Visualização de leitura

FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately

FreeRDP released version 3.31.0, addressing 22 security flaws and multiple bugs in its open-source Remote Desktop Protocol implementation, and urges users and distributors to update promptly.

FreeRDP is widely used by Linux systems, thin clients, remote-access tools, and enterprise applications to connect to Windows Remote Desktop Services.

Because it processes network data from remote servers and supports features such as graphics, smart cards, USB redirection, clipboard sharing, and authentication, memory-handling mistakes can create serious security exposure.

The 3.31.0 release includes fixes for 22 GitHub Security Advisories, covering issues reported through the project’s security process. The advisory identifiers include GHSA-c5gr-hmqp-pwj4, GHSA-h5w2-q35j-443h, GHSA-m85m-3qxv-63h5, and 19 others.

While the release notes do not provide public technical details for every flaw, the vendor’s “update ASAP” warning shows that maintainers consider the addressed issues significant.

FreeRDP Fixes 22 Security Flaws

Several changes in the release point to security-sensitive code paths. FreeRDP fixed bounds checking in the AVC444v2 YUV decoder, which processes remote desktop graphics data.

It also corrected parsing and length-validation problems in dynamic virtual channels, Remote Desktop Gateway tunnel responses, clipboard format lists, smart-card data, USB redirection, and device-redirection components.

The update further resolves use-after-free conditions involving the printer driver singleton and the reallocation of aligned memory. Use-after-free bugs occur when software continues to access memory after it has been released.

Depending on the affected code path and surrounding protections, such flaws can lead to application crashes, information disclosure, or possibly remote code execution. Authentication and cryptographic components also received attention.

The release improves NTLM and SSPI memory handling, adds checks before accessing signature buffers, fixes SPNEGO mechanism fallback behavior, and improves error handling when BIO or SSL object creation fails.

These changes are important because FreeRDP often handles authentication exchanges and encrypted connections to remote systems.

In addition to security fixes, version 3.31.0 brings performance improvements. The project said an optimized YUV decoder should deliver faster client-side graphics for AVC and H.264 remote desktop sessions. It also adds support for more hardware decoders and switches AV1 decoding to dav1d in supported configurations.

Administrators should identify systems that package or embed FreeRDP, including desktop clients, remote-access gateways, virtual desktop tools, and third-party products built on the library.

Organizations should install FreeRDP 3.31.0 through their supported distribution channel or build the updated release from the official source package. Teams should also verify the downloaded archive using the published SHA-256 checksum and signature where possible.

Prompt patching is especially important for systems that connect to untrusted or internet-exposed RDP servers. The official release includes source archives, ZIP packages, signatures, and checksums for version 3.31.0.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post FreeRDP Fixes 22 Security Flaws and Urges Users to Update Immediately appeared first on Cyber Security News.

Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks

SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances.

The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands.

The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident Response Team investigated a case indicating active exploitation.

SonicWall urged organizations to install the available platform hotfixes immediately and review exposed systems for signs of compromise.

The vulnerabilities affect SMA1000 6210, 7210, and 8200v appliances running version 12.4.3-03453 or earlier, as well as version 12.5.0-02835 or earlier. SonicWall stated that SSL-VPN services running on SonicWall firewalls and the SMA 100 Series product line are not affected.

SonicWall RCE Vulnerabilities Exploited

The most severe issue is tracked as CVE-2026-83548 and carries a CVSS score of 10.0. It is a pre-authentication server-side request forgery vulnerability in the SMA1000 Appliance Workplace interface.

According to SonicWall, the flaw stems from an unintended alternate access path that can serve as a forward proxy. A remote, unauthenticated attacker could exploit this path to access sensitive internal functionality and perform unauthorized operations.

The vulnerability is associated with CWE-918, covering server-side request forgery, and CWE-441, which describes an unintended proxy or confused-deputy condition.

SSRF vulnerabilities are especially dangerous in remote-access appliances because they can allow attackers to make requests from the device itself, potentially bypassing network restrictions designed to protect internal services.

SonicWall also addressed CVE-2026-83549, a post-authentication remote code execution flaw in the SMA1000 Appliance Management Console.

The vulnerability has a CVSS score of 7.8 and stems from improper neutralization of special characters in operating system commands.

An authenticated attacker with administrator privileges could exploit the command injection issue to execute arbitrary commands on the appliance operating system.

