Vulnerability News

Vulnerability Cyber Security News.

Vulnerability Archives – Cyber Security News World’s #1 Premier Cybersecurity and Hacking News Portal

  • Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices
    by Abinaya on July 25, 2026 at 3:36 am

    Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions. The issue, tracked as CVE-2026-57239, was disclosed following research into Foxit’s updater and service architecture and represents a high-impact post-exploitation pathway, although it requires prior code execution on the The post Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices appeared first on Cyber Security News.

  • Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
    by Abinaya on July 23, 2026 at 7:59 am

    A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California, San Diego, highlights a growing risk associated with dealer-installed hardware that falls outside the traditional The post Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks appeared first on Cyber Security News.

  • CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
    by Abinaya on July 23, 2026 at 5:23 am

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232, the flaw affects Check Point Security Management and Multi-Domain Management platforms and carries a CVSS The post CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.

  • ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution
    by Abinaya on July 22, 2026 at 5:30 pm

    ASUS has released critical security updates to address a high-severity router vulnerability that could allow remote attackers to execute arbitrary commands on affected devices. The flaw, tracked as CVE-2026-13385, impacts multiple ASUS router firmware branches, including the widely deployed 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102 series. According to the ASUS Product Security Advisory, the vulnerability stems from The post ASUS Patches Critical Router Vulnerability Enabling Remote Command Execution appeared first on Cyber Security News.

  • Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files
    by Abinaya on July 22, 2026 at 2:34 pm

    A broken access control flaw in Meta’s shared customer support systems exposed sensitive user data, including emails, chat conversations, and uploaded files. Discovered during security testing of Meta Horizon Managed Solutions, the vulnerability revealed a broader authorization weakness across multiple support services within Meta’s ecosystem. What initially seemed to be a limited product-specific flaw quickly The post Critical Meta Vulnerability Exposed Customer Support Emails, Chats, and Uploaded Files appeared first on Cyber Security News.

  • Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers
    by Abinaya on July 21, 2026 at 8:24 am

    Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions up to v1.26.4 and has been fixed in v1.27.0. The flaw exists in Gitea’