Search
Search the Hacker Posts newsroom.
Estée Lauder confirms Oracle EBS zero-day breach in Cl0p campaign
Estée Lauder notified the California AG on July 21 that Cl0p exploited Oracle EBS CVE-2025-61882 to steal HR data — names, SSNs, passports, bank accounts, health records — starting August 2025.
Arctic Wolf ties CVE-2026-0257 GlobalProtect bypass to Qilin ransomware
Arctic Wolf documented Qilin ransomware deployments through Palo Alto CVE-2026-0257 in June — six weeks after Rapid7 first flagged the auth-bypass exploitation and CISA added the CVE to KEV.
ServiceNow CVE-2026-6875: pre-auth sandbox escape RCE now exploited
ServiceNow's July 13 patch closes CVE-2026-6875 — a pre-auth sandbox escape in the AI Platform that yields unauthenticated RCE. Defused observed in-the-wild exploitation five days later.
Windows VMSwitch CVE-2026-57092: CVSS 9.9 guest-to-host escape in Hyper-V
Microsoft's July 14 Patch Tuesday closed CVE-2026-57092 — a CVSS 9.9 use-after-free in the Windows VMSwitch that lets a low-privileged guest reach the Hyper-V host.
Zimbra 10.1.20 patches critical command injection plus three CVEs
Zimbra shipped Daffodil 10.1.20 with a critical command injection in the SNMP monitor, four Classic UI XSS bugs, an SSRF in Nextcloud, and CVE-2026-50055 / CVE-2026-10631 / CVE-2026-50054.
FortiSandbox: CVE-2026-25089 and CVE-2026-39808 land in KEV, exploited
CISA added two critical unauthenticated OS command injection flaws in Fortinet FortiSandbox to KEV on July 16, 2026. BOD 26-04 gave FCEB agencies until July 19 to patch. Both are CVSS 9.1.
AD FS zero-day CVE-2026-56155: Microsoft DART finds DKM ACL bug already exploited
Microsoft's DART discovered CVE-2026-56155 during a live intrusion. CISA added it to KEV on July 14. Patch KB 5121391 audits DKM ACLs today, auto-remediates October 13.
WordPress patches wp2shell pre-auth RCE in 7.0.2 and 6.9.5
WordPress 7.0.2 and 6.9.5 shipped July 17 to close CVE-2026-63030 — a pre-auth RCE in Core built on the CVE-2026-60137 SQL injection. Detection PoC is already public.
Zoom Workplace on Windows: CVE-2026-53412 lets a network attacker take an account
Zoom bulletin ZSB-26014 patches CVE-2026-53412, a CVSS 9.8 pre-auth account takeover in Zoom Workplace and the VDI client for Windows. Update to 7.0.0 / 7.0.10 / 6.6.15 / 6.5.18.
LegacyHive drops Windows profsvc zero-day PoC after Patch Tuesday
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
SonicWall SMA1000 zero-days chained: CISA adds CVE-2026-15409 and 15410 to KEV
CISA added SonicWall SMA1000 zero-days CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 to KEV on July 14, chained by Rapid7 MDR. Federal deadline July 17.
CISA adds SharePoint CVE-2026-56164 to KEV, chained with two prior bugs
CISA added SharePoint auth-bypass CVE-2026-56164 to KEV on July 14 and re-issued a hardening alert citing three chained on-prem SharePoint CVEs under active exploitation. FCEB deadline July 17.
SonicWall SMA1000 CVE-2026-15409/15410 chained in the wild, KEV
SonicWall confirms in-the-wild chaining of an unauth SSRF (CVE-2026-15409, CVSS 10.0) and a post-auth command injection (CVE-2026-15410, CVSS 7.2) on SMA1000 6210/7210/8200v. CISA KEV due 2026-07-17.