While this vulnerability requires valid administrator access, it could be especially damaging when chained with another weakness that provides unauthorized access to appliance functions.

Remote-access infrastructure remains a high-value target because it often sits at the edge of enterprise networks and handles user authentication, VPN connectivity, and access to internal resources.

A compromised SMA appliance may provide attackers with a foothold for credential theft, lateral movement, and further network intrusion.

There is no workaround for either issue. Organizations should upgrade SMA1000 appliances to version 12.4.3-03526 or later, or to version 12.5.0-02952 or later, depending on the software branch they have deployed.

SonicWall also recommends contacting technical support to review appliances for indicators of compromise. If compromise indicators are found, organizations should re-image affected physical appliances or redeploy affected virtual appliances.

Administrators should then change all user and administrator passwords and reset TOTP tokens to invalidate potentially stolen authentication factors.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks appeared first on Cyber Security News.

Critical ServiceNow Flaws Let Attackers Execute Code and Access Data

ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges.

The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through its internal security research and responsible disclosure programs.

ServiceNow said each vulnerability was remediated independently and urged self-hosted customers to promptly apply the available updates or upgrade to a patched release.

ServiceNow Fixes Critical Flaws

Three of the flaws affect the ServiceNow AI platform. CVE-2026-18885 is a critical code injection vulnerability that could allow an unauthenticated attacker, under certain circumstances, to execute arbitrary code within the ServiceNow platform.

Successful exploitation could also let an attacker access or modify instance data beyond intended permissions. This creates a serious risk for organizations that use ServiceNow to manage IT operations, security workflows, employee requests, customer service records, and enterprise automation.

An attacker who gains unauthorized code execution may be able to abuse the platform’s access to connected business processes and sensitive operational information.

The second critical issue, tracked as CVE-2026-18886, is another code injection flaw in the ServiceNow AI platform. ServiceNow said an unauthenticated attacker could potentially create or alter instance data outside expected authorization limits. This could lead to privilege escalation, enabling an attacker to gain broader access than originally granted.

The third critical vulnerability, CVE-2026-74820, is a SQL injection flaw affecting the ServiceNow AI platform. If exploited, the issue could allow an unauthenticated attacker to execute arbitrary SQL statements against the affected instance’s underlying database.

This could expose sensitive data stored in ServiceNow environments or allow attackers to modify database-backed records. ServiceNow also addressed CVE-2026-6876, a high-severity sandbox escape vulnerability in the Now Platform.

The company said the issue could allow an unauthenticated user to execute arbitrary code on the platform and potentially gain access beyond what was intended.

Sandbox escape flaws are particularly concerning because they can allow attackers to break out of restricted execution environments designed to limit the impact of untrusted code.

Customers enrolled in the ServiceNow Patching Program have already received the appropriate updates. However, organizations should verify that their instances are running a fixed version.

Patched releases include Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b, Patch 13 Hot Fix 4, and later supported fixes; Zurich Patch 7b Hot Fix 3 through Patch 12; and Australia Patch 2 Hot Fix 3 through Patch 5.

Organizations operating self-hosted ServiceNow deployments should treat the three critical AI platform vulnerabilities as a priority.

Security teams should confirm installed versions, apply relevant hotfixes, review privileged access, and monitor instance activity for suspicious data changes, unexpected code execution, or abnormal database queries.

The post Critical ServiceNow Flaws Let Attackers Execute Code and Access Data appeared first on Cyber Security News.

BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges

BeyondTrust has disclosed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) product for Windows that could allow attackers with local access to elevate privileges or bypass anti-tamper controls.

Tracked as CVE-2026-40144 and CVE-2026-40145, the flaws affect all versions of BeyondTrust Endpoint Privilege Management (Windows Deployment) released before version 26.1.2. The company published the advisory, BT26-04, on August 17, 2026.

BeyondTrust said the vulnerabilities were discovered internally during security assessment activities using frontier AI models and proprietary testing harnesses. The company said it has found no evidence that either flaw was exploited before remediation.

The most serious vulnerability, CVE-2026-40144, has a CVSS v4 score of 7.3 and is classified as high severity. It is an out-of-bounds read issue, identified as CWE-125, in a kernel-mode component of BeyondTrust EPM for Windows.

The flaw exists because the affected kernel component does not sufficiently validate certain input. A local attacker with standard, non-administrative user privileges could potentially cause the component to access memory outside its intended bounds.

