CVE Tools

Security news, decoded.

What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.

RSS
Latest signal The Hacker News Research NVIDIA NemoClaw ai-ml Ollama

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Read full story

Oasis Security has disclosed a vulnerability in NVIDIA NemoClaw that permits attackers to hijack local Ollama instances via malicious webpages, specifically on Windows and WSL configurations. By exploiting DNS rebinding against unauthenticated API endpoints bound to all network interfaces, threat actors can inject hidden instructions into AI model chat templates, thereby compromising agent behavior without user knowledge. While a patch for macOS and Linux is available in NemoClaw v0.0.35, affected Windows users should restrict exposure of port 11434, as no specific fix has yet been released for those platforms.

Earlier39 stories
Aug 25
SecurityWeek Exploited WordPress auth-bypass2 min read

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing attackers to log in as any user, including administrators. The flaws, identified as CVE-2026-61979 and CVE-2026-15981, affect a widely used plugin with over 10,000 installations of its free edition alone. While patches are available, the lack of clear security advisories for paid versions complicates remediation efforts, making active mitigation essential.

Aug 25
The Hacker News Patch Marimo Notebook Software ai-ml4 min read

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo has patched a high-severity code injection vulnerability, tracked as CVE-2026-75149, which permitted attackers to execute unauthorized Model Context Protocol (MCP) commands within their notebook software. The flaw, rated 8.7 on the CVSS v4 scale, affects versions prior to 0.23.15 and allows a crafted notebook to launch a local subprocess containing attacker-controlled data when opened in edit mode. This risk arises before any notebook cells are executed, effectively bypassing standard execution boundaries. Users are advised to upgrade immediately to version 0.23.15 or later to mitigate this threat.

Aug 25
BleepingComputer Exploited Zimbra Collaboration Suite rce4 min read

Hackers breached over 270 Zimbra servers in ongoing attacks

Over 270 internet-facing instances of Zimbra Collaboration Suite have been compromised through active exploitation of CVE-2026-73570, a high-severity remote code execution vulnerability. Synacor addressed this flaw, which involves command injection in the SNMP component when notifications are enabled, by releasing version 10.1.20. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog following reports from CERT Polska and Shadowserver, prompting urgent patching directives for federal agencies.

Aug 25
Help Net Security Exploited Zimbra Collaboration Suite rce3 min read

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Shadowserver reports that at least 274 internet-exposed Zimbra Collaboration Suite instances have been breached through active exploitation of CVE-2026-73570. This unauthenticated code injection vulnerability impacts installations using the optional zimbra-snmp package with SNMP notifications enabled, allowing attackers to execute arbitrary OS commands. Synacor released a patch in version 10.1.20 on July 20, 2026, and CISA has now added the issue to its Known Exploited Vulnerabilities catalog, mandating remediation for federal agencies. With thousands of potentially vulnerable systems still unpatched, administrators are urged to apply the update immediately and audit their systems for signs of intrusion.

Aug 25
The Hacker News Exploited miniOrange SAML 2.0 Single Sign On plugin auth-bypass3 min read

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers are actively targeting the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, leveraging two critical flaws to assume administrative control of vulnerable sites. The campaign exploits CVE-2026-61979 and CVE-2026-15981, which stem from a flawed signature validation process that incorrectly treats malformed inputs as successful verifications, enabling unauthorized session creation. Since a proof-of-concept exists for these authentication bypasses, site administrators should immediately update to version 17.0.6 of the Standard edition to mitigate this high-risk threat.

Aug 25
SecurityWeek Exploited Oracle HTTP Server SnowLight3 min read

CISA Warns of Exploited Oracle WebLogic Vulnerability

CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, warning that this critical remote code execution flaw is being actively used against Oracle WebLogic environments. The vulnerability, rated with a perfect CVSS score of 10, affects both the Oracle HTTP Server and the WebLogic Server Proxy plugin, allowing attackers to compromise systems without authentication. Federal agencies were directed to apply the fix from Oracle's January 2026 security update by August 27, following reports that the bug has been targeted by China-linked threat actors since early in the year.

