Microsoft’s April 2026 security update has fixed 167 flaws in its products. This update includes 2 serious zero-day threats and another flaw that needs urgent attention from organizations. Zero-Day Under Active Exploitation The main flaw this month is CVE-2026-32201, a flaw in Microsoft SharePoint Server that is being actively used …
Read More »
Active Exploits & 0-Day Threats
Fortinet Flaw Under Attack While CrowdStrike EDR 0-Day Gets Reverse Engineered
The Cybersecurity and Infrastructure Security Agency (CISA) has made an urgent warning about a serious security flaw in Fortinet products. On April 13, 2026, the agency put a severe SQL injection threat into its Known Exploited Vulnerabilities (KEV) list. This shows that attackers are using the flaw in real situations. …
Read More »
ALERT
Zombie Microsoft flaws resurface, enabling criminals and ransomware
Crooks are taking advantage of four Microsoft flaws – one fixed 14 years ago and another linked to ransomware – as reported by the top U.S. cyber defense agency, which on Monday told federal agencies they have two weeks to fix them. The four security issues added to CISA’s Known …
Read More »Infosecbulletin Weekly CVE Briefing (April 6 – April 12, 2026)
During the past seven days (week) , security researchers and organizations tracked a total of 1,615 vulnerabilities requiring immediate triage and context. The severity distribution for these threats highlights a significant volume of high-risk entries that security teams must prioritize. . Vulnerability Severity Breakdown: The following breakdown categorizes the week‘s …
Read More »
CVE-2026-34621
Adobe Patches Actively Exploited Acrobat Reader Flaw
Adobe has put out urgent updates to fix a serious security problem in Acrobat Reader that is being actively used for attacks. The flaw known as CVE-2026-34621 has a CVSS score of 8.6 out of 10. If an attacker takes advantage of this issue, they can run harmful code on …
Read More »
ALERT
OpenAI Warns macOS Users to Update ChatGPT Over Axios Breach
OpenAI has shared details about a security issue linked to Axios, a popular third-party JavaScript library, which is part of a larger attack on software supply chains found on March 31, 2026. The company stated in a news release that there is no proof that anyone accessed its user data, …
Read More »“sockpuppeting” can jailbreak 11 AI models like ChatGPT, Claude, and Gemini
Newly identified jailbreak technique dubbed “sockpuppeting” lets attackers bypass the safety guardrails of 11 major large language models (LLMs) using a single line of code. This method uses APIs that allow assistant prefill to add fake acceptance messages. This makes models give answers to banned requests. The attack takes advantage …
Read More »Palo Alto Fixes 3 Security Flaws: Agent Disabling to System Privileges
Palo Alto Networks has issued important updates to fix 3 different flaws in its security products. These issues affect the Cortex XDR Agent, the Autonomous Digital Experience Manager (ADEM), and Cortex XSOAR/XSIAM platforms. The flaws include ways to skip local protection and access resources without permission. The first flaw, known …
Read More »IBM Identity and Verify Access Vulns Allow to Access Sensitive Data
A security bulletin alert points out several flaws in IMB Verify Identity Access and Security Verify Access products. Tracked as CVE-2026-2862 and CVE-2026-1491, these flaws in HTTP request smuggling come from problems with reverse proxy management and have a CVSS score of 5.3. A remote attacker who is not logged in …
Read More »Fortinet FortiClient EMS 0-Day Flaw Actively Exploited
Fortinet has released an urgent fix after security experts disclosed a zero-day flaw in FortiClient EMS that is being used by hackers. CVE-2026-35616 is an Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Successful attacks do not …
Read More »
InfoSecBulletin Cybersecurity for mankind