CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)

CISA has warned U.S. government agencies about an actively exploited vulnerability impacting Cisco Secure Firewall Management Center. CISA added the CVE-2026-20316 to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 1, 2026. Successful exploitation of this vulnerability could allow an attacker to log in to the affected system and access sensitive data as … Continue reading “CISA Warns of Cisco Secure Firewall Management Center Vulnerability (CVE-2026-20316)”

JetBrains TeamCity Remote Code Execution Vulnerability (CVE-2026-63077)

JetBrains released a security advisory addressing a critical severity vulnerability impacting TeamCity On-Premises. Tracked as CVE-2026-63077, successful exploitation of the vulnerability may allow an unauthenticated attacker to bypass authentication checks and execute arbitrary operating system commands. JetBrains mentioned in their advisory that they are not aware of any active exploitation of this vulnerability.

VMware ESX, vCenter, Workstation, and Fusion Multiple Vulnerabilities

Broadcom has released a security advisory addressing five vulnerabilities affecting VMware ESX, vCenter, Workstation, and Fusion. Three of these vulnerabilities, tracked as CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, have been given critical severity ratings.

Adobe Releases Patches for Multiple Critical Vulnerabilities

Adobe released two security advisories addressing nine vulnerabilities affecting the Adobe Bridge and Adobe Format Plugins. All these vulnerabilities have critical severity ratings given by Adobe.

Oracle Critical Patch Update, July 2026 Security Update Review

Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this quarterly Oracle Critical Patch Update, Oracle E-Business Suite received the highest … Continue reading “Oracle Critical Patch Update, July 2026 Security Update Review”

WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)

Threat actors have released public exploit code for the WordPress core remote code execution vulnerabilities, named wp2shell. Tracked as CVE-2026-63030 and CVE-2026-60137, the vulnerabilities can be chained together to achieve pre-authentication remote code execution. Adam Kues of Searchlight Cyber discovered and reported the vulnerability to WordPress. The article mentioned that more than 500 million websites use WordPress, which … Continue reading “WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)”

Mozilla Firefox Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-15718 & CVE-2026-15719)

Mozilla released a security update to address two vulnerabilities impacting the Firefox browser, tracked as CVE-2026-15718 & CVE-2026-15719. Mozilla mentioned in the advisory that they are aware that exploit code for this is public; however, they are unaware of any attacks in the wild abusing this flaw. CVE-2026-15718 This is an invalid pointer vulnerability exists … Continue reading “Mozilla Firefox Zero-day Vulnerabilities Exploited in Attacks (CVE-2026-15718 & CVE-2026-15719)”

Microsoft Patch Tuesday, July 2026 Security Update Review

Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes, highlights … Continue reading “Microsoft Patch Tuesday, July 2026 Security Update Review”

CISA Warns About Langflow Authorization Bypass Vulnerability Exploitation (CVE-2026-55255)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently acknowledged the active exploitation of the Langflow vulnerability. Tracked as CVE-2026-55255, the vulnerability may allow an authenticated attacker to execute another user’s flow by specifying the victim’s flow ID in the request. The vendor has given this vulnerability a critical severity rating with a CVSS score of 9.9. CISA added the vulnerability to … Continue reading “CISA Warns About Langflow Authorization Bypass Vulnerability Exploitation (CVE-2026-55255)”

Adobe Releases Patches for ColdFusion Critical Vulnerabilities

Adobe released security updates to address 11 vulnerabilities impacting the ColdFusion web app development platform and the Campaign Classic marketing automation platform. Six of these vulnerabilities have a maximum severity that can be exploited in low-complexity attacks without any user interaction. Adobe has mentioned in the advisory that they are unaware of any active exploits of these vulnerabilities.