Aug 25
The Hacker News Exploited Oracle HTTP Server rce3 min read

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

CISA has listed CVE-2026-21962 in its Known Exploited Vulnerabilities catalog after confirming active attacks against Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. This maximum-severity flaw (CVSS 10.0) stems from improper access control, allowing unauthenticated attackers over HTTP to gain full control or modify critical data. Although Oracle released patches earlier this year, threat actors have intensified exploitation efforts, with federal agencies required to remediate by August 27, 2026.

Aug 25
Qualys Security Blog PoC Microsoft Defender privilege-escalation5 min read

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

A proof-of-concept exploit has become available for CVE-2026-69414, a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine within Microsoft Defender. This flaw enables local attackers with low privileges to execute code as NT AUTHORITY\SYSTEM on affected systems, including Windows 11 25H2 and Windows Server 2025. Microsoft assigned the CVE identifier on August 14, 2026, but no security update is currently available. Organizations relying on CISA Binding Operational Directive (BOD) 26-04 must address this risk within 14 days, necessitating immediate mitigation strategies until the vendor releases a formal patch.

Aug 24
Dark Reading Exploited Zimbra Collaboration Suite rce6 min read

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has mandated that federal agencies patch a critical remote code execution vulnerability in Zimbra Collaboration Suite by August 24, following confirmed active exploitation in the wild. The flaw, identified as CVE-2026-73570, allows unauthenticated attackers to execute arbitrary commands on servers where SNMP notifications are enabled, a setting that is active by default in affected versions. Zimbra addressed the issue in version v10.1.20, urging organizations to update immediately while treating exposed instances as potential security incidents requiring log review and incident response procedures.

Aug 24
BleepingComputer PoC Calix GS7 XGS network-edge4 min read

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Security researchers disclosed CVE-2026-75501, an unpatched missing authentication vulnerability affecting Calix GS7 XGS residential routers running EXOS/6.6.47 firmware. The flaw allows remote attackers to bypass Network Address Translation and firewall protections by sending unauthenticated SOAP requests to the exposed MiniUPnPd control endpoint on the WAN interface. This enables threat actors to create permanent port-forwarding rules that expose internal assets, such as IP cameras and NAS devices, to the public internet without vendor remediation.

Aug 24
BleepingComputer Exploited miniOrange SAML SSO Plugin auth-bypass3 min read

Hackers target WordPress sites in miniOrange auth bypass attacks

Threat actors are actively chaining two critical authentication bypass vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses using HMAC-SHA1 and misinterpreted OpenSSL verification errors to log in as site administrators. Although fixed versions were released in July for all editions of the plugin, incomplete vendor disclosure regarding the paid tiers left many installations vulnerable to recent exploitation attempts. Site owners should manually update to patched releases, such as version 17.06 for the Standard edition, as automatic dashboard alerts may not trigger for premium versions.

Aug 24
The Hacker News Exploited Siemens PLCs UNC629317 min read

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. government agencies warn that threat actors are leveraging artificial intelligence to generate exploit scripts for internet-exposed Siemens S7 Series PLCs, posing an active risk to critical infrastructure sectors like water and energy. Meanwhile, GitLab is facing immediate danger as CVE-2026-19478, a high-severity code injection flaw, is being actively exploited by unauthenticated attackers to modify public projects. Other significant developments include the leakage of live API keys for 659 Stripe merchants, the discovery of 768 corporate AWS keys with full administrative rights in public repositories, and the release of RedC2 4.0 Linux backdoors via trojanized npm packages.

