Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

2+ day, 16+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

2+ day, 22+ hour ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension

Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

3+ day, 14+ hour ago   (429+ words) The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. Fortinet on Tuesday released patches for 10 vulnerabilities across its products, including critical security defects. The first critical bug, tracked as CVE-2026-84390 (CVSS score of 9.6), is…...

SecurityWeek
securityweek.com > ivanti-patches-critical-flaws-across-enterprise-security-products

Ivanti Patches Critical Flaws Across Enterprise Security Products

3+ day, 18+ hour ago   (410+ words) Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for…...

SecurityWeek
securityweek.com > microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

4+ day, 9+ hour ago   (727+ words) Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local…...

SecurityWeek
securityweek.com > elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

1+ week, 15+ hour ago   (589+ words) Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is…...

SecurityWeek
securityweek.com > hpe-patches-critical-rce-vulnerabilities-in-aos-cx-2

HPE Patches Critical RCE Vulnerabilities in AOS-CX

1+ week, 16+ hour ago   (479+ words) Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are…...

SecurityWeek
securityweek.com > sangoma-switchvox-vulnerabilities-exploited-in-the-wild

Sangoma Switchvox Vulnerabilities Exploited in the Wild

1+ week, 1+ day ago   (533+ words) Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn. Tracked as CVE-2026-9586 (CVSS…...

SecurityWeek
securityweek.com > over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

1+ week, 2+ day ago   (575+ words) A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin exposes over 3 million websites to remote code execution (RCE) attacks, WordPress security firm Defiant warns. Tracked as CVE-2026-19949 (CVSS score of 8.8), the security defect is described as a…...

SecurityWeek
securityweek.com > exploit-published-for-fresh-cleo-harmony-vulnerability

Exploit Published for Fresh Cleo Harmony Vulnerability

1+ week, 3+ day ago   (441+ words) Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony. Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument…...