A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges, change admin accounts, and run code with admin rights. The public proof‑of‑concept (PoC) from the MSNightmare GitHub account describes the bug as a “Windows user profile service arbitrary hive load …
Read More »Cursor, SonicWall, SharePoint 0-day exploited to the wild
A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers run any code on Windows systems. Just opening a harmful repository can start this process. It doesn’t need any clicks, confirmations, or approvals from the user. The flaw was found by …
Read More »Microsoft Patch Tuesday July-2026 fixes 570 flaws, 3 zero-days
Microsoft’s Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June’s big update, which had a record 206 issues and three that were already known to the public. This big update comes after Microsoft’s recent change to use artificial intelligence for finding security …
Read More »Fortinet Patches 7 Flaws In FortiOS, FortiProxy, FortiPAM, and FortiSandbox
Fortinet fixes seven new security warnings on July 14, 2026. These affect FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The issues vary from minor header problems to more serious buffer overflows and a troubling issue with VNC access in FortiSandbox. While none carry a critical rating, several affect widely deployed enterprise firewall …
Read More »Attackers exploit critical flaw in Oracle E-Business
Attackers are now using a flaw (called CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial app, according to the security firm Defused. This security issue was discovered in the File Transmission part of EBS’s Oracle Payments product. It allows hackers without authentication and with HTTP network access to take over weak …
Read More »F5 Patches NGINX Flaw for Code Execution and DoS Attacks
F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and cause denial-of-service (DoS) attacks in affected systems. The notice, published on June 17, 2026, points out important problems affecting NGINX Open Source, NGINX Plus, and related products like NGINX Gateway …
Read More »
ALERT
Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks
Cisco on Monday told customers about a new SD-WAN product flaw used in attacks. The flaw, called CVE-2026-20262, is a medium-severity issue that lets files be written anywhere in the Catalyst SD-WAN Manager. “This file could later be used to elevate to root,” Cisco explained, adding, “To exploit this vulnerability, …
Read More »Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion
A critical security flaw has affected the open-source security community. Recently, complete details and working exploit code were shared online. This critical Wazuh flaw lets verified endpoints change central log systems directly. So, any company testing this new platform must take urgent action. If not, they risk major damage to …
Read More »Microsoft June Patches 200 Vulnerabilities including 3 zero days
Microsoft’s June 2026 Patch Tuesday updates fix about 200 security flaws found in the company’s products. None of the flaws fixed this month seem to have been used by anyone outside, but three issues were shared publicly before Microsoft fixed them. One of them is CVE-2026-49160, which is a denial-of-service (DoS) …
Read More »VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts
Broadcom has revealed three stored cross-site scripting (XSS) flaws that affect VMware Cloud Foundation Operations and some other products. They warn that attackers who are logged in could add harmful scripts to do admin tasks in the system. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the issues were fixed in the …
Read More »
InfoSecBulletin Cybersecurity for mankind