Aug 24
Check Point Research Exploited Snowflake Copilot data-breach6 min read

24th August – Threat Intelligence Report

Major vendors including GitLab, Cisco, and Citrix have released urgent patches for critical vulnerabilities that are already seeing exploitation or carry maximum severity scores. Notably, GitLab fixed CVE-2026-19478 in its Community and Enterprise editions, a CVSS 9.4 code injection flaw, while Citrix addressed authentication bypass issues CVE-2026-19489 and CVE-2026-19490 in NetScaler ADC and Gateway. These fixes coincide with significant breach disclosures affecting Latvia's CSDD and Japan's Sakura Internet, as well as warnings regarding active AI-assisted attacks on Siemens S7 PLCs and a new Cl0p extortion campaign targeting PTC Windchill via CVE-2026-12569.

Aug 24
SecurityWeek Patch Spring Framework rce3 min read

91 Vulnerabilities Patched in Spring Application Framework

Broadcom has released updates for the Spring application framework addressing 91 vulnerabilities across various modules, including Spring Security, Spring AI, and Spring GraphQL. Among these fixes is a critical flaw in Spring Security’s embedded LDAP server (CVE-2026-59270) that permits unauthorized modification of directory entries, alongside over a dozen high-severity issues enabling remote code execution and data leakage. The scale of this update impacts more than 200,000 downstream components, highlighting how the increased use of AI-assisted coding by Broadcom has accelerated the emergence of security defects in the ecosystem.

Aug 24
The Hacker News Patch Keycloak auth-bypass5 min read

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released security updates to remediate a critical vulnerability in the identity access management platform that allows unauthenticated attackers to hijack user accounts. The flaw, identified as CVE-2026-18963 and scored 9.1 by Red Hat, stems from improper state validation during the password reset process, enabling an attacker to force a credential change without verification tokens. To secure their infrastructure, administrators should upgrade upstream Keycloak instances to version 26.7.2, or apply the corresponding fixes in Red Hat build of Keycloak versions 26.4.15 and 26.6.6. While no active exploitation has been confirmed, Red Hat recommends disabling the "Forgot password" feature in all realms as a temporary mitigation if immediate patching is not possible.

Aug 24
BleepingComputer Exploited Zimbra Collaboration Suite rce4 min read

CISA orders urgent patching of actively exploited Zimbra flaw

CISA has directed U.S. federal agencies to patch a critical vulnerability in Zimbra Collaboration Suite within three days due to active exploitation in the wild. Tracked as CVE-2026-73570, this command injection flaw in the SNMP monitoring component allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled. Zimbra addressed the issue in version 10.1.20, and security teams should update immediately while monitoring for suspicious file creation or service restarts.

Aug 23
Help Net Security Exploited Windows 11 Medusa14 min read

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

A threat actor identified as TheHatman claims to have exfiltrated millions of employee records from the Microsoft Azure environments of several Fortune 500 companies, including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. In related developments, US federal agencies issued a joint warning stating that the Medusa ransomware group has successfully infiltrated more than 500 organizations since its inception in June 2021.

Aug 21
Patchstack Exploited miniOrange auth-bypass13 min read

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

DigitalOcean's security team detected active exploitation of two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On WordPress plugin. These flaws allow unauthenticated attackers to forge SAML assertions and assume control of administrator accounts, posing a severe risk to site integrity. A significant portion of affected installations remained unaware of the threat because the plugin ships seven distinct commercial editions under a single WordPress slug, with paid versions patched silently without public advisories or database entries. To mitigate this immediate risk, administrators must manually verify their specific edition version and apply the relevant vendor fix or implement the temporary hotfixes documented by DigitalOcean.

Aug 21
The Hacker News PoC Windows Defender privilege-escalation7 min read

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has demonstrated a technique to weaponize Microsoft Defender's internal BTR.sys driver, enabling administrators to execute arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. The proof-of-concept tool, BTRCLI, leverages a hard-coded encryption key within the driver to install it as a boot service, allowing the removal of locked security components like WdFilter.sys during system startup before user-mode defenses initialize. Although the method requires existing administrative privileges and no traditional software flaw was exploited, the capability to strip endpoint protection using a native, signed Windows component poses a significant risk to defensive architectures.