SAP patches NetWeaver ABAP memory corruption (CVE-2026-44747, CVSS 9.9)
SAP's July 14 Patch Day ships 16 notes: a NetWeaver ABAP memory-corruption bug at CVSS 9.9, an Approuter request-smuggling flaw and Commerce Cloud default credentials both at 9.1.
EU + UK ship first joint cyber sanctions on Russia — FSB Centre 16 and Turla named
EU lists 9 individuals + 4 entities under the cyber regime; UK adds 24 more. FSB Centre 16 designated for the Poland grid attempt; ANSSI ties Turla to FSB unit 61240.
Zimbra 10.1.19 patches Classic Web Client stored XSS, TAG-reported
Zimbra shipped Daffodil 10.1.19 on July 7 to fix a stored XSS in the Classic Web Client where a crafted email runs JavaScript in the recipient's mailbox session. Reporter: Google TAG. No CVE assigned.
Two more Joomla extensions hit CISA KEV: iCagenda and Balbooa Forms
CISA added CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) to KEV on July 10. Both unauth file-upload to RCE. Patches: iCagenda 4.0.8/3.9.15, Balbooa Forms 2.4.1.
GhostLock (CVE-2026-43499): 15-year rtmutex UAF gives root on every Linux distro
A use-after-free in the Linux kernel's futex priority-inheritance path, present since May 2011, hands root to any local user. Fixed in mainline commit 3bfdc63936dd; distros started shipping July 9.
Tenda routers ship a hidden backdoor password — CVE-2026-11405 unpatched
CERT/CC disclosed CVE-2026-11405 on July 6: five Tenda firmware images ship a plaintext strcmp() backdoor in /bin/httpd. Tenda didn't respond and no patch is available.
Ubiquiti UniFi Connect CVE-2026-50746 (10.0): SAB-066 lands 25 flaws
Ubiquiti's SAB-066 patches 25 UniFi flaws led by CVE-2026-50746 — an unauthenticated command injection in Connect ≤3.4.16 (CVSS 10.0). Fix ships in Connect 3.4.20.
Two Joomla page-builder RCEs hit CISA KEV, remediation due today
CISA added CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Page Builder CK) to KEV on July 7. Both CVSS 10.0, unauth file-upload to RCE. FCEB deadline: July 10.
Gitea CVE-2026-20896: Docker image trusts X-WEBAUTH-USER from anywhere
Gitea's Docker template shipped REVERSE_PROXY_TRUSTED_PROXIES=* — any client can send X-WEBAUTH-USER: admin and impersonate any account. CVSS 9.8. Patched in 1.26.3, skip to 1.26.4.
Microsoft patches Defender RoguePlanet LPE CVE-2026-50656
Microsoft shipped Malware Protection Engine 1.1.26060.3008 on July 9 to close a race condition in mpengine.dll that hands SYSTEM to any local user. Public PoC has been circulating for a month.
Januscape (CVE-2026-53359): 16-year-old KVM UAF escapes VMs on Intel and AMD
A shadow-MMU use-after-free in KVM/x86 lets a root guest reach into the host on Intel VMX and AMD SVM. Stable kernels shipped the fix on July 4; embargo lifted July 6 with a public PoC.
Langflow CVE-2026-55255 IDOR added to CISA KEV, patch to 1.9.2
CISA added the Langflow /api/v1/responses IDOR (CVE-2026-55255, CVSS 9.9) to KEV on July 7. Sysdig first observed exploitation on June 25. Third Langflow flaw to hit KEV in seven months.
Adobe ColdFusion CVE-2026-48282 hits honeypots within hours of writeup
KEVIntel logged in-the-wild exploitation of Adobe ColdFusion CVE-2026-48282 within two hours of watchTowr's July 2 technical writeup. Path traversal → RCE, pre-auth, CVSS 10.
Cisco Catalyst Center CVE-2026-20191: unauth arbitrary file read
Cisco advisory cisco-sa-catc-file-read-wLH2vf8X patches CVE-2026-20191, a CVSS 7.5 pre-auth path traversal in Catalyst Center. Fixed in 3.1.6 GSMU200 and 2.3.7.11-VA GSMU100. No workaround.
