Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control
CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...
CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution
CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...
Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems
Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injection...
Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE
Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...
Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs
Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...
Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover
Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators should patch exposed...
OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses
OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency discovery and...
Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution
A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...