Aug 21
SecurityWeek Exploited RondoDox Salt Typhoon5 min read

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

CISA has added CVE-2025-62593 in Ray-Project Ray to its Known Exploited Vulnerabilities catalog after observing active abuse by the RondoDox botnet, prompting a mandate for federal agencies to prioritize remediation. This development sits alongside several other high-profile incidents, including GitHub's clarification that a vulnerability exploited by Wiz's AI agent was human-authored rather than generated by Copilot, and reports of T-Mobile physically cutting a router cable to halt an intrusion by Salt Typhoon. Additionally, FortiGuard Labs identified Evooo1Bot, a Linux botnet leveraging multiple CVEs, while Medusa ransomware groups are actively targeting unpatched vulnerabilities in Fortra GoAnywhere and BeyondTrust.

Aug 21
Bishop Fox Research Citrix NetScaler ADC network-edge18 min read

No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452

Bishop Fox has published a detection utility to help administrators verify the patch status of Citrix NetScaler ADC and Gateway appliances affected by CVE-2026-8452. This high-severity memory corruption vulnerability allows unauthenticated attackers to trigger remote code execution via SAML processing, requiring an upgrade to the latest 13.1 or 14.1 builds. The provided tool enables non-disruptive verification of the fix across virtual servers without crashing the appliance.

Aug 21
BleepingComputer Exploited TrueConf Server Head Mare3 min read

CISA orders feds to patch actively exploited TrueConf Server flaws

CISA has directed U.S. federal agencies to remediate two critical vulnerabilities in TrueConf Server, which are currently under active exploitation in the wild. The first flaw, CVE-2026-72529, permits unauthenticated remote code execution via an undocumented function on port 4307/TCP, while CVE-2026-72530 enables a sandbox escape through complex code injection. Kaspersky identifies the hacktivist group Head Mare as the actor leveraging these weaknesses since July 2026 to distribute trojanized client installers containing backdoor malware, primarily targeting Russian organizations. Federal civilian executive branch agencies must complete patches by September 3.

Aug 21
Help Net Security Exploited Microsoft Entra ID rce2 min read

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has addressed a critical remote code execution flaw identified as CVE-2026-69836 within its Entra ID cloud identity service, which is actively being exploited in the wild. Rated with the maximum CVSS score of 10.0, this vulnerability stems from the deserialization of untrusted data and permits unauthenticated attackers to execute code across the network without prior credentials. The issue was discovered by internal security engineer Robert Fitzpatrick and has already been fully mitigated by Microsoft, meaning no specific remediation steps are necessary for customers. Despite confirming active exploitation, the company has not yet disclosed details regarding the threat actors involved, the timeline of attacks, or the potential scope of compromised organizations.

Aug 21
BleepingComputer Incident SickKids data-breach4 min read

SickKids data breach exposes employee and job applicant info

The Hospital for Sick Children (SickKids) has revealed that personal data belonging to current and former employees, as well as job applicants, was accessed during a cybersecurity incident. The hospital attributes the breach to a vulnerability in an unspecified third-party application, which has since been remediated. While clinical systems and patient records remain secure, the incident prompted a temporary takedown of the institution's public Careers website. SickKids is currently reviewing the scope of the exposure with external experts and will notify affected individuals directly, offering complimentary credit monitoring services in the interim.

Aug 21
The Hacker News Patch Crosswork Data Gateway web-app4 min read

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco has issued security updates addressing nine vulnerabilities across its Crosswork and Secure Workload products, discovered during an internal security review. Four high-severity issues affect Crosswork Data Gateway, Network Controller, and Planning, including CVE-2026-20030, CVE-2026-20357, CVE-2026-20358, and CVE-2026-20359, all of which are fixed in Release version 7.2.1-SP. Additionally, five vulnerabilities impact Secure Workload SaaS and on-premises deployments, such as CVE-2026-20315 and CVE-2026-20317, with fixes available in versions 3.10.9.1 and 4.0.4.16. Cisco states these flaws are not currently being actively exploited but urges administrators to apply the latest updates promptly to mitigate risk.

