Wednesday , October 7 2026
cPanel

ALERT
Patch Now! Critical Exchange Server, cPanel, and Kubernetes Flaws Exploited

cPanel & WHM and WP Squared have recently provided fixes for five critical flaws. These issues include the ability to read any file and SQL injection, which threaten server safety and data privacy.

The biggest flaw found this time let anyone get into sensitive system resources without permission.

Contract and server dispute brought down Bangladesh’s digital payment

Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
Contract and server dispute brought down Bangladesh’s digital payment

Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
Critical Atlassian & IBM Flaws Expose Files and Enable Remote Code Execution

Citrix NetScaler SAML 0-Day Flaw Under Attack

Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
Citrix NetScaler SAML 0-Day Flaw Under Attack

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

CVE-2026-29205 (CVSS 8.6) – Arbitrary File Read: A mix of wrong privilege dropping and not enough path filtering lets attackers read random files through some cpdavd endpoints. This impacts versions 120 and above.

CVE-2026-32993 (CVSS 8.3) – HTTP Header Injection: An insecure endpoint in cpsrvd was found to let users add any HTTP headers. This affects versions 132 and up.

CVE-2026-32992 (CVSS 8.2) – Credential Theft via DNS Cluster: SSL checks were not completely applied in the DNS Cluster system. A bad server could do a man-in-the-middle attack to steal credentials. This impacts versions 126 and above.

CVE-2026-29206 (CVSS 8.1) – SQL Injection: The sqloptimizer script has a flaw that lets anyone run any SQL query they want. This is important because it affects all versions of cPanel and WHM.

CVE-2026-32991 (CVSS 7.1)  Team Member Privilege Escalation: Low-privilege team users (role=default) can gain full owner rights using certain UAPI modules. This applies to versions 110 and above.

Patches have been sent out to different release levels so all active users can protect their environments.

Exchange Server

Microsoft has sent out an urgent alert for groups using on-site email systems. A new security flaw in Outlook Web Access (OWA) is now being targeted by attackers, who can run harmful code just by sending a specially made email.
The flaw, known as CVE-2026-42897 (CVSS 8.1), is a big risk for company security because it affects the user’s browser.
According to the Exchange Team, this is a Microsoft Exchange Server Spoofing Vulnerability that hinges on user interaction within a web browser. The mechanism of the attack is deceptively simple: “An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context”.

Microsoft has confirmed that this flaw has been used in real situations, which means criminals are already using it to get around security measures.

The vulnerability impacts several generations of on-premises servers:

Exchange Server 2016 (Any update level)
Exchange Server 2019 (Any update level)
Exchange Server Subscription Edition (SE) (Any update level)

Kubernetes 

Researchers have found security flaw in Kubernetes-based database systems. This issue is in CloudNativePG (CNPG) and is called CVE-2026-44477 with a high CVSS score of 9.4. It lets users with low privileges gain full PostgreSQL superuser access and run any commands on the operating system.

The flaw is with how this exporter connects. It first connects as the postgres superuser through a local Unix socket. Then, it tries to lower its access with the SET ROLE pg_monitor command. But this lowering is not real.

Researchers identified two distinct ways this flaw can be weaponized in the wild:

Path 1: Custom Metric Sabotage: Any database user who owns a schema on the search_path of a scraped database can “shadow” a common function used in a custom metric query. Within one scrape interval (typically 30 seconds), their malicious shadow expression executes with superuser rights.

Path 2: The “Stock” Vulnerability: Even deployments using only default configurations are at risk. A specific metric, pg_extensions, used an unqualified call that could be shadowed by any non-superuser who owns a user database.
This vulnerability affects all deployments on any supported release with default monitoring enabled.

Affected Versions: All versions prior to 1.28.3 and version 1.29.0. The CloudNativePG team has put out three fixes for the problem, now available in Patched Versions 1.28.3 and 1.29.1.

Microsoft’s MDASH VS Anthropic’s Mythos VS OpenAI’s Daybreak

Check Also

Zimbra mail servers

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. …