsoft's June 9, 2026 Patch Tuesday update. The issue affects any system using the Microsoft Corporation UEFI CA 2011 certificate. Attackers can exploit this by copying an old shim along with a malicious second-stage loader onto a target device. Two vulnerabilities are involved: CVE-2026-8863 and CVE-2026-10797. Users are advised to apply the latest UEFI revocations and ensure their systems are updated.

Jul 14
ESET WeLiveSecurity Research UEFI shim bootloader zero-day26 min read

Forgotten UEFI shims undermining Secure Boot

ESET researchers uncovered 11 outdated UEFI shim bootloaders (versions 0.9 or lower) that can be used to bypass UEFI Secure Boot on any system trusting the Microsoft Corporation UEFI CA 2011 certificate. Attackers could exploit these shims to execute untrusted code during boot, enabling malicious UEFI bootkits like Bootkitty, HybridPetya, or BlackLotus. The vulnerabilities were addressed in Microsoft's June 9th, 2026 Patch Tuesday update, which revoked the affected binaries. Two CVE IDs—CVE-2026-8863 and CVE-2026-10797—were assigned to track the issues.

Jul 14
The Hacker News Incident U.S. Treasury Department GRU Unit 291556 min read

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

The U.S. Treasury Department has imposed sanctions on FirstVPN (1VPNS) and two individuals for enabling ransomware attacks against American businesses and critical infrastructure. The service, which operated since 2014, was dismantled in May 2026 after being linked to cybercriminals who used it to mask the origins of their attacks. Alongside FirstVPN’s administrator, Dmytro Rashevskyi, and cryptor seller Yegor Silayev, the move highlights growing efforts to hold bad actors accountable for facilitating large-scale cybercrime. These actions are part of broader international measures targeting Russian state-backed cyber operations and ransomware enablers.

Jul 13
Rapid7 Blog PoC Microsoft SharePoint zero-day6 min read

CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)

Researchers at Rapid7 have revealed a critical authentication bypass flaw in Microsoft SharePoint, tracked as CVE-2026-55040. This vulnerability enables unauthenticated attackers to impersonate users or administrators on vulnerable SharePoint servers by exploiting weaknesses in the JWT token validation process. The flaw is part of an exploit chain that leads to remote code execution, with the RCE component expected to be patched in August 2026. A proof-of-concept script demonstrates how attackers can enumerate user SIDs or UPNs and bypass authentication entirely. Microsoft has acknowledged the issue and released a fix for the authentication bypass in its July updates.

Jul 13
BleepingComputer Exploited iCagenda rce3 min read

CISA warns of actively exploited RCE flaws in Joomla extensions

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting two remote code execution (RCE) vulnerabilities in popular Joomla extensions—iCagenda and Balbooa Forms. These flaws allow malicious actors to upload arbitrary files, potentially leading to full website compromise. The vulnerabilities, tracked as CVE-2026-48939 and CVE-2026-56291, were added to CISA's Known Exploited Vulnerabilities catalog with maximum priority, requiring immediate mitigation. Patches are now available for both extensions.

Jul 13
The Hacker News Roundup ai-ml17 min read

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

This week's security landscape highlights a growing trend: vulnerabilities are being discovered and exploited faster than ever. Progress has issued an urgent advisory for ShareFile customers to shut down Windows servers running Storage Zone Controllers amid a credible external threat. Meanwhile, ransomware groups are exploiting the recently disclosed Citrix Bleed 2 flaw (CVE-2025-5777) to deploy DragonForce ransomware. Additionally, researchers have uncovered new methods to manipulate AI coding assistants into installing malicious botnets through a technique called HalluSquatting. With dozens of critical CVEs emerging weekly, organizations must prioritize patch management and proactive monitoring to mitigate risks.

Jul 13
The Hacker News Research ai-ml8 min read

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

A new attack called MemGhost enables attackers to manipulate AI assistants by planting false 'memories' through a single email. This technique, dubbed stealth memory injection, allows an attacker to alter the agent’s internal knowledge without alerting the user. The attack exploits how personal AI agents store and retrieve information from memory files during sessions. Researchers tested the method successfully on several AI frameworks, including OpenClaw and Claude Code SDK agents. The vulnerability lies in the fact that these systems process untrusted inputs—like emails—and can modify their own memory without user consent. While no immediate patch exists, experts recommend separating tasks involving untrusted content from those that modify memory. OpenClaw acknowledged the risk and suggested mitigations such as routing emails through a restricted agent before processing.

