Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root
A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...
Crafted PNGs and RTSP Playlists Expose VLC Users to Memory Corruption and Data Leaks
Two VLC Media Player flaws can trigger heap corruption through a malicious PNG or leak process memory through a hostile RTSP server. Versions 3.0.0 through 3.0.23 are affected,...
Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution
A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...
CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack
CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...
CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List
CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...
State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...
BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days in Espionage Attacks
Multiple espionage groups are using the BlueMoon exploit kit to chain Chrome and Windows flaws against government, defense and commercial targets. The campaign highlights the danger of patch-gap...
AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide
A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...