Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

2+ day, 21+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

3+ day, 3+ hour ago   (436+ words) Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports. Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug…...

SecurityWeek
securityweek.com > ivanti-patches-critical-flaws-across-enterprise-security-products

Ivanti Patches Critical Flaws Across Enterprise Security Products

3+ day, 23+ hour ago   (410+ words) Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. Ivanti on Tuesday announced security updates that address vulnerabilities rated critical and high severity in its Neurons for…...

SecurityWeek
securityweek.com > microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

4+ day, 14+ hour ago   (727+ words) Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local…...

SecurityWeek
securityweek.com > adobe-patches-over-170-vulnerabilities-including-commerce-zero-day

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

4+ day, 15+ hour ago   (547+ words) Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score…...

SecurityWeek
securityweek.com > sap-patches-critical-extended-passport-processing-vulnerability

SAP Patches Critical Extended Passport Processing Vulnerability

4+ day, 18+ hour ago   (626+ words) Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability. Tracked as…...

SecurityWeek
securityweek.com > elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

1+ week, 20+ hour ago   (589+ words) Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is…...

SecurityWeek
securityweek.com > hpe-patches-critical-rce-vulnerabilities-in-aos-cx-2

HPE Patches Critical RCE Vulnerabilities in AOS-CX

1+ week, 20+ hour ago   (479+ words) Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in its Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are…...

SecurityWeek
securityweek.com > sangoma-switchvox-vulnerabilities-exploited-in-the-wild

Sangoma Switchvox Vulnerabilities Exploited in the Wild

1+ week, 1+ day ago   (533+ words) Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn. Tracked as CVE-2026-9586 (CVSS…...

SecurityWeek
securityweek.com > vmware-workstation-and-fusion-updates-patch-critical-vulnerability

VMware Workstation and Fusion Updates Patch Critical Vulnerability

1+ week, 1+ day ago   (440+ words) The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as…...