Steam Windows Zero-Day Turns Local Access Into Full SYSTEM Control
A newly disclosed weakness in the Steam Client Service reportedly lets a standard Windows user execute code with SYSTEM privileges. With no confirmed vendor fix at publication time,...
Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root
A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...
High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access
A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...
Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...
Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control
CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...
Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems
TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...