The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a serious security flaw in Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities catalog on Friday, noting it was actively being exploited despite a patch released in June 2024. CVE-2024-37079 (CVSS score: 9.8) is a vulnerability related to a heap …
Read More »
CVE-2026-20045
Cisco discloses Unified Communications RCE zero day flaw exploited in attacks
Cisco revealed a zero-day RCE vulnerability, CVE-2026-20045, that is being actively exploited. The vulnerability in key Unified Communications products lets unauthenticated attackers execute arbitrary commands on the OS, risking root access. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability …
Read More »NVIDIA Patches High-Severity Flaws in AI Tools And Graphics
NVIDIA has issued a dual security alert for developers and data scientists, announcing important updates for its Nsight Graphics and Merlin recommender system. Both vulnerabilities have a high CVSS score of 7.8 and can allow harmful code injection attacks that may compromise entire systems. The flaws jeopardize the tools needed …
Read More »Oracle patched 337 flaws for over 30 products
Oracle released 337 security patches for more than 30 products in its January 2026 Critical Patch Update (CPU), targeting approximately 230 unique CVEs. Several patches fix CVE-2025-66516 (CVSS score 10/10), a serious Apache Tika vulnerability that may allow XML External Entity (XXE) injection. The vulnerability affects three Apache Tika modules …
Read More »Zoom Critical Command Injection Vuln allows Remote Code Execution
A critical command injection flaw in Node Multimedia Routers (MMRs) may let meeting participants run arbitrary code on vulnerable systems. CVE-2026-22844 is a highly critical vulnerability with a CVSS score of 9.9, indicating an urgent need for immediate action. Zoom Command Injection Vulnerability: A command injection flaw is found in …
Read More »GPT-5.2 Can Develop Zero-Day Exploits: Study unveils
Recent research shows that AI systems can now handle complex exploit development tasks that used to need specialized human skills. The agents had to create exploits while facing realistic challenges like modern security measures, unknown heap conditions, and restrictions on hardcoded memory addresses. In six scenarios focused on tasks like spawning …
Read More »TP-Link Router Flaw Allows Auth Bypass Via Password Recovery Mechanism
A critical security flaw in TP-Link’s VIGI surveillance cameras allows attackers on local networks to change admin passwords without permission. CVE-2026-0629 identifies a critical flaw in the camera’s web interface password recovery, rated 8.7 on the CVSS v4.0 scale. The authentication bypass issue arises from incorrect client-side state handling in …
Read More »Canon patches multiple flaws allowing hackers remote access
Canon has issued a security alert for its laser and small office printers, revealing seven critical vulnerabilities that could let remote attackers fully control the devices. These flaws, which all have a CVSS score of 9.8, impact many imageCLASS, i-SENSYS, and Satera models available in the US, Europe, and Japan. …
Read More »Cisco 0-Day RCE Secure Email Gateway Vuln actively Exploited
Cisco has confirmed that a serious zero-day vulnerability allowing remote code execution is being actively exploited in its Secure Email Gateway and Secure Email and Web Manager appliances. The CVE-2025-20393 flaw lets unauthorized attackers run arbitrary root commands by sending specific HTTP requests to the Spam Quarantine feature. Cisco aware …
Read More »Chrome 144 Released, Fixing 10 V8 Engine Vulnerabilities
Google has released Chrome 144 for Windows, Mac, and Linux, fixing 10 security issues, mainly in the V8 JavaScript engine. The rollout is scheduled to reach users progressively over the coming days and weeks. Critical Security Patches for V8 Engine: Chrome version 144.0.7559.59 for Linux and 144.0.7559.59/60 for Windows and …
Read More »
InfoSecBulletin Cybersecurity for mankind