Cursor DuneSlide: two critical sandbox escapes in the AI IDE (CVE-2026-50548 / -50549)
Two CVSS 9.3 flaws let a prompt-injected agent write outside Cursor's workspace and reach OS-level RCE. Patched in Cursor 3.0. Credit: Cato AI Labs.
JetBrains Hub ships 2026.1.13757 patching two critical auth-bypass CVEs
JetBrains Hub 2026.1.13757 fixes CVE-2026-50242 (CVSS 10.0 auth bypass) and CVE-2026-56141 (CVSS 9.8 account takeover via predictable restore codes). LTS backports available.
Bad Epoll CVE-2026-46242: Linux epoll race lifts any user to root
A race-condition use-after-free in the Linux kernel epoll subsystem lets an unprivileged process reach root on desktops, servers, and Android. Reported to Google kernelCTF by Jaeyoung Chung.
runZero drops seven FatFs CVEs; only CVE-2026-6684 fixed in R0.16
Seven FatFs bugs disclosed July 1 by runZero — FAT32, exFAT and long-filename paths across ESP-IDF, STM32Cube, Zephyr, MicroPython. Only CVE-2026-6684 has an upstream fix.
Oracle EBS Payments CVE-2026-46817 exploited before any public PoC existed
Defused honeypots caught in-the-wild exploitation of CVE-2026-46817 (CVSS 9.8) on June 27, six weeks after Oracle's May patch. ~950 EBS instances are internet-exposed.
Citrix CTX696604: six NetScaler CVEs, CVE-2026-8451 leaks memory
Citrix's CTX696604 fixes six NetScaler ADC/Gateway CVEs on June 30. CVE-2026-8451, a pre-auth memory overread on the SAML IdP path, echoes CitrixBleed 2. Patch 14.1-72.61 or 13.1-63.18.
CISA adds SharePoint CVE-2026-45659 to KEV, FCEB deadline July 4
CISA added SharePoint RCE CVE-2026-45659 to the KEV catalog on July 1 after confirmed exploitation. Deserialization bug patched OOB May 21; FCEB agencies have three days.
Adobe ships APSB26-68 out of band: 11 ColdFusion CVEs, six at CVSS 10
APSB26-68 fixes 11 ColdFusion CVEs on June 30 — six at CVSS 10, all pre-auth RCE. Priority 1. Patch to 2025.10 or 2023.21 today.
Progress LoadMaster CVE-2026-8037: pre-auth root RCE, PoC-ready diff
Progress patches an unauth pre-auth command-injection RCE in Kemp LoadMaster. CVSS 9.8. GA 7.2.63.2 and LTSF 7.2.54.18 ship the fix; watchTowr posted the full chain on June 29.
OpenAM 16.1.1 patches 10+ CVEs as wodzen coordinated disclosure rolls out
OpenAM 16.1.1 shipped June 17 with fixes for 17 CVEs. Public advisories began June 22 and continued through June 29: pre-auth RADIUS spoof, MSISDN LDAP injection, OAuth2 takeover, Groovy sandbox RCE.
CISA adds SimpleHelp CVE-2026-48558 to KEV after OIDC bypass exploited
CISA added the SimpleHelp OIDC auth bypass (CVSS 10) to KEV on June 29. ~14,000 servers are internet-exposed; 5.5.16 and 6.0 RC2 shipped the fix on June 9.
FBI: Russian intel now phishes Signal Backup Recovery Keys
FBI PSA I-062626-PSA names UNC5792 and UNC4221, attributes the activity to Russian Intelligence Services, and adds a new Signal Backup Recovery Key phishing tactic to the March warning.
