Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root

13 September 2026  |  dark6  |  Vulnerability

A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...

>> read more

Crafted PNGs and RTSP Playlists Expose VLC Users to Memory Corruption and Data Leaks

13 September 2026  |  dark6  |  Vulnerability

Two VLC Media Player flaws can trigger heap corruption through a malicious PNG or leak process memory through a hostile RTSP server. Versions 3.0.0 through 3.0.23 are affected,...

>> read more

Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution

12 September 2026  |  dark6  |  Vulnerability

A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...

>> read more

CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack

12 September 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...

>> read more

CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List

11 September 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...

>> read more

State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment

11 September 2026  |  dark6  |  Vulnerability

Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...

>> read more

BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days in Espionage Attacks

10 September 2026  |  dark6  |  Vulnerability

Multiple espionage groups are using the BlueMoon exploit kit to chain Chrome and Windows flaws against government, defense and commercial targets. The campaign highlights the danger of patch-gap...

>> read more

AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide

10 September 2026  |  dark6  |  Vulnerability

A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...

>> read more