Jul 13
Check Point Research Advisory AssuranceAmerica data-breach6 min read

13th July – Threat Intelligence Report

Check Point Research's latest Threat Intelligence Report highlights significant cybersecurity events from the week of July 13, 2026. Among the top incidents was a breach at U.S. auto insurer AssuranceAmerica impacting 7 million individuals due to compromised employee credentials. Latvia’s state-owned forestry company also fell victim to a ransomware attack exploiting an unpatched system for two years. In the realm of vulnerabilities, multiple Tenda router models were found vulnerable via an undocumented backdoor (CVE-2026-11405), while Linux maintainers patched a severe flaw in the KVM hypervisor (CVE-2026-53359). Additionally, AI threats emerged with JadePuffer, an LLM-driven ransomware operation exploiting CVE-2025-3248. These developments underscore the growing complexity and scale of modern cyber threats.

Jul 13
SecurityWeek RabbitMQ3 min read

RabbitMQ Vulnerability Threatens Enterprise Systems

A critical vulnerability in RabbitMQ, tracked as CVE-2026-5721 (CVSS 8.7), allows attackers to retrieve the broker's confidential OAuth secret without authentication through an outdated management endpoint. This flaw could enable adversaries to impersonate the broker and gain administrative access to systems using identity providers like Auth0, Azure AD, Keycloak, or UAA. The issue affects RabbitMQ versions starting from 3.13.0 and was fixed in 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15. Enterprises are urged to update immediately and secure their management interfaces to prevent potential breaches.

Jul 13
Help Net Security Advisory ShareFile cloud3 min read

Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers

Progress Software has issued an urgent warning about a 'credible external security threat' affecting its ShareFile Storage Zone Controllers (SZC), prompting the company to disable access to affected accounts and urge customers to manually shut down their on-premises SZC servers. The move follows reports that attackers might be exploiting two vulnerabilities—CVE-2026-2699 and CVE-2026-2701—to gain remote code execution on unpatched systems. While no unauthorized access has been confirmed, Progress is collaborating with cybersecurity experts to investigate the incident and restore services.

Jul 13
BleepingComputer Advisory NSA Berserk Bear3 min read

US and allies warn of Russian critical infrastructure attacks

Cybersecurity agencies from the US and eight other nations have jointly warned that Russian state-backed hackers are targeting misconfigured and vulnerable routers to breach critical infrastructure networks. The advisory, authored by the NSA, FBI, CISA, and partners from Australia, the UK, Canada, and others, identifies several hacking groups—Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra—as responsible for scanning for weak SNMP credentials and using spoofed IPs to steal router configurations. These attacks pose a serious threat to sectors like energy, communications, healthcare, and government services. Agencies recommend upgrading to SNMPv3, disabling unused features like Cisco Smart Install, enforcing strong passwords, and blocking unnecessary traffic at firewalls.

Jul 13
SecurityWeek Exploited Balbooa Forms web-app2 min read

Organizations Warned of Exploited Joomla Extension Vulnerabilities

Security researchers have confirmed that cybercriminals are actively exploiting two severe vulnerabilities in widely used Joomla extensions, enabling unauthenticated attackers to execute arbitrary code remotely. The affected components are Balbooa Forms and iCagenda, both of which were found to contain critical file upload flaws. These issues—CVE-2026-56291 and CVE-2026-48939—have already been weaponized in attacks before patches were available, making them zero-days. Both vendors have now released updates to resolve the issues, but administrators must act quickly to apply them. CISA has also added these flaws to its Known Exploited Vulnerabilities catalog, emphasizing their urgent risk.

Jul 13
SecurityWeek Incident ShareFile Storage Zone Controller malware2 min read

Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns

Progress Software has advised ShareFile customers to immediately shut down their Storage Zone Controller servers following reports of a credible external security threat. The company temporarily restricted access to accounts using these controllers and is conducting an investigation. While no unauthorized access has been confirmed, speculation points to potential exploitation of two high-severity vulnerabilities—CVE-2026-2699 and CVE-2026-2701—which could allow unauthenticated remote code execution.

Jul 13
The Hacker News Exploited Balbooa Forms web-app5 min read

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

CISA has added two high-severity vulnerabilities affecting the iCagenda and Balbooa Forms extensions for Joomla to its catalog of known exploited vulnerabilities, after reports confirmed they were being actively exploited as zero-days. CVE-2026-48939 in iCagenda enables arbitrary file uploads leading to remote code execution, while CVE-2026-56291 in Balbooa Forms allows unauthenticated attackers to upload malicious PHP files. Both flaws have been addressed in updated versions—4.0.8 and 3.9.15 for iCagenda, and 2.4.1 for Balbooa Forms. Administrators are urged to update immediately and scan for suspicious files on their systems.

Jul 12
Help Net Security Roundup19 min read

Week in review: Accenture data breach, great open-source cybersecurity tools

Accenture has confirmed a potential data breach after a hacker claimed to have stolen over 35GB of source code. Meanwhile, attackers are exploiting a critical vulnerability in Adobe ColdFusion (CVE-2026-48282) and another flaw in Langflow (CVE-2026-55255), both recently added to CISA's exploited vulnerabilities list. These incidents highlight the urgency for organizations to apply patches promptly and strengthen their defenses.