Vulnerabilities
Threat actors are exploiting a critical-severity vulnerability in Motors theme for WordPress to change arbitrary user passwords.
Hi, what are you looking for?
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
Threat actors are exploiting a critical-severity vulnerability in Motors theme for WordPress to change arbitrary user passwords.
WhatsApp told SecurityWeek that it linked the exploited FreeType vulnerability CVE-2025-27363 to a Paragon exploit.
Cisco has resolved a high-severity vulnerability in Meraki MX and Meraki Z devices. Atlassian pushed patches for multiple third-party dependencies.
Misconfigured permissions in Google’s Gerrit code collaboration platform could have led to the compromise of ChromiumOS and other Google projects.
Citrix has released patches for critical- and high-severity vulnerabilities in NetScaler and Secure Access Client and Workspace for Windows.
Qualys has disclosed two Linux vulnerabilities that can be chained for full root access, and CISA added a flaw to its KEV catalog.
Google has released a Chrome 137 update to resolve two memory bugs in the browser’s V8 and Profiler components.
Veeam and BeyondTrust have resolved several vulnerabilities that could be exploited for remote code execution.
GreyNoise warns of a spike in exploitation attempts targeting a two-year-old vulnerability in Zyxel firewalls.
CISA warns that a vulnerability impacting multiple discontinued TP-Link router models is exploited in the wild.
A high-severity authorization bypass vulnerability in Asus Armoury Crate provides attackers with low-level system privileges.
Mitel has announced patches for a MiCollab path traversal vulnerability that can be exploited remotely without authentication.
Trend Micro patches critical-severity Apex Central and Endpoint Encryption PolicyServer flaws leading to remote code execution.
Learn how attackers hide in plain sight—and what you can do to stop them without slowing down your business.
Palo Alto Networks has released patches for seven vulnerabilities and incorporated the latest Chrome fixes in its products.
Patches released by Fortinet and Ivanti resolve over a dozen vulnerabilities, including high-severity flaws leading to code execution, credential leaks.
Google and Mozilla have released patches for a combined total of four high-severity memory bugs in Chrome and Firefox.
Patch Tuesday: Adobe documents hundreds of bugs across multiple products and warns of code execution, feature bypass risks.
Redmond warns that external control of a file name or path in WebDAV "allows an unauthorized attacker to execute code over a network."
Security researchers uncover critical flaws and widespread misconfigurations in Salesforce’s industry-specific CRM solutions.