BeyondTrust Windows EPM Vulnerabilities

Successful exploitation could enable an attacker to corrupt kernel memory and execute arbitrary code in kernel mode. Since kernel-mode code has the highest privilege level in Windows, an attacker could potentially gain full control of the affected endpoint.

The vulnerability requires local access, meaning it cannot be directly exploited over the internet without another method of gaining a foothold on the system.

However, local privilege-escalation bugs are often valuable to attackers after they compromise a low-privileged user account via phishing, malware, stolen credentials, or another initial access technique.

The second flaw, CVE-2026-40145, carries a CVSS v4 score of 7.1. It is an insufficient access-control vulnerability, tracked as CWE-1220, involving an interaction between a BeyondTrust EPM support utility and the product’s anti-tamper protections.

Under specific conditions, protections applied to the support utility process may not be enforced as intended. An attacker who already has elevated privileges on an endpoint may be able to influence the utility and execute code outside the intended scope of EPM’s anti-tamper controls.

Unlike the first issue, CVE-2026-40145 requires an attacker to possess already elevated privileges, local access, and additional endpoint-specific preconditions.

While it does not provide an initial path to administrator access, it could help attackers weaken security controls once they have gained privileged access.

BeyondTrust has fixed both issues in Endpoint Privilege Management (Windows Deployment) version 26.1.2. Organizations using affected versions should upgrade endpoints to version 26.1.2 or later as soon as possible.

Security teams should also review systems for unusual local privilege escalation activity, unexpected kernel-level crashes, suspicious process behavior involving EPM support utilities, and attempts to disable or interfere with endpoint security controls.

The advisory highlights the importance of promptly patching privilege-management tools. These products often run with elevated permissions and enforce critical security boundaries, making vulnerabilities in their kernel components or anti-tamper mechanisms especially attractive to attackers.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post BeyondTrust Windows EPM Vulnerabilities Allows Attackers to Escalate Privileges appeared first on Cyber Security News.

Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS

Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application crashes, kernel memory access, and arbitrary code execution.

The updates were released on August 17, 2026, and include macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and iPadOS 18.7.10. The company said the patches include fixes that were previously delivered through iOS, iPadOS, and macOS beta releases.

Apple follows a policy of withholding technical details about security flaws until it completes an investigation and security updates are broadly available.

Several flaws affect components that process media, web content, and graphics. Apple fixed an integer overflow in ImageIO that could allow a specially crafted image to trigger arbitrary code execution. A separate ImageIO issue could cause a denial-of-service condition when a vulnerable device processes a malicious image.

Apple Fixes 28 Security Vulnerabilities

The updates also address multiple issues in IOGPUFamily, an Apple graphics framework. Apple warned that malicious web content could cause memory corruption.

At the same time, other flaws could enable remote attackers to terminate a system unexpectedly or allow a local application to read kernel memory. Such bugs are significant because the kernel runs with high privileges and controls core operating-system functions.

An additional kernel-level issue in the older iOS 18.7.10 and iPadOS 18.7.10 releases could allow a malicious application to execute arbitrary code with kernel privileges via a buffer overflow. Apple resolved the flaw through improved size validation.

Apple patched an Audio logic issue that could allow an application to leak sensitive user information. The company addressed the problem by adding improved checks. This vulnerability affects both macOS Tahoe 26.6.2 and the newer iOS and iPadOS releases.

The mobile updates also include an Accessibility fix for devices running iOS 18.7.10 and iPadOS 18.7.10. Apple said an attacker with physical access could potentially access sensitive data during iPhone Mirroring. This feature links an iPhone with a Mac. The issue was fixed through improved state management.