Linux pedit COW CVE-2026-46331: page-cache LPE PoC drops in 24h
Researcher Massimiliano Oldani published a working root exploit (packet_edit_meme) for CVE-2026-46331 one day after the kernel.org CVE landed. Ubuntu 18.04–26.04 vulnerable.
macOS.Gaslight: DPRK Rust implant attacks LLM-based malware triage
SentinelLABS named macOS.Gaslight on June 23 — a Rust backdoor whose 3.5 KB prompt-injection payload is built to make an AI triage agent abort the analysis.
Ubiquiti UniFi OS: three chained CVSS 10.0 flaws hit CISA KEV (CVE-2026-34908/34909/34910)
CISA gave federal agencies three days to patch the Bulletin 064 UniFi OS triple — access control bypass, path traversal, command injection — all CVSS 10.0, all exploited.
Linux DirtyClone CVE-2026-43503: working LPE PoC from JFrog
JFrog published a full local-root exploit for the DirtyFrag-family kernel flaw CVE-2026-43503 on June 25. Patched in v7.1-rc5. Container hosts are the priority.
Lantronix EDS5000 CVE-2025-67038 in CISA KEV — patch deadline is today
CISA added the CVSS 9.8 command-injection bug — plus three perfect-10 UniFi OS flaws — to KEV on June 23. BOD 26-04 forces federal patching by June 26.
PTC Windchill CVE-2026-12569 in CISA KEV — federal patch deadline June 28
CISA added the CVSS 10 deserialization RCE in Windchill PDMLink and FlexPLM to KEV on June 25. PTC ships patches, BSI repeats the alarm. Three days to act.
Cisco Unified CM CVE-2026-20230 now drops webshells via Tor
Three weeks after the June 3 patch, Defused honeypots see automated Tor-routed sweeps deploying multi-stage JSP shells via the WebDialer SSRF. Patch alone won't evict them.
Symantec ties new Mistic backdoor to ransomware broker KongTuke
Symantec links a stealth in-memory backdoor used since April 2026 to KongTuke (Woodgnat), the initial-access broker that has fed Interlock, Rhysida, Akira, 8Base and Black Basta.
DifyTap: four cross-tenant flaws hit Dify, one still unpatched
Zafran Security discloses four Dify CVEs (41947–41950). Three patched in 1.14.2; the CVSS-9.4 Plugin Daemon path traversal CVE-2026-41948 remains unfixed at release time.
Squidbleed: 29-year-old Squid FTP gateway leaks heap memory (CVE-2026-47729)
Squid project published SQUID-2026:4 on June 23 — a heap over-read in the FTP gateway that leaks raw memory to a malicious FTP server. Fix in Squid 7.6.
Splunk Enterprise CVE-2026-20253: KEV-listed unauthenticated RCE via PostgreSQL sidecar
CVE-2026-20253 is a CVSS 9.8 missing-authentication flaw in Splunk Enterprise 10. CISA added it to KEV on June 18 with a three-day patch deadline. WatchTowr published a working RCE exploit.
Texas Parks & Wildlife vendor breach hits 3M license holders
TPWD says a third-party license vendor was breached, exposing driver's licenses, passport numbers, emails, phones and addresses for 3M+ hunting and fishing customers. SSNs and financials not affected.
Node.js ships June 18 security release — 12 CVEs across v22, v24, v26
Node.js v22.23.0, v24.17.0 and v26.3.1 fix 12 CVEs including a TLS wildcard hostname bypass (CVE-2026-48618) and a WebCrypto integer overflow DoS (CVE-2026-48933).
Gravity SMTP CVE-2026-4020: API keys leaked, 17M exploit attempts
Wordfence blocked 17M attempts at the unauth REST endpoint that dumps Gravity SMTP's full System Report — live API keys and OAuth tokens included. Patch is 2.1.5.
JetBrains pulls 15 plugins exfiltrating AI API keys, 70K installs
Aikido Security found 15 JetBrains Marketplace plugins under 7 vendor accounts that exfiltrated OpenAI, DeepSeek, and SiliconFlow keys over plaintext HTTP. JetBrains pulled them on June 16, 2026.