Aug 21
SecurityWeek PoC Microsoft Azure SQL Database rce2 min read

Microsoft Rolls Out 22 Fresh Security Patches

Microsoft has distributed 22 new security updates to remediate critical and high-severity vulnerabilities across its portfolio, including Azure, Entra ID, Exchange Online, Fabric, and Partner Center. The release addresses several maximum-scoring flaws, such as remote code execution and elevation of privilege issues in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555, CVE-2026-65816), and Entra ID (CVE-2026-69836). For most of these defects, customers do not need to take action because Microsoft implemented the mitigations on the server side, though additional patches cover high-severity bugs in services like Copilot and Windows Remote Help Defense.

Aug 21
Help Net Security Patch Citrix NetScaler ADC auth-bypass4 min read

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has issued urgent security updates for NetScaler ADC and NetScaler Gateway to address two newly disclosed vulnerabilities, with the primary threat being CVE-2026-19490. This critical flaw carries a CVSS v4.0 score of 9.3 and permits attackers to bypass authentication mechanisms under specific configuration conditions involving Gateway or AAA virtual servers. A secondary issue, CVE-2026-19489 (CVSS 8.8), involves a memory overflow that could lead to denial of service when SIP ALG is enabled on Large Scale NAT groups. While Rapid7 reports no evidence of active exploitation as of mid-August, Citrix advises immediate upgrades to supported builds, specifically versions 14.1-73.32 and 13.1-63.21, given the high likelihood of rapid opportunistic attacks against exposed infrastructure.

Aug 21
SecurityWeek Exploited TrueConf Server Head Mare3 min read

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA has added two critical vulnerabilities affecting TrueConf Server, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities catalog following reports of active use by the hacktivist group Head Mare. These flaws allow remote attackers with access to port 4307/TCP to execute arbitrary code on the host system, enabling the deployment of the PhantomCore malware. Federal agencies are urged to apply patches immediately, while all users of affected server versions should update to releases 5.3.9, 5.4.9, or 5.5.5 to mitigate the risk.

Aug 21
The Hacker News Exploited GitLab CE rce3 min read

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

WatchTowr has detected active in-the-wild exploitation of CVE-2026-19478, a critical code injection vulnerability affecting GitLab CE and EE shortly after its public disclosure. With a CVSS score of 9.4, this flaw allows unauthenticated attackers to manipulate or delete public projects via the GraphQL interface without needing credentials. Affected versions include GitLab 18.2 prior to 18.11.11, 19.0 before 19.0.8, 19.1 prior to 19.1.6, and 19.2 before 19.2.4. Organizations should upgrade to the patched releases immediately or mitigate risk by restricting unauthenticated access to /api/graphql while reviewing web logs for suspicious @glintroduced directives.

Aug 21
The Hacker News Exploited Microsoft Entra ID rce2 min read

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft has disclosed and fixed a critical remote code execution vulnerability in its cloud identity platform, Microsoft Entra ID. Tracked as CVE-2026-69836 with a maximum CVSS score of 10.0, the flaw stems from the deserialization of untrusted data, potentially allowing attackers to execute arbitrary code over the network. While reports confirm the vulnerability is being actively exploited in the wild, Microsoft states that it has fully mitigated the issue on their end and advises customers that no specific action is needed.

Aug 21
Palo Alto Unit 42 Research npm supply-chain7 min read

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Palo Alto Networks' Unit 42 has published new research detailing how threat actors are shifting their focus from final software binaries to the foundational tools of the software development lifecycle (SDLC). The report highlights incidents such as the XZ Utils vulnerability (CVE-2024-3094) and the ChainDrop npm worm, which exploited preinstall hooks to harvest secrets from GitHub Actions runners and propagate via stolen tokens. By targeting un-sandboxed environments like developer endpoints, CI/CD pipelines, and cloud container runtimes, attackers can bypass traditional application scans. Key affected areas include npm, GitHub Actions, and VS Code, where malicious extensions or scripts operate with user-level privileges. To mitigate these risks, the team recommends strict execution controls, such as ignoring install scripts and limiting credential lifetimes.

