Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,” Microsoft …
Read More »Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that FortiOS 7.2.x and 7.4.x are affected. The listing has not been independently verified and does not confirm the existence of a new FortiGate zero-day vulnerability. The ad by Dark Web …
Read More »CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks
CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers are using this flaw in real attacks. The flaw, known as CVE-2026-76461, impacts Cisco AsyncOS software on Cisco Secure Email Gateway devices. CVE-2026-76461 is a type of SQL injection flaw, listed …
Read More »Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft
GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and credential theft. There is also a major flaw that might let someone run code from afar. The company launched new versions of GitLab Community Edition and Enterprise Edition. These are versions …
Read More »Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution
Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run any code with full control on affected PA-Series hardware firewalls. Tracked as CVE-2026-0310, the flaw is in XML processing, and the seller says it is very urgent. The weakness is …
Read More »Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks
Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used in attacks. The flaw has a highest CVSS score of 10.0. It lets remote attackers, who are not logged in, get around security checks and run scripts or commands as the …
Read More »cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root
cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take full control of affected servers. cPanel announced this issue on September 8, 2026. They say that an attacker needs a valid cPanel account with email rights to use this weakness. …
Read More »FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited
An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access trojan (RAT). This makes the affected devices key points for spying and stealing information. The SOCRadar Threat Research Unit has found that attackers are using CVE-2025-25249. This is a serious …
Read More »The first zero-click worm to spread through WeChat calls across iOS and Android
A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target’s WeChat account in seconds without the victim having to answer the call. Calif researchers said the bug was reported to Tencent in July. Tencent has fixed the issue for users, but …
Read More »
ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass
Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could let users and servers face cross-site scripting, email header issues, data access from other users, remote content tricks, and attacks that misuse server requests. The new versions, Roundcube 1.6.19 and …
Read More »
InfoSecBulletin Cybersecurity for mankind