CVEComponentAffected release(s)ImpactVulnerability type / remediation
CVE-2026-65339AudioiOS/iPadOS 26.6.1; macOS Tahoe 26.6.2An app may leak sensitive user informationLogic issue; improved checks
CVE-2026-65347ImageIOiOS/iPadOS; macOSProcessing an image may cause DoSImproved checks
CVE-2026-65346ImageIOiOS/iPadOS; macOSProcessing an image may enable arbitrary code executionInteger overflow; improved input validation
CVE-2026-64788IOGPUFamilyiOS/iPadOS; macOSCrafted web content may cause memory corruptionImproved memory handling
CVE-2026-65343KerneliOS/iPadOS; macOSRemote attacker may terminate the systemUse-after-free; improved memory management
CVE-2026-65349KerneliOS/iPadOS; macOSApp may terminate the system or read kernel memoryOut-of-bounds read; improved input validation
CVE-2026-65330KerneliOS/iPadOS; macOSApp may terminate the system or corrupt kernel memoryImproved memory handling
CVE-2026-65329TelephonyiOS 26.6.1 only; iPhone 11 and laterPrivileged network attacker may bypass IPSec authentication and intercept trafficAuthentication issue; improved state management
CVE-2026-64784WebKitiOS/iPadOS; macOSCrafted web content may crash SafariOut-of-bounds access; improved bounds checking
CVE-2026-43795WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved memory handling
CVE-2026-65338WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved memory handling
CVE-2026-65341WebKitiOS/iPadOS; macOSCrafted web content may cause memory corruptionImproved memory handling
CVE-2026-64782WebKitiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved locking
CVE-2026-64781WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved input validation
CVE-2026-65351WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65340WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65337WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65336WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65335WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65333WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65332WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-65331WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved state management
CVE-2026-64715WebKitiOS/iPadOS; macOSCrafted web content may cause an unexpected process crashUse-after-free; improved memory management
CVE-2026-64780WebKitiOS/iPadOS; macOSCrafted web content may crash SafariImproved checks
CVE-2026-65334WebKitiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved state management
CVE-2026-43794WebKitiOS/iPadOS; macOSCrafted web content may cause memory corruptionMemory-corruption flaw; improved memory handling
CVE-2026-64787WebKitiOS/iPadOS; macOSCrafted web content may terminate a processUse-after-free; improved memory management
CVE-2026-64778WebKit HistoryiOS/iPadOS; macOSVisiting a crafted website may leak sensitive dataImproved checks
CVE-2026-64779WebKit StorageiOS/iPadOS; macOSCrafted web content may crash SafariMemory-corruption flaw; improved locking

Apple also corrected an IPSec authentication issue in iOS 26.6.1 and iPadOS 26.6.1. A threat actor in a privileged network position could bypass IPSec authentication and intercept network traffic, posing a risk to users on hostile or compromised networks.

iOS 26.6.1 and iPadOS 26.6.1 are available for iPhone 11 and later, supported iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

The iOS 18.7.10 and iPadOS 18.7.10 updates protect older iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th-generation devices. Users should install the updates promptly. Apple notes that iPhone, iPad, Apple TV, Apple Watch, and Vision Pro software cannot be downgraded after an update is installed.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS appeared first on Cyber Security News.

Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely

Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or Configuration Manager.

The flaws could allow an attacker to execute malicious code remotely on an SCCM primary site server, potentially taking control of an organization’s managed Windows environment.

The attack is especially concerning because a standard Active Directory domain user could start the original chain. The account does not need SCCM administrative permissions, elevated Windows privileges, or user interaction.

A successful attack targets the SCCM primary site server, a critical system responsible for software deployment, patching, operating system installation, compliance monitoring, and device management.

Microsoft SCCM Vulnerability

XM Cyber reported the vulnerabilities to Microsoft on May 23. Microsoft assigned CVE-2026-47301 to the broken authorization issue and released a fix on July 14, 2026.

However, researchers said the remaining weaknesses in the chain are still unpatched. Microsoft plans to address them in ConfigMgr 2609, expected in October 2026.

The first issue involved SCCM’s AdminService REST API. SCCM supports uploading console extension packages through CAB archives. One upload endpoint checked for the required role-based access control permission.

In contrast, a chunked upload endpoint did not perform the same authorization check. This allowed authenticated domain users to submit specially crafted CAB files to the server.

Chain Overview (Source : xmcyber )
Chain Overview (Source : xmcyber )

The second weakness affected signature validation. SCCM checked whether a CAB archive had a valid embedded signature, but reportedly did not enforce that the signing certificate belonged to Microsoft or the victim organization.

It also skipped certificate revocation checks. As a result, an attacker could use a certificate that SCCM accepted to sign a malicious extension package.

Researchers also identified a path traversal flaw called “CabSlip.” During CAB extraction, SCCM failed to block relative path sequences properly. A crafted archive could write files outside the intended temporary extraction folder.

This gave attackers arbitrary file write access on the site’s server. The final step abused DLL loading behavior in the SMS Executive service. SMS Executive runs with NT AUTHORITY\SYSTEM privileges.

