Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

2+ day, 16+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > organizations-warned-of-cisco-secure-fmc-exploitation

Organizations Warned of Cisco Secure FMC Exploitation

2+ day, 18+ hour ago   (578+ words) Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole,…...

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

2+ day, 22+ hour ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

3+ day, 18+ hour ago   (489+ words) Industrial giants Schneider Electric, Siemens, and Aveva have published September 2026 Patch Tuesday advisories, informing customers about vulnerabilities found in their ICS products. Schneider Electric published four new security advisories and updated four others, including one originally released in 2019. The most…...

SecurityWeek
securityweek.com > hpe-patches-critical-rce-vulnerabilities-in-aos-cx-2

HPE Patches Critical RCE Vulnerabilities in AOS-CX

1+ week, 16+ hour ago   (479+ words) Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are…...

SecurityWeek
securityweek.com > sangoma-switchvox-vulnerabilities-exploited-in-the-wild

Sangoma Switchvox Vulnerabilities Exploited in the Wild

1+ week, 1+ day ago   (533+ words) Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn. Tracked as CVE-2026-9586 (CVSS…...

SecurityWeek
securityweek.com > cisco-warns-of-unpatched-secure-email-flaws-patches-critical-switch-vulnerabilities

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

1+ week, 2+ day ago   (546+ words) Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure…...

SecurityWeek
securityweek.com > exploit-published-for-fresh-cleo-harmony-vulnerability

Exploit Published for Fresh Cleo Harmony Vulnerability

1+ week, 3+ day ago   (441+ words) Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony. Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument…...

SecurityWeek
securityweek.com > hackers-start-exploiting-critical-langflow-vulnerability

Hackers Start Exploiting Critical Langflow Vulnerability

1+ week, 4+ day ago   (400+ words) Tracked as CVE-2026-0768 (CVSS score of 9.8), the security defect exists within the code validator in Langflow’s custom component editor. Because a user-supplied string is not properly validated before it is used for Python code execution, an attacker could exploit the…...

SecurityWeek
securityweek.com > critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

1+ week, 4+ day ago   (496+ words) A critical vulnerability in JFrog Artifactory is reportedly being exploited in the wild just days after its public disclosure. JFrog Artifactory is a widely used solution for managing the full lifecycle of software artifacts, binaries, AI models, containers, and packages....