Aug 20
The Hacker News PoC Windows Defender Mabna Institute16 min read

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Security researchers have disclosed critical remote code execution vulnerabilities in Gogs (CVE-2026-52813) and n8n (CVE-2026-33696), prompting immediate patch releases. Additionally, the U.S. Department of Justice has formally charged seventeen individuals affiliated with the Iran-based Mabna Institute for orchestrating a massive cyber-theft campaign targeting global academic institutions. Administrators should update Gogs to version 0.14.3 and n8n to versions 2.14.1, 2.13.3, or 1.123.27 to mitigate these risks. This week’s intelligence also highlights new exploitation techniques involving Microsoft Defender components and AI-assisted vulnerability discovery.

Aug 20
SecurityWeek Exploited Zimbra Collaboration Suite rce2 min read

Hackers Target Zimbra Servers in Active Exploitation Campaign

CERT Polska has confirmed that attackers are actively exploiting a high-severity vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. The flaw allows unauthenticated attackers to execute arbitrary OS commands when the optional zimbra-snmp package is installed and SNMP notifications are enabled. This critical risk was addressed in version 10.1.20, released on July 20, so administrators should apply the patch immediately to prevent full server compromise, credential harvesting, and lateral movement.

Aug 20
BleepingComputer PoC Elementor Pro rce3 min read

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical remote code execution flaw identified as CVE-2026-32475 affects versions of Elementor Pro prior to 4.2.2, allowing unauthenticated attackers to upload executable files to WordPress servers. The vulnerability arises from a mismatch between file validation and processing loops in the File Upload module, specifically when handling empty filename entries within multipart uploads. Researchers at Patchstack disclosed that the exploit requires only a published Elementor form with a file upload field, enabling adversaries to place PHP payloads in public directories where they can be executed by the server. While no active exploitation has been observed yet, a proof-of-concept is available, urging administrators to immediately update to the fixed version and manually inspect their upload directories for malicious content.

Aug 20
Qualys Security Blog PoC Microsoft Defender privilege-escalation5 min read

CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

A public proof-of-concept has surfaced for ShieldBreak (CVE-2026-69414), a zero-day elevation-of-privilege flaw in the Microsoft Malware Protection Engine underlying Microsoft Defender. This vulnerability enables low-privileged local attackers to achieve full SYSTEM access by manipulating how Defender processes cloud-hydrated files via the Cloud Filter API. The exploit affects Windows 11 25H2 and Windows Server 2025, where attackers can abuse privileged processing paths to execute arbitrary code under high-trust contexts.

Aug 20
The Hacker News Patch NetScaler ADC auth-bypass5 min read

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has issued security updates for NetScaler ADC and NetScaler Gateway to remediate two vulnerabilities, including a high-severity authentication bypass. The critical flaw, identified as CVE-2026-19490 with a CVSS score of 9.3, allows attackers to bypass authentication on devices configured as Gateway or AAA servers under specific conditions. Additionally, CVE-2026-19489 (CVSS 8.8) introduces a memory overflow risk that could lead to denial-of-service when SIP ALG is enabled. Administrators are advised to upgrade to NetScaler ADC and NetScaler Gateway version 14.1-73.32 or later, or version 13.1-63.21 or later, to mitigate these risks, though no active exploitation has been confirmed.

Aug 20
The Hacker News Exploited Zimbra Collaboration Suite rce3 min read

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

CERT Polska has confirmed active in-the-wild exploitation of CVE-2026-73570, a high-severity command injection vulnerability in Zimbra Collaboration Suite versions prior to 10.1.20. The flaw affects installations where the zimbra-snmp package is present and allows unauthenticated attackers to execute arbitrary OS commands by sending crafted SMTP requests that bypass input sanitization during SNMP notification handling. While Zimbra released a patch for this issue in July, the recent confirmation of real-world attacks underscores the urgent need for organizations to verify they have upgraded to version 10.1.20 and should inspect system logs for signs of compromise.