SurrealDB 3.1.5 patches five flaws; lead is a HIGH file read
SurrealDB shipped 3.1.5 on June 19, closing five same-day GitHub advisories — including arbitrary file read via DEFINE ANALYZER mapper at CVSS 7.7. No CVE IDs assigned yet.
FortiBleed dumps 73,932 Fortinet firewall creds; CISA orders resets
Researcher Bob Diachenko found an open attacker server holding plaintext admin and SSL VPN credentials for 73,932 FortiGate appliances across 194 countries. CISA issued reset guidance June 18.
NGINX 1.31.2 / 1.30.3 patches HTTP/3 UAF (CVE-2026-42530) and two more
F5 shipped NGINX 1.31.2 and 1.30.3 on June 17 fixing a use-after-free in the HTTP/3 module, a heap overflow in proxy_v2/grpc, and a buffer overread in charset.
Mastra npm scope hijacked: 142 packages backdoored via easy-day-js
Microsoft documents the @mastra npm takeover: 142 packages republished in 88 minutes on June 17 with the easy-day-js typosquat, dropping a cross-platform Node.js infostealer.
Cisco SD-WAN Manager CVE-2026-20262 exploited, KEV-added
Second Cisco Catalyst SD-WAN Manager zero-day in two weeks. CVE-2026-20262 is an arbitrary file write under exploitation; CISA gave agencies until June 29 to patch.
CISA adds JCE Joomla CVE-2026-48907 to KEV — pre-auth RCE, CVSS 10
CISA added CVE-2026-48907 to KEV on June 16 — an unauth profile-import chain in the JCE Joomla extension that lets attackers upload and execute PHP. Patch in JCE 2.9.99.5.
LiteSpeed cPanel CVE-2026-54420 in KEV: symlink path to root, second LiteSpeed cPanel KEV in 3 weeks
CISA added CVE-2026-54420 — a CVSS 8.5 symlink-following bug in the LiteSpeed cPanel plugin — to KEV on June 15. Federal patch deadline: June 18.
Chrome ships fix for V8 zero-day CVE-2026-11645, CISA adds to KEV
Google's June 8 Stable Channel pushes 149.0.7827.102/.103 for an actively exploited V8 out-of-bounds read/write. CISA added the CVE to KEV the next day.
CISA gives feds 3 days to patch Ivanti Sentry CVE-2026-10520
Unauthenticated root RCE in Ivanti Sentry. CVSS 10.0. Shadowserver sees exploitation a day after the patch. CISA KEV deadline is June 14.
Fortinet patches unauth command injection in FortiSandbox (CVE-2026-25089)
Crafted HTTP requests against the FortiSandbox web UI yield OS command execution. CVSS 9.1. No active exploitation reported. Fixed in 5.0.6 and 4.4.9.
Langflow CVE-2026-5027 exploited; fix shipped but unlabelled
VulnCheck added CVE-2026-5027 to its KEV on June 8 after detecting in-the-wild exploitation. Path traversal in /api/v2/files yields unauth RCE; ~7,000 instances are publicly exposed.
Everest Forms Pro CVE-2026-3300 exploited since April 13 to plant rogue admins
Wordfence's firewall blocked 29,300+ exploit attempts against a CVSS 9.8 PHP-eval RCE in Everest Forms Pro. Sites pre-1.9.13 should hunt for the rogue admin diksimarina.
Oracle PeopleSoft zero-day CVE-2026-35273 hits 100+ orgs
Oracle ships an out-of-band Security Alert for an unauthenticated RCE in PeopleTools 8.61/8.62. Mandiant ties exploitation since May 27 to ShinyHunters (UNC6240).
Arista EOS CVE-2026-7473 added to CISA KEV — vendor says no patch coming
Tunnel-decap logic flaw in Arista EOS lets crafted VXLAN/GRE/decap-group packets reach configured decap IPs. Exploited in the wild. Arista will not patch — mitigate with ACLs.
