Check Point Research found that CVE-2026-50751, a serious flaw in Check Point Remote Access VPN and Mobile Access, is being actively used by attackers. It can let them bypass authentication (CVSS 9.3). CVE-2026-50751 affects systems using the old IKEv1 key exchange method. A remote attacker can take advantage of a …
Read More »CVE-2026-50751
Cisco SD-WAN Flaw Exploited and Trend Micro Flaws Allows to Security Bypass
Trend Micro’s Deep Security Agent for Linux has a design flaw. This issue lets a local attacker, who does not have special access, create short “blind spots.” During these moments, endpoint protections are not working temporarily. The issue stems from how the agent unloads and reloads its bmhook and tmhook …
Read More »
CVE-2026-20230
Cisco Patches in Unified CM as Exploit Code Goes Public
Cisco has fixed a flaw in Unified Communications Manager that allows an attacker on the network to write files to the system and then gain full access. It is known as CVE-2026-20230, and proof of concept exploit code is already available. Cisco’s PSIRT says they have not seen anyone use this …
Read More »TP-Link Router Flaw Enables Remote Command Execution Attacks
TP-Link has revealed a serious security problem in its Archer BE450 and Archer BE7200 Wi-Fi routers. This flaw could let an attacker run commands from afar if they get admin access. The flaw, called CVE-2026-5509, has a score of 8.5 (High) in CVSS v4.0, showing how dangerous it is for …
Read More »
ALERT
Google patches one exploited Android zero-day and 124 issues
Google has shared the June 2026 Android security updates to fix 124 flaws, including one zero-day issue used in special attacks. Local attackers can take advantage of a serious Android Framework flaw (known as CVE-2025-48595) to run code and gain higher access on devices using Android 14 or newer. “There are …
Read More »CISA warns two-year-old Oracle Vuln as actively exploited in attacks
CISA has given a new warning about a serious Oracle WebLogic Server flaw, named CVE-2024-21182, and added it to its Known Exploited Vulnerabilities list on June 1, 2026. The alert highlights the growing danger from open enterprise middleware systems, especially those that can be accessed through network protocols like T3 …
Read More »CISA gives feds 4 days to fix cPanel plugin vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has told U.S. federal agencies to secure their servers in four days. This is because of a serious weakness in the LiteSpeed cPanel user-end plugin that is being used in attacks. This vulnerability, called CVE-2026-48172, lets someone gain higher access due to …
Read More »
CVE-2026-25724
Terra Security researchers discovered Flaws in Anthropic’s Claude Code
Terra Security shared results from recent tests that showed flaws in AI apps, agents, and AI-made code workflaws. The company has launched a new module for its constant testing platform. This lets security experts keep simulating attacks on AI systems to find flaws. Terra has tested different applications made with …
Read More »SonicWall Firewall Targeted by Hackers; 597,000 Sessions Observed
A big increase in scanning across the internet for SonicWall firewall management interface has been observed. GreyNoise, a threat intelligence company, found a big increase in scans of SonicWall SonicOS management APIs from May 9 to May 18, 2026. The most notable spike occurred on May 12, when approximately 597,000 …
Read More »Cisco and Splunk patches for multiple flaws: Update now
Splunk has put out security updates for many flaws in Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit. These issues could cause denial-of-service (DoS) attacks and expose sensitive information. The flaws revealed on May 20, 2026, have three known weaknesses: CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240. Organizations should quickly apply …
Read More »
InfoSecBulletin Cybersecurity for mankind