CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.
Related Posts:
Critical Google Chrome Vulnerabilities Patched in New Update
CVE-2026-80047: Hugging Face Transformers Library Vulnerability
CVE-2026-68162: Linux Kernel Root Escalation PoC Public
The post CVE-2026-9586: Switchvox RCE Exploited in the Wild appeared first on Daily CyberSecurity.
CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution.
ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug.
Related Posts:
Critical MongoDB Security Vulnerabilities Require Immediate Patching
CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device
D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login
The post CVE-2026-18885 (CVSS 10): ServiceNow Code Injection and SQL Injection Flaws Patched appeared first on
Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix.
Related Posts:
CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM
CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM
CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1)
The post CVE-2026-20030: Cisco Crosswork SQL Command Injection Scores CVSS 10.0 appeared first on Daily CyberSecurity.
A public PoC for CVE-2026-0075 exposes an Android elevation of privilege in ContactsProvider2 with no user interaction. Details are now disclosed.
Related Posts:
CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM
CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM
CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1)
The post CVE-2026-0075: PoC Discloses Android EoP With No User Interaction appeared first on Daily CyberSecurity.
A GeoServer unauthenticated SQL injection (CVSS 9.8) is exploited in the wild. A public PoC reaches RCE. Patch GeoServer now.
Related Posts:
CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups
The post GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public appeared first
Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug.
Related Posts:
Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs
Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8)
The post CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext appeared first on Daily CyberSe
Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug.
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems.
A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure.
A security researcher with the handler q1uf3ng discloded the vulnerability that has yet to be assigned a CVE identifier.
实话说今天是非常不开心的一天 实际上最近一段时间
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems.
A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure.
A security researcher with the handler q1uf3ng discloded the vulnerability that has yet to be assigned a CVE identifier.
The flaw lies in the jsonArrayContains functionality and allows unauthorised SQL injection. Under some configurations, especially where the service can reach a privileged database account, that path may lead to remote code execution
The vulnerability has yet to be assigned a CVE identifier.
The issue was publicly disclosed on 12 August 2026. Within hours, watchTowr said it had begun seeing exploitation attempts, with hundreds of probes coming from a small number of IP addresses.
“Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses. Yet another example of how quickly attackers move once a vulnerability enters the public domain,” said WatchTowr’s Jake Knott.
That timing matters. Once a proof of concept or enough technical detail is public, attackers don’t need to wait for a polished exploit. They can scan broadly, trigger errors, compare responses, and build a list of systems worth revisiting later. It’s reconnaissance with an error message as a compass.
Threat actors are probing vulnerable GeoServer systems, but no follow-up activity has been observed yet. However, researchers warn exploitation could soon escalate.
“However, this is unlikely to remain the case for long: GeoServer has a track record of being targeted and exploited at scale, with multiple vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog,” Knott added.
“With no patch currently available and exploitation already underway, organizations running GeoServer should take this vulnerability seriously and, where possible, identify exposed instances, restrict public access, and monitor for a vendor fix,”
Attackers are probing GeoServer systems for the unpatched zero-day, triggering errors to identify vulnerable targets before likely exploitation.
GeoServer is a popular platform for publishing and sharing geographic data through web services. It appears in public-sector portals, environmental platforms, mapping projects, utilities, transport systems, research institutions, and internal business applications. That makes a remotely reachable instance more than a technical footnote; it may expose geospatial information, backend services, credentials, or a route into a wider network.
The absence of a patch changes the usual response. Teams cannot simply schedule an update and move on. They need to identify every GeoServer instance, determine whether it is internet-facing, restrict access wherever possible, inspect logs for unusual requests and database errors, and limit the permissions available to the application’s database account.
This is also not GeoServer’s first encounter with active exploitation. In 2024, attackers used the critical GeoServer GeoTools vulnerability CVE-2024-36401 (CVSS score of 9.8), to pull compromised systems into DDoS and cryptocurrency-mining botnets and residential proxy networks. That history does not prove that every exposed instance will be compromised this time, but it does make complacency hard to defend.
The practical priority is exposure reduction. Put GeoServer behind a VPN, a reverse proxy, IP allow-listing, or another access-control layer if the service does not need to be public. If public access is unavoidable, treat it as a temporary high-risk exception, watch it closely, and prepare to apply the vendor fix as soon as it arrives.
A critical Metabase SQL injection zero-day (CVSS 10) is exploited in the wild. Unauthenticated attackers gain admin access. Patch now.
Related Posts:
CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw
CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day
Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public
The post Metabase SQL Injection Zero-Day (CVSS 10) Exploited appeared first on Daily CyberSecurity.
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.
The post Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn appeared first on TechRepublic.
Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.