Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control

28 August 2026  |  dark6  |  Vulnerability

CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...

>> read more

CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution

27 August 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...

>> read more

Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems

27 August 2026  |  dark6  |  Vulnerability

Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injection...

>> read more

Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE

27 August 2026  |  dark6  |  Vulnerability

Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...

>> read more

Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs

27 August 2026  |  dark6  |  Vulnerability

Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...

>> read more

Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover

26 August 2026  |  dark6  |  Vulnerability

Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators should patch exposed...

>> read more

OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses

26 August 2026  |  dark6  |  Vulnerability

OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency discovery and...

>> read more

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

22 August 2026  |  dark6  |  Vulnerability

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...

>> read more