Although it validates a primary DLL, the service can load a secondary DLL named adsource.dll without performing equivalent integrity checks.

An attacker could overwrite that DLL through the path traversal flaw. When SCCM later loads the library, the malicious code would run as SYSTEM. Microsoft’s July update blocks standard domain users from abusing the chunked upload endpoint.

Yet users assigned the built-in Operations Administrator role, or a custom role with Create permission on the SMS_ConsoleExtensionData object, may still access the downstream attack path.

Defenders should monitor AdminService.log for DirectoryNotFoundException errors followed by HTTP 500 responses, inspect unexpected CAB upload activity, and watch for changes to adsource.dll in the Configuration Manager installation directory.

Organizations should also restrict access to the AdminService network port and urgently review SCCM role assignments until Microsoft releases a complete fix.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely appeared first on Cyber Security News.

Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities

Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code execution flaw, server-side request forgery bypasses, injection vulnerabilities, and stored cross-site scripting issues.

Administrators using Roundcube 1.6.x or 1.7.x should update as soon as possible. The most serious issue is a remote code execution vulnerability in the markasjunk plugin. The flaw affects the plugin’s cmd_learn driver, which is used to send messages to a spam-learning backend.

Security researcher nept1337 reported the issue. Successful exploitation could allow an attacker to execute commands within the affected Roundcube environment, posing a direct risk to the webmail server and potentially to other systems reachable from it.

Roundcube is widely used as a browser-based interface for email services. Because it processes email content, connects to IMAP servers, and may integrate with LDAP directories, Sieve filters, and spam-management tools, a compromise can provide a useful entry point into an organization’s messaging infrastructure.

Roundcube 1.6.18 and 1.7.3 Released With Fix

An RCE vulnerability in this environment could enable attackers to steal mail data, establish persistence, or pivot to internal services. The release also fixes SSRF filter bypass vulnerabilities in Roundcube’s local URL validation logic.

SSRF occurs when an attacker can make an application send requests to locations chosen by the attacker, including internal services that are not publicly accessible. One bypass involved special local address ranges, including 100.64.0.0/10 and fe80::/10.

Another used crafted nip.io and sslip.io hostnames that could evade the is_local_url() check. Dmytro Ivanenko and Milan Hoppe reported the issues.

In a practical scenario, an attacker could exploit an SSRF vulnerability to request an internal administrative page, a cloud metadata endpoint, or a service running only on a private network interface.

The impact depends on network design and outbound access controls. However, webmail servers with broad internal connectivity may face greater exposure.

Other fixes in the two releases include an LDAP filter injection flaw, arbitrary Sieve script injection, IMAP command injection, stored XSS in the “Add to address book” action, and HTML/CSS sanitization bypasses.

Roundcube also fixed a password-driver issue that could expose an authentication token to a user-controlled host. Researchers credited for the broader set of findings include Zach Hanley of Horizon3.ai, Paulos Yibelo of pwn.ai, vectrain, and meifukun.

Affected deployments include Roundcube 1.6.x versions earlier than 1.6.18 and 1.7.x versions earlier than 1.7.3. Roundcube has not reported confirmed in-the-wild exploitation in its advisory. However, the range and severity of the patched bugs make rapid remediation important.

Administrators should upgrade to Roundcube 1.6.18 or 1.7.3, depending on their release branch. They should also review whether the markasjunk plugin is required and disable it if it is not in use.

Organizations can further reduce SSRF risk by restricting outbound connections from the Roundcube host and limiting its access to sensitive internal services.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities appeared first on Cyber Security News.

Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges

TP-Link has disclosed multiple high-severity vulnerabilities affecting ISP-managed Aginet networking products, including mesh systems, routers, PON devices, and xDSL modems.

The flaws could allow attackers with network access to bypass authentication, escalate privileges, steal sensitive information, read device files, and execute operating system commands.

The security advisory, last updated on August 10, 2026, tracks the issues as CVE-2025-30237 through CVE-2025-30241. The affected products are commonly supplied, configured, and updated by internet service providers, meaning firmware availability may vary by operator and region.

The most serious flaw, CVE-2025-30237, is an authentication bypass vulnerability in the web management interface. It has a CVSS v4 score of 8.7 and results from broken access control on certain endpoints.

An attacker on an adjacent network may send specially crafted requests to reach privileged functions without providing valid credentials. If exploited, the issue could give an unauthenticated attacker full control of the affected device.

