Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution
Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...
Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry
Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...
Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch
Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...
Critical ASUS Control Center Chain Opens Managed Fleets to Root Takeover
A CVSS 10.0 flaw chain in ASUS Control Center Enterprise can reportedly give an unauthenticated network attacker a root shell and control of centrally managed devices. Organizations should...
TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft
TP-Link has fixed two Archer AX55 v4 vulnerabilities affecting EasyMesh and web login security. A local attacker could crash or potentially take over the router, while captured HTTP...
Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform
A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...
Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine
Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...