Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch
A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated...
Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell
Researchers found that macOS's Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password....
AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation
Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline...
Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code
A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no...
Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems
TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...
Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk
A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...
Microsoft’s August 2026 Patch Tuesday Closes 394 Flaws, Including One Zero-Day Already Under Attack
Microsoft's August 2026 security update addresses 394 vulnerabilities spanning Windows, Office, SharePoint, Azure, and developer tools, including three zero-days. One of them, a Windows kernel driver flaw tied...
Zoom Patches ‘Zoomsday’ Flaw That Let Meeting Guests Hijack Devices Without a Single Click
Zoom has fixed four vulnerabilities in its meeting clients, including a high-severity bug dubbed 'Zoomsday' that let any meeting participant execute code on another attendee's device with zero...