Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

22 August 2026  |  dark6  |  Vulnerability

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...

>> read more

Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live

21 August 2026  |  dark6  |  Vulnerability

Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...

>> read more

Researchers Show How a Signed Windows Defender Driver Could Be Turned Against Security Tools

21 August 2026  |  dark6  |  Vulnerability

Check Point researchers reverse-engineered Microsoft Defender's BTR.sys driver and found that its undocumented transaction protocol could be reproduced to disable antivirus and EDR products from the Windows kernel...

>> read more

Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide

20 August 2026  |  dark6  |  Vulnerability

NSA, CISA, the FBI, DOE and EPA have jointly warned that hackers are actively scanning for and probing Siemens S7-series PLCs across U.S. critical infrastructure. The campaign favors...

>> read more

CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw

20 August 2026  |  dark6  |  Vulnerability

CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...

>> read more

Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely

20 August 2026  |  dark6  |  Vulnerability

Citrix has patched two new NetScaler ADC and Gateway vulnerabilities, including a 9.3-severity authentication bypass that can let remote attackers slip past login controls on SSL VPN, ICA...

>> read more

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control

18 August 2026  |  dark6  |  Vulnerability

A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...

>> read more