Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • CVE-2026-9586: Switchvox RCE Exploited in the Wild Do Son
    CVE-2026-9586, a critical Sangoma Switchvox vulnerability, is exploited in the wild, giving unauthenticated attackers SQL injection and remote code execution. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post CVE-2026-9586: Switchvox RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-18885 (CVSS 10): ServiceNow Code Injection and SQL Injection Flaws Patched Do Son
    ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post CVE-2026-18885 (CVSS 10): ServiceNow Code Injection and SQL Injection Flaws Patched appeared first on
     
  • ✇Cybersecurity News
  • CVE-2026-20030: Cisco Crosswork SQL Command Injection Scores CVSS 10.0 Do Son
    Cisco patches a Crosswork SQL injection flaw, CVE-2026-20030, rated CVSS 10.0. A BroadWorks XXE bug (CVE-2026-20320) also gets a fix. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-20030: Cisco Crosswork SQL Command Injection Scores CVSS 10.0 appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-0075: PoC Discloses Android EoP With No User Interaction Do Son
    A public PoC for CVE-2026-0075 exposes an Android elevation of privilege in ContactsProvider2 with no user interaction. Details are now disclosed. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-0075: PoC Discloses Android EoP With No User Interaction appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public Do Son
    A GeoServer unauthenticated SQL injection (CVSS 9.8) is exploited in the wild. A public PoC reaches RCE. Patch GeoServer now. Related Posts: CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups The post GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public appeared first
     
  • ✇Cybersecurity News
  • CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext Do Son
    Phoenix Contact patched three PLCnext flaws, including CVE-2025-41771, which lets an attacker execute unauthorized SQL queries, plus a CVSS 9.8 RCE bug. Related Posts: Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 CVE-2026-15826: User Profile Builder Bug Under Active Attack, Grants Full Admin Takeover (CVSS 9.8) The post CVE-2025-41771: SQL Injection Flaw Hits Phoenix Contact PLCnext appeared first on Daily CyberSe
     
  • ✇Cybersecurity News
  • Metabase SQL Injection Zero-Day (CVSS 10) Exploited Do Son
    A critical Metabase SQL injection zero-day (CVSS 10) is exploited in the wild. Unauthenticated attackers gain admin access. Patch now. Related Posts: CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public The post Metabase SQL Injection Zero-Day (CVSS 10) Exploited appeared first on Daily CyberSecurity.
     
❌
❌