Microsoft June 2026 Patch Tuesday: 3 publicly disclosed zero-days
Microsoft's June 9 Patch Tuesday fixes around 200 CVEs and 33 Critical flaws, including publicly disclosed zero-days in BitLocker, HTTP.sys (HTTP/2 Bomb) and CTFMON.
Veeam patches critical RCE in Backup & Replication (CVE-2026-44963)
An authenticated domain user can run code on a domain-joined VBR backup server. CVSS 9.4. Fixed in 12.3.2.4854; v13 is not affected.
Check Point patches IKEv1 VPN bypass CVE-2026-50751, exploited since May
Check Point hotfixes a CVSS 9.3 cert-validation bypass on Remote Access and Mobile Access VPN. Exploitation since May 7, 2026 — one case linked to a Qilin affiliate.
Linux nf_tables CVE-2026-23111: full LPE chain now public via Exodus
Exodus Intelligence published a complete local root exploit for CVE-2026-23111 — a one-character nf_tables UAF patched upstream Feb 5. Container escape on default distros.
CISA adds SolarWinds Serv-U CVE-2026-28318 to KEV, DoS in the wild
CISA added CVE-2026-28318 — an unauthenticated DoS in SolarWinds Serv-U — to KEV on June 5. CVSS 7.5. Fix is 15.5.4 Hotfix 1. FCEB deadline June 19.
Anthropic patches Claude Code GitHub Action repo-takeover chain
GMO Flatt Security's RyotaK chained a checkWritePermissions bot bypass with prompt injection to hijack any public repo running claude-code-action. Fix shipped in v1.0.94.
Cisco SD-WAN Manager CVE-2026-20245 exploited, no patch yet
Cisco disclosed a command-injection zero-day in Catalyst SD-WAN Manager on June 5. Mandiant credited as reporter. CVSS 7.8, exploitation observed, no fix available.
VS Code github.dev zero-day exposed full GitHub OAuth tokens in one click
Researcher Ammar Askar dropped a webview-postMessage exploit on June 2 that steals github.dev OAuth tokens via a single click. Microsoft shipped a stopgap fix the next day.
CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog
CISA added the two-year-old Oracle WebLogic auth-bypass CVE-2024-21182 to KEV on June 1, citing active exploitation. Federal agencies have until June 4 to patch.
Android Framework zero-day CVE-2025-48595 added to CISA KEV
Google's June 2026 Android Security Bulletin fixes 124 flaws, including a Framework integer overflow under limited, targeted exploitation. CISA wants federal agencies patched by 5 June.
HTTP/2 Bomb (CVE-2026-49975) drops nginx, Apache, IIS, Envoy
Calif researchers crash 32 GB of Envoy memory in seconds with one connection. nginx 1.29.8 and Apache mod_http2 2.0.41 are patched; IIS, Envoy and Cloudflare Pingora are not.
Red Hat npm packages backdoored: Miasma worm hits @redhat-cloud-services
Red Hat security bulletin RHSB-2026-006 confirms 32 @redhat-cloud-services npm packages were trojaned on June 1, 2026 with a self-spreading credential-stealing worm derived from Shai-Hulud.
Windows Netlogon RCE CVE-2026-41089 now exploited in the wild
Belgium's CCB confirms active exploitation of the CVSS 9.8 Netlogon stack-overflow patched by Microsoft in May. Unauthenticated, no user interaction, domain controller takeover.
CIFSwitch: 19-year-old Linux CIFS bug gives any local user root
Researcher Asim Manizada disclosed CIFSwitch on May 28 — a cifs.spnego upcall flaw that grants root on default Mint, Rocky, AlmaLinux, Kali, and SUSE 15 SP7.