Multiple TP-Link Vulnerabilities

CVE-2025-30238, rated 8.6, is an improper authorization flaw in user-management functions. A low-privileged authenticated user may be able to perform administrator-level actions, including creating privileged accounts or changing critical device settings. This could allow an attacker with limited access to expand their control over a router or mesh node.

Another high-severity issue, CVE-2025-30239, involves hardcoded cryptographic keys stored in firmware. The vulnerability has a CVSS score of 8.5.

An attacker with access to the device’s storage could recover the embedded keys and decrypt protected configuration data. Exposed information may include credentials and ISP-related service settings, creating a risk of further compromise.

CVE-2025-30240 is a medium-severity arbitrary file-read issue with a CVSS score of 5.1. The flaw affects the USB HTTPS access path and stems from improper handling of symbolic links on external USB storage.

A person with physical access to the device may create a malicious symbolic link on a supported medium and use it to access sensitive files in the router filesystem.

CVEVulnerabilitySeverity
CVE-2025-30237Authentication bypassHigh
CVE-2025-30238Privilege escalationHigh
CVE-2025-30239Sensitive data exposureHigh
CVE-2025-30240Arbitrary file readMedium
CVE-2025-30241OS command injectionHigh

The final issue, CVE-2025-30241, is an OS command injection vulnerability with a severity rating of 8.6. It exists because some web-interface components fail to properly validate user-controlled input before passing it to system-level command functions.

An authenticated attacker on the local network could inject commands and execute them with elevated privileges, potentially taking complete control of the device. Affected hardware includes models from TP-Link’s HB, HX, HC, EB, EC, EX, XC, XX, and VX series.

Examples include HB810, HB710, EX220, EX222, EX920, EC220-G5, XX530v, and VX1800v variants. The exact impact depends on the regional model, hardware version, ISP customizations, and installed firmware.

TP-Link said remediation for ISP-managed devices will be coordinated through service providers. In many cases, updates may be installed automatically through ISP management platforms.

Users should check the router administration interface or the provider’s management application for firmware updates. If an update is unavailable, customers should contact their ISP to confirm whether their device is affected and when a patched firmware release will be deployed.

Because several flaws require local or adjacent-network access, users should also restrict exposure of management interfaces, use strong, unique administrator credentials, turn off unnecessary remote management features, and keep untrusted users off the local network.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges appeared first on Cyber Security News.

Cisco Patches Multiple Critical Cisco IOS XE Software Vulnerabilities – Patch Now!

Cisco has released a critical security hardening update for Cisco IOS XE Software, fixing several serious vulnerabilities that could expose enterprise network devices to remote attacks.

The advisory covers vulnerabilities identified during Cisco’s internal security testing, including testing supported by frontier AI models.

Cisco said it is not aware of public exploitation or malicious activity linked to these flaws. However, the severity of the issues, combined with the lack of available workarounds, makes prompt patching essential.

The vulnerabilities affect Cisco IOS XE Software running in autonomous mode or controller mode, regardless of device configuration. Cisco assessed releases 17.9, 17.12, 17.15, 17.18, and 26.1 as part of this review. Cisco Catalyst 3650 and 3850 Series Switches were not evaluated because they do not run the reviewed releases.

The most severe issue is CVE-2026-20272, which carries a maximum CVSS score of 9.8 out of 10. The flaw is linked to CWE-74, or improper neutralization of special elements. This weakness can include command injection, operating system injection, and argument injection risks.

Cisco Patches Critical IOS XE Flaws

If successfully exploited, such weaknesses may allow an attacker to execute unintended commands or alter how a system processes input.
Cisco also addressed CVE-2026-20267, an improper access control issue rated 9.0.

This vulnerability falls under CWE-284 and includes risks involving authentication bypasses, authorization failures, privilege issues, and other access-control weaknesses. Attackers could potentially abuse these conditions to gain access beyond their intended permissions.

Several other vulnerabilities received a maximum CVSS score of 8.6. CVE-2026-20268 involves memory buffer restrictions, including possible buffer overflows and out-of-bounds writes.

CVE-2026-20269 relates to improper resource lifetime management, such as invalid memory handling, null pointer dereferences, and file handler issues.

Cisco also patched CVE-2026-20270, which covers incorrect calculations and numeric conversion problems, including integer overflow and truncation.

