CISA added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog on Monday due to evidence of active exploitation.
The list of flaws is as follows:
By infosecbulletin
/ Saturday , July 18 2026
A new free tool is adding AI helpers into security work. PentestCode is a version of OpenCode made just for...
Read More
By infosecbulletin
/ Saturday , July 18 2026
The WordPress security team received reports about these flaws: CVE-2026-60137 : A facilitated SQL injection issue reported as a team...
Read More
By infosecbulletin
/ Friday , July 17 2026
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges,...
Read More
By infosecbulletin
/ Thursday , July 16 2026
Zoom has issued updates for a flaw in the Windows desktop client, known as CVE-2026-53412. This issue may allow an...
Read More
By infosecbulletin
/ Thursday , July 16 2026
India is speeding up its work to make homegrown AI models for cybersecurity. These models will help protect important digital...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
Microsoft's Patch Tuesday in July 2026 fixes around 570 security flaws in its products. This comes after June's big update,...
Read More
By infosecbulletin
/ Wednesday , July 15 2026
Fortinet fixes seven new security warnings on July 14, 2026. These affect FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The issues vary...
Read More
By infosecbulletin
/ Tuesday , July 14 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are using CVE-2008-4128, a CSRF flaw in Cisco...
Read More
By infosecbulletin
/ Tuesday , July 14 2026
Meta announced on Monday that its data center in Richland Parish, Louisiana, will grow to 5 gigawatts of computing power....
Read More
CVE-2014-3931 (CVSS score: 9.8) A buffer overflow vulnerability in Multi-Router Looking Glass (MRLG) that could allow remote attackers to cause an arbitrary memory write and memory corruption.
CVE-2016-10033 (CVSS score: 9.8) A command injection vulnerability in PHPMailer that could allow an attacker to execute arbitrary code within the context of the application or result in a denial-of-service (DoS) condition.
CVE-2019-5418 (CVSS score: 7.5) A path traversal vulnerability in Ruby on Rails’ Action View that could cause contents of arbitrary files on the target system’s file system to be exposed
CVE-2019-9621 (CVSS score: 7.5) A Server-Side Request Forgery (SSRF) vulnerability in the Zimbra Collaboration Suite that could result in unauthorized access to internal resources and remote code execution.
No public reports exist on the exploitation of the first three vulnerabilities in real attacks. However, Trend Micro linked the exploitation of CVE-2019-9621 to a Chinese threat actor named Earth Lusca in September 2023, who used it to deploy web shells and Cobalt Strike.
Billions Of Gmail And Outlook Users At Risk