Thursday , July 30 2026

Vulnerabilities

Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 actively exploited 0 days

April

Microsoft’s April 2026 security update has fixed 167 flaws in its products. This update includes 2 serious zero-day threats and another flaw that needs urgent attention from organizations. Zero-Day Under Active Exploitation The main flaw this month is CVE-2026-32201, a flaw in Microsoft SharePoint Server that is being actively used …

Read More »

Active Exploits & 0-Day Threats
Fortinet Flaw Under Attack While CrowdStrike EDR 0-Day Gets Reverse Engineered

Fortinet

The Cybersecurity and Infrastructure Security Agency (CISA) has made an urgent warning about a serious security flaw in Fortinet products. On April 13, 2026, the agency put a severe SQL injection threat into its Known Exploited Vulnerabilities (KEV) list. This shows that attackers are using the flaw in real situations. …

Read More »

Infosecbulletin Weekly CVE Briefing (April 6 – April 12, 2026)

Week

During the past seven days (week) , security researchers and organizations tracked a total of 1,615 vulnerabilities requiring immediate triage and context. The severity distribution for these threats highlights a significant volume of high-risk entries that security teams must prioritize. . Vulnerability Severity Breakdown: The following breakdown categorizes the week‘s …

Read More »

“sockpuppeting” can jailbreak 11 AI models like ChatGPT, Claude, and Gemini

“sockpuppeting”

Newly identified jailbreak technique dubbed “sockpuppeting” lets attackers bypass the safety guardrails of 11 major large language models (LLMs) using a single line of code. This method uses APIs that allow assistant prefill to add fake acceptance messages. This makes models give answers to banned requests. The attack takes advantage …

Read More »

Palo Alto Fixes 3 Security Flaws: Agent Disabling to System Privileges

Palo Alto

Palo Alto Networks has issued important updates to fix 3 different flaws in its security products. These issues affect the Cortex XDR Agent, the Autonomous Digital Experience Manager (ADEM), and Cortex XSOAR/XSIAM platforms. The flaws include ways to skip local protection and access resources without permission. The first flaw, known …

Read More »

IBM Identity and Verify Access Vulns Allow to Access Sensitive Data

Verify Access

A security bulletin alert points out several flaws in IMB Verify Identity Access and Security Verify Access products. Tracked as CVE-2026-2862 and CVE-2026-1491, these flaws in HTTP request smuggling come from problems with reverse proxy management and have a CVSS score of 5.3. A remote attacker who is not logged in …

Read More »

Fortinet FortiClient EMS 0-Day Flaw Actively Exploited

EMS

Fortinet has released an urgent fix after security experts disclosed a zero-day flaw in FortiClient EMS that is being used by hackers. CVE-2026-35616 is an Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Successful attacks do not …

Read More »