Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform
A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...
Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release
PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...
CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw
CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...
Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch
A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated...
SonicWall VPN Gateways Hit by Zero-Click Root Takeover Chain Tied to INC Ransomware
Attackers are chaining two SonicWall SMA 1000 series flaws to gain root access to VPN gateways without a password or any user interaction. Researchers at Resecurity tie the...
Arista VeloCloud SD-WAN Orchestrators Under Active Attack via Maximum-Severity Command Injection Flaw
A perfect-10 command injection vulnerability in on-premises Arista VeloCloud Orchestrator deployments is being actively exploited, letting unauthenticated attackers reach privileged internal functions over the exposed web interface. Patches...
CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw
CISA has added CVE-2026-58644, a critical unauthenticated remote code execution flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. Federal agencies must remediate...
Hackers Actively Exploit CVE-2026-46817 in Oracle E-Business Suite — 456 Attacks Recorded in 24 Hours
Threat actors are actively exploiting CVE-2026-46817, a critical CVSS 9.8 unauthenticated remote takeover flaw in Oracle E-Business Suite, with 456 attack hits recorded in a single day across...