Google released security updates to address 12 vulnerabilities impacting the Chrome browser. One of these vulnerabilities, tracked as CVE-2026-85046, is being exploited in the wild. CVE-2026-85046 is a type confusion vulnerability in the V8 JavaScript engine. CISA acknowledged the active exploitation of the vulnerability by adding it to its Known Exploited Vulnerabilities Catalog. CISA urges users … Continue reading “Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)”
CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of two vulnerabilities affecting the SonicWall SMA1000. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.
CISA Added JFrog Artifactory Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2026-82329)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of a vulnerability impacting JFrog Artifactory, tracked as CVE-2026-82329. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before September 5, 2026.
Langflow Remote Code Execution Vulnerability Exploited in Attacks (CVE-2026-0768)
A vulnerability impacting Langflow is being exploited in the wild. Tracked as CVE-2026-0768, the vulnerability has a critical severity rating with a CVSS score of 9.8. Successful exploitation of the vulnerability may allow a remote attacker to execute arbitrary code on affected installations of Langflow. Peter Girnus, William Gamazo Sanchez, and Alfredo Oliveira of Trend Research have discovered and reported the vulnerability to Langflow.
Veeam Released Patches for Critical Vulnerability (CVE-2026-65641)
Veeam released a security advisory addressing a vulnerability affecting Veeam ONE. Tracked as CVE-2026-65641, the vulnerability has a critical severity rating with a CVSS score of 9.3. Successful exploitation of the vulnerability may allow an unauthenticated network attacker to coerce SMB authentication from the service account.
PaperCut NG/MF Zero-day Vulnerability Exploited in the Attacks (CVE-2026-82078 & CVE-2026-81578)
PaperCut released an Urgent Security Advisory to address two actively exploited vulnerabilities, tracked as CVE-2026-82078 & CVE-2026-81578, impacting all versions of PaperCut NG and PaperCut MF. When chained together, these vulnerabilities can enable pre-authentication remote code execution in the PaperCut Application Server. The flaw originates from a request-confusion/authorization gap. The vendor has mentioned in their … Continue reading “PaperCut NG/MF Zero-day Vulnerability Exploited in the Attacks (CVE-2026-82078 & CVE-2026-81578)”
CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns users about the active exploitation of Zimbra vulnerability, tracked as CVE-2026-73570. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 24, 2026. The vulnerability exists in the SNMP monitoring component when SNMP notifications are enabled. Successful exploitation of the vulnerability … Continue reading “CISA Warns of Zimbra OS Command Injection Vulnerability Active Exploitation (CVE-2026-73570)”
Oracle Critical Patch Update, August 2026 Security Update Review
Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle Hyperion received the highest number of patches, 262. … Continue reading “Oracle Critical Patch Update, August 2026 Security Update Review”
CISA Warns of Apple macOS Vulnerability Exploited in Attack (CVE-2026-65400)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently acknowledged the active exploitation of the macOS vulnerability. Tracked as CVE-2026-65400, the vulnerability affects macOS Tahoe, macOS Sequoia, and macOS Sonoma. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch it before August 21, 2026. Alfredo Pesoli via Bynario Atlas discovered and reported the vulnerability to Apple.
Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)
Cisco released a security advisory to address a high-severity vulnerability tracked as CVE-2026-20349. The vulnerability impacts the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. Successful exploitation of this vulnerability could allow an unauthenticated, remote attacker to cause the affected device … Continue reading “Cisco ASA and FTD DoS Vulnerability Exploited in the Wild (CVE-2026-20349)”