Monday , September 28 2026

Vulnerabilities

Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention

A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges, change admin accounts, and run code with admin rights. The public proof‑of‑concept (PoC) from the MSNightmare GitHub account describes the bug as a “Windows user profile service arbitrary hive load …

Read More »

Fortinet Patches 7 Flaws In FortiOS, FortiProxy, FortiPAM, and FortiSandbox

FortiPAM

Fortinet fixes seven new security warnings on July 14, 2026. These affect FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The issues vary from minor header problems to more serious buffer overflows and a troubling issue with VNC access in FortiSandbox. While none carry a critical rating, several affect widely deployed enterprise firewall …

Read More »

Attackers exploit critical flaw in Oracle E-Business

Oracle E-Business Suite

Attackers are now using a flaw (called CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial app, according to the security firm Defused. This security issue was discovered in the File Transmission part of EBS’s Oracle Payments product. It allows hackers without authentication and with HTTP network access to take over weak …

Read More »

ALERT
Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

SD-WAN

Cisco on Monday told customers about a new SD-WAN product flaw used in attacks. The flaw, called CVE-2026-20262, is a medium-severity issue that lets files be written anywhere in the Catalyst SD-WAN Manager. “This file could later be used to elevate to root,” Cisco explained, adding, “To exploit this vulnerability, …

Read More »

Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

Wazuh

A critical security flaw has affected the open-source security community. Recently, complete details and working exploit code were shared online. This critical Wazuh  flaw lets verified endpoints change central log systems directly. So, any company testing this new platform must take urgent action. If not, they risk major damage to …

Read More »

Microsoft June Patches 200 Vulnerabilities including 3 zero days

June

Microsoft’s June 2026 Patch Tuesday updates fix about 200 security flaws found in the company’s products. None of the flaws fixed this month seem to have been used by anyone outside, but three issues were shared publicly before Microsoft fixed them. One of them is CVE-2026-49160, which is a denial-of-service (DoS) …

Read More »

VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts

VMware

Broadcom has revealed three stored cross-site scripting (XSS) flaws that affect VMware Cloud Foundation Operations and some other products. They warn that attackers who are logged in could add harmful scripts to do admin tasks in the system. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the issues were fixed in the …

Read More »