Saturday, August 1, 2026
Follow on LinkedIn

Vulnerability

Keycloak Vulnerability Exposes User Names and Email Addresses Across Admin Boundaries

Keycloak has addressed a broken access control vulnerability that could allow restricted administrators to access usernames, email addresses, and other profile information belonging to users outside their permitted scope. This issue, tracked as CVE-2026-17059, affects the Keycloak Admin REST API...

Critical SolarWinds Flaw Lets Attackers Bypass Web Help Desk SAML Login

SolarWinds has patched a critical security vulnerability in its Web Help Desk platform that could allow attackers to bypass SAML-based authentication. CVE-2026-28323 affects SolarWinds Web Help Desk deployments using SAML 2.0 single sign-on (SSO)and was fixed in version 2026.2.1,...

CISA Warns of Cisco Secure Firewall Management 0-Day Vulnerability Exploited in Attacks

CISA has issued a warning regarding a serious vulnerability in the Cisco Secure Firewall Management Center (FMC), which is currently being exploited in attacks. The flaw, identified as CVE-2026-20316, affects Cisco's centralized management platform for firewall solutions and could allow...

Cisco Firewall Management Center 0-Day Actively Exploited to Access Sensitive Data

Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This vulnerability, tracked as CVE-2026-20316, arises from static credentials embedded in the FMC web interface. Although the flaw carries a CVSS...

Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices

Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions. The issue, tracked as CVE-2026-57239, was disclosed following research into Foxit’s updater and service...

Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks

A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California,...

CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232,...

ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution

ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked as CVE-2026-13385, impacts multiple ASUS router firmware branches, including the widely deployed 3.0.0.4_386,...

Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files

A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files. Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multiple...

Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers

Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions...

Latest News

Latest News