Visualização de leitura

Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws

Jellyfin has released version 12.0, a significant update to its open-source media server. This version includes a wide range of platform improvements and essential security updates affecting both the server and the web client. The project strongly advises administrators to plan their upgrade carefully because it includes database migrations and compatibility-breaking changes for existing deployments. […]

The post Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access

Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions […]

The post Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released […]

The post ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary […]

The post Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered

Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release […]

The post Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft

TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and […]

The post TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection

Security researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this […]

The post Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS

Three high-severity vulnerabilities in HP Easy Start for macOS could allow both local and network-positioned attackers to disrupt the printer software installation process and, under certain conditions, gain privileged access or modify files with root permissions. These vulnerabilities, tracked as CVE-2026-12554, CVE-2026-12555, and CVE-2026-12556, were discovered by researcher Nir Yehoshua from Cipher Security Labs during […]

The post Three HP Easy Start Flaws Let Attackers Gain Root Privileges on macOS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs

FreeRDP version 3.31.0 has been released as a significant security and stability update, addressing 22 disclosed security vulnerabilities in the widely used open-source implementation of the Remote Desktop Protocol (RDP). Project maintainers have termed this release a “huge bug fix and security release” and strongly encourage distributors to update promptly due to the serious nature […]

The post FreeRDP 3.31.0 Fixes 22 Security Flaws Including Heap Overflow and Pre-Auth DoS Bugs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild

SonicWall has issued an urgent security advisory regarding two vulnerabilities affecting its SMA 1000 Series secure access appliances. The company warns that there have been cases indicating active exploitation in the wild. The vulnerabilities are tracked as CVE-2026-83548 and CVE-2026-83549 and impact SonicWall SMA 1000 models 6210, 7210, and 8200v that are running vulnerable platform […]

The post Critical SonicWall SMA 1000 Vulnerabilities Actively Exploited in the Wild appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws

Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled […]

The post Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root

SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe issue, tracked as CVE-2026-66152, has a CVSS score of 8.8/10 and affects NetExtender Linux Client versions 10.3.5 and earlier. […]

The post SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities

Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This stable-channel update is being rolled out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS. This update is significant due to the sheer number and severity of memory-safety issues fixed across Chrome’s […]

The post Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code

Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code execution on exposed on-premises servers. The flaws, tracked as CVE-2026-55040 and CVE-2026-63520, affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft SharePoint Flaws The urgency has increased after Defused reported […]

The post Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Multiple Zscaler Client Connector Flaws Enable Remote Code Execution

Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context. This vulnerability, tracked as CVE-2026-59568, is rated as Critical, with a CVSS v3.1 score of 9.1. The attack vector is network-accessible and requires no privileges or user interaction. Multiple […]

The post Multiple Zscaler Client Connector Flaws Enable Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts

Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later […]

The post Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data

A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind DN, granting them the ability to read or modify data stored in an application’s in-memory LDAP directory. This issue, tracked as CVE-2026-59270, was disclosed on August 20, […]

The post Critical Spring Security LDAP Flaw Lets Remote Attackers Read and Modify Directory Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services

Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August […]

The post Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE

Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, access control, server-side request forgery (SSRF), denial-of-service, certificate validation, and information disclosure. Tracked as SVD-2026-0808 and published on August 19, 2026, the […]

The post Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access

Researchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI Scanner interfaces, an authentication flaw tracked as CVE-2026-41473, stored cross-site scripting (XSS) tracked as CVE-2026-41472, and CyberPanel’s built-in cron-job functionality. CyberPanel is […]

The post CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