Marimo CVE-2026-39987 RCE chains into LLM-driven post-exploit
Sysdig documents an LLM agent driving post-exploitation after a CVE-2026-39987 Marimo notebook compromise: cloud creds and SSH key pulled in under three minutes.
npm supply-chain campaign: 14 typosquats target AWS, Vault, npm tokens
Microsoft says a single maintainer 'vpmdhaj' pushed 14 typosquatted npm packages on May 28 that exfiltrate AWS, ECS, HashiCorp Vault and npm tokens via a Bun-runtime payload.
Palo Alto GlobalProtect auth bypass (CVE-2026-0257) added to CISA KEV after weeks of exploitation
PAN-OS portals with authentication-override cookies on a shared certificate let attackers forge a valid session. Rapid7 observed exploitation since May 17. Federal patch deadline June 19.
FortiClient EMS bug CVE-2026-35616 now drops EKZ stealer as fake patch
Arctic Wolf says attackers are using the pre-auth FortiClient EMS flaw to push a previously undocumented infostealer disguised as a Fortinet endpoint update.
CISA links GitHub repo exfiltration to malicious Nx Console 18.95.0
CISA's May 28 alert ties the 3,800-repo GitHub breach to a poisoned Nx Console VS Code extension. CVE-2026-48027 is in KEV. Federal deadline June 10.
Gitea CVE-2026-27771: anyone could pull your private container images, no login
An access-control flaw in Gitea's container registry let anonymous clients pull images marked private. Patched in 1.26.2. Forgejo affected too.
Starlette BadHost (CVE-2026-48710): one Host header bypasses auth in FastAPI, vLLM, MCP
X41 D-Sec discloses CVE-2026-48710 in Starlette <1.0.1: a Host-header re-parse desync that lets attackers forge request.url.path. Upgrade to 1.0.1.
KnowledgeDeliver CVE-2026-5426: Mandiant traces RCE to shared ASP.NET keys
Mandiant traces a zero-day in Japan's KnowledgeDeliver LMS to ASP.NET machineKey values reused across customers — enabling unauthenticated ViewState RCE and BLUEBEAM web-shell drops.
CISA flags Langflow CVE-2025-34291: CORS chain yields RCE
CISA added CVE-2025-34291 to the KEV catalog on May 21. An overly permissive CORS plus a misconfigured refresh-token cookie chain to account takeover and code execution in Langflow ≤ 1.6.9.
Ghost CMS SQLi (CVE-2026-26980) hijacks 700+ sites — Harvard, Oxford, DuckDuckGo serve ClickFix
An unauthenticated SQL injection in Ghost's Content API leaks admin API keys. Attackers chain it into stored XSS and a fake Cloudflare ClickFix lure. Upgrade to 6.19.1.
Trend Micro Apex One CVE-2026-34926 exploited; CISA deadline June 4
Trend Micro patches a directory-traversal flaw in the Apex One server after observing in-the-wild exploitation. CISA orders federal agencies to remediate by June 4.
Canvas LMS breach: ShinyHunters claims 275M records; Instructure says it paid for deletion
ShinyHunters exfiltrated 3.65 TB from Instructure's Canvas LMS, defaced login pages at 330 schools, then accepted a payment in exchange for 'returning' the data. The data is still out there.
Drupal patches highly critical SQL injection (CVE-2026-9082) — exploited in the wild within 48h
An unauthenticated SQL injection in Drupal core's database abstraction API affects every PostgreSQL-backed site. Drupal scored it 23/25. Attacks started two days after the patch dropped.
Laravel-Lang Composer packages hijacked — 700+ versions ship a credential stealer
Attackers rewrote Git tags across four Laravel-Lang repos to point at a malicious fork, planting a Composer-autoloaded stealer that runs on every request. Packagist has unlisted the packages.
LiteSpeed cPanel plugin RCE (CVE-2026-48172, CVSS 10.0) actively exploited — any cPanel user can run code as root
A privilege-escalation flaw in the LiteSpeed User-End cPanel plugin lets any cPanel account execute arbitrary scripts as root. Mass scanning began within 72 hours of disclosure.