Thursday , July 30 2026

Vulnerabilities

Microsoft Patch Tuesday May 2026 fixed 120 flaws, Including 29 Critical RCE

Microsoft’s May 2026 Patch Tuesday brings many updates for businesses. It fixes 120 security flaws in Windows, Office, Azure, developer tools, and Microsoft 365 apps. Among these, 29 critical flaws let attackers run code from far away. Microsoft says there are no zero-days used in attacks or announced before this …

Read More »

Palo Alto to Patch Zero-Day Flaw Exploited to Gain Root Access

zero-day flaw

Palo Alto Networks is fixing a serious PAN-OS zero-day flaw that was used to hack some of its firewall. Tracked as CVE-2026-0300, this issue is a buffer overflow that affects the User-ID Authentication Portal (Captive Portal) service of PAN-OS software. “Limited exploitation has been observed targeting Palo Alto Networks User-ID …

Read More »

WhatsApp Reveals File Spoofing, URL Scheme Flaw

Flaw

Meta-owned WhatsApp has released two new security warnings about flaws fixed earlier this year in the well-known messaging app. One issue is CVE-2026-23863, a medium-risk attachment spoofing problem that affects WhatsApp for Windows before version 2.3000.1032164386.258709. An attacker could use the flaw to make a harmful document with NUL bytes …

Read More »

Apache Server Exposes Millions of Servers to Remote Code Execution Attacks

Apache

The Apache Software Foundation launched an important security update for Apache HTTP Server. This update fixes five security issues, including a serious double-free problem that could allow Remote Code Execution (RCE) in version 2.4.67, which came out on May 4, 2026. All users with version 2.4.66 or older should upgrade …

Read More »

CVE-2026-31431
CISA Adds Actively Exploited Linux “Copy Fail” 0-Day Vuln Exploited to Root Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a new security flaw affecting different Linux versions to its list of Known Exploited Vulnerabilities (KEV). They mentioned that there is proof of this flaw being used in real attacks. The flaw, known as CVE-2026-31431 (CVSS score: 7.8), is a type …

Read More »

PoC released for cPanel Vulnerability: 44,000 Servers Compromised

PoC

A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to the compromise of tens of thousands of servers worldwide with attack activity traced as far back as late February 2026. CVE-2026-41940 is a …

Read More »