CVE-2026-20271 addresses insufficient control-flow management, including race conditions, uncontrolled recursion, and infinite loops. CVE-2026-20273 concerns improper input validation, with potential impacts including path traversal and unsafe external path handling.

CVE IDVulnerability ClassCWEMaximum CVSS Score
CVE-2026-20267Improper access controlCWE-2849.0
CVE-2026-20268Improper restriction of operations within a memory bufferCWE-1198.6
CVE-2026-20269Improper control of a resource through its lifetimeCWE-6648.6
CVE-2026-20270Incorrect calculationCWE-6828.6
CVE-2026-20271Insufficient control-flow managementCWE-6918.6
CVE-2026-20272Improper neutralization of special elements, including command injectionCWE-749.8
CVE-2026-20273Improper input validationCWE-208.6

Cisco has confirmed that there are no workarounds for these flaws. Organizations using affected IOS XE releases must install the fixed software versions to remediate the exposure fully.

Cisco strongly recommends affected organizations immediately upgrade to fixed software releases, as outlined in advisory cisco-sa-hardening-iosxe-V8NMuMZJ published on August 5, 2026. The first patched versions are IOS XE 17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, and 26.1.2.

Network administrators should first identify all Cisco IOS XE devices in their environment and confirm their currently installed release. They should then review hardware capacity, configuration compatibility, and maintenance windows before upgrading.

Because IOS XE devices often support core routing, switching, wireless, and controller functions, patching should be carefully planned and treated as a high-priority security task.

Cisco PSIRT validates only the affected and fixed release information listed in the advisory. Organizations should also monitor Cisco security advisories for additional fixes and upgrade guidance.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Cisco Patches Multiple Critical Cisco IOS XE Software Vulnerabilities – Patch Now! appeared first on Cyber Security News.

Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution

Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable systems. The update, tracked as APSB26-120 and published on August 3, 2026, carries Adobe’s highest priority rating of 1.

The security issues affect Adobe Campaign Classic ACC v7.4.3 build 9398 and earlier on Windows and Linux. Organizations should upgrade to ACC v7.4.3 build 9399 as soon as possible.

Organizations use Adobe Campaign Classic to manage cross-channel marketing campaigns, customer profiles, email workflows, and campaign automation. A successful compromise could give attackers access to sensitive marketing data, internal infrastructure, customer information, and connected systems.

Adobe Campaign Classic Vulnerabilities

The most serious flaws are three unauthenticated remote vulnerabilities (CVSS 10.0) that can lead to arbitrary code execution: CVE-2026-48331 – Server-side request forgery (SSRF), CVE-2026-48323 – Template engine injection, CVE-2026-48330 – SQL injection.

Their CVSS vectors show that an attacker could exploit them remotely over a network without requiring authentication or user interaction. This makes internet-facing and externally accessible Campaign Classic deployments especially important to patch quickly.

CVE-2026-48331 is an SSRF vulnerability. SSRF bugs can allow an attacker to make the vulnerable server send requests to internal services, cloud metadata endpoints, or systems that are normally inaccessible from the internet. In certain environments, this can help attackers access credentials, map internal networks, or reach administrative services.

Adobe also fixed another SQL injection vulnerability, CVE-2026-48326, rated 9.9 out of 10. Unlike the maximum-severity SQL injection flaw, exploiting this issue requires low-level privileges. However, a malicious authenticated user or an attacker with stolen credentials could potentially use it to execute code and compromise the underlying server.

CVE-2026-48333, rated 9.8, is an incorrect authorization vulnerability that could allow privilege escalation. Attackers may exploit such flaws to access functions or data beyond their intended permissions.

The remaining issues include CVE-2026-48317, an eval injection vulnerability with a CVSS score of 9.6, and CVE-2026-48399, a security feature bypass flaw with a CVSS score of 7.5.

Eval injection can occur when an application processes dynamic code unsafely, potentially allowing attackers to run attacker-controlled commands.

Adobe said it is not aware of any exploits targeting these vulnerabilities in the wild. However, the critical severity, remote attack paths, and lack of authentication requirements make rapid remediation essential.

The Adobe bulletin applies to on-premise and hybrid Adobe Campaign Classic deployments, while Adobe-hosted instances have already been remediated and require no customer action.

Security teams should identify exposed Campaign Classic servers, apply build 9399, review administrative accounts, restrict unnecessary network access, and monitor logs for unusual requests, unexpected database activity, or suspicious changes to privileges.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution appeared first on Cyber Security News.

❌