Thursday , September 17 2026
cPanel

ALERT
Patch Now! Critical Exchange Server, cPanel, and Kubernetes Flaws Exploited

cPanel & WHM and WP Squared have recently provided fixes for five critical flaws. These issues include the ability to read any file and SQL injection, which threaten server safety and data privacy.

The biggest flaw found this time let anyone get into sensitive system resources without permission.

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

CVE-2026-29205 (CVSS 8.6) – Arbitrary File Read: A mix of wrong privilege dropping and not enough path filtering lets attackers read random files through some cpdavd endpoints. This impacts versions 120 and above.

CVE-2026-32993 (CVSS 8.3) – HTTP Header Injection: An insecure endpoint in cpsrvd was found to let users add any HTTP headers. This affects versions 132 and up.

CVE-2026-32992 (CVSS 8.2) – Credential Theft via DNS Cluster: SSL checks were not completely applied in the DNS Cluster system. A bad server could do a man-in-the-middle attack to steal credentials. This impacts versions 126 and above.

CVE-2026-29206 (CVSS 8.1) – SQL Injection: The sqloptimizer script has a flaw that lets anyone run any SQL query they want. This is important because it affects all versions of cPanel and WHM.

CVE-2026-32991 (CVSS 7.1)  Team Member Privilege Escalation: Low-privilege team users (role=default) can gain full owner rights using certain UAPI modules. This applies to versions 110 and above.

Patches have been sent out to different release levels so all active users can protect their environments.

Exchange Server

Microsoft has sent out an urgent alert for groups using on-site email systems. A new security flaw in Outlook Web Access (OWA) is now being targeted by attackers, who can run harmful code just by sending a specially made email.
The flaw, known as CVE-2026-42897 (CVSS 8.1), is a big risk for company security because it affects the user’s browser.
According to the Exchange Team, this is a Microsoft Exchange Server Spoofing Vulnerability that hinges on user interaction within a web browser. The mechanism of the attack is deceptively simple: “An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context”.

Microsoft has confirmed that this flaw has been used in real situations, which means criminals are already using it to get around security measures.

The vulnerability impacts several generations of on-premises servers:

Exchange Server 2016 (Any update level)
Exchange Server 2019 (Any update level)
Exchange Server Subscription Edition (SE) (Any update level)

Kubernetes 

Researchers have found security flaw in Kubernetes-based database systems. This issue is in CloudNativePG (CNPG) and is called CVE-2026-44477 with a high CVSS score of 9.4. It lets users with low privileges gain full PostgreSQL superuser access and run any commands on the operating system.

The flaw is with how this exporter connects. It first connects as the postgres superuser through a local Unix socket. Then, it tries to lower its access with the SET ROLE pg_monitor command. But this lowering is not real.

Researchers identified two distinct ways this flaw can be weaponized in the wild:

Path 1: Custom Metric Sabotage: Any database user who owns a schema on the search_path of a scraped database can “shadow” a common function used in a custom metric query. Within one scrape interval (typically 30 seconds), their malicious shadow expression executes with superuser rights.

Path 2: The “Stock” Vulnerability: Even deployments using only default configurations are at risk. A specific metric, pg_extensions, used an unqualified call that could be shadowed by any non-superuser who owns a user database.
This vulnerability affects all deployments on any supported release with default monitoring enabled.

Affected Versions: All versions prior to 1.28.3 and version 1.29.0. The CloudNativePG team has put out three fixes for the problem, now available in Patched Versions 1.28.3 and 1.29.1.

Microsoft’s MDASH VS Anthropic’s Mythos VS OpenAI’s Daybreak

Check Also

Secure Email Gateway

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center …