Visualização normal

Ontem — 7 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • Roundcube Security Update Fixes 12 Webmail Flaws Do Son
    The Roundcube security update fixes 12 webmail flaws, including a zero-click stored XSS and an SSRF bypass. Update to 1.6.19 or 1.7.4 now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post Roundcube Security Update Fixes 12 Webmail Flaws appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • CVE-2026-21580: Stored XSS Hits Atlassian Confluence Do Son
    A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now. Related Posts: CVE-2026-13737: Commvault Command Execution Flaws Expose Networks CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites BeyondTrust EPM Flaws Allow Windows Privilege Escalation The post CVE-2026-21580: Stored XSS Hits Atlassian Confluence appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 Do Son
    Roundcube fixes a webmail RCE flaw and an SSRF filter bypass in versions 1.6.18 and 1.7.3. Update your mail server now. Related Posts: CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code The post Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3 appeared first on Daily Cyber
     
  • ✇Cybersecurity News
  • GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs Do Son
    The new GitLab patch release fixes 13 flaws, including high-severity XSS and authorization bugs. Update to 19.2.2, 19.1.4, or 19.0.6 now. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins Do Son
    A BdThemes supply chain attack poisoned a plugin API feed to run silent XSS in admin browsers, creating rogue admins across WordPress sites. Related Posts: Fake AI Tools Malware Targets Developers Through GitHub DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT Interlock Ransomware Abuses Volatility3 for Credential Theft The post BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution Do Son
    WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now. Related Posts: Metabase SQL Injection Zero-Day (CVSS 10) Exploited Multiple ClamAV Flaws Let Remote Attackers Cause DoS CryptoJS Randomness Vulnerability Drains Crypto Wallets The post CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution appeared first on Daily CyberSecurity.
     
❌
❌