Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > SQL Injection
#SQL Injection

Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform

4 September 2026  |  dark6  |  Vulnerability

A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...

>> read more

A Popular WordPress Backup Plugin’s Flaw Puts 5 Million Sites One Restore Away From Takeover

4 September 2026  |  dark6  |  Vulnerability

A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin, installed on more than five million WordPress sites, can be triggered through the platform's own...

>> read more

Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths

29 August 2026  |  dark6  |  Vulnerability

ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...

>> read more

Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk

15 August 2026  |  dark6  |  Vulnerability

A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...

>> read more

Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated

10 August 2026  |  dark6  |  Vulnerability

A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...

>> read more

APT Campaign Exploits cPanel CVE-2026-41940 to Breach Government and Military Servers Across South-East Asia

3 May 2026  |  dark6  |  Vulnerability

A sophisticated threat actor has exploited the critical cPanel authentication bypass CVE-2026-41940 to compromise government and military servers across South-East Asia, while also deploying a custom zero-day SQL-to-OS...

>> read more

Critical SAP SQL Injection CVE-2026-27681 (CVSS 9.9) Exposes Financial Data in Business Planning and Warehouse Systems

19 April 2026  |  dark6  |  Vulnerability

SAP's April 2026 Patch Day addresses CVE-2026-27681, a near-perfect CVSS 9.9 SQL injection flaw in SAP Business Planning and Consolidation (BPC) and Business Warehouse (BW). A low-privileged user...

>> read more

Critical Fortinet FortiClient EMS Vulnerability CVE-2026-21643 Actively Exploited — CISA Demands Patch Today

16 April 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-21643, a critical pre-authentication SQL injection flaw in Fortinet FortiClient EMS (CVSS 9.1), to its Known Exploited Vulnerabilities catalog with a mandatory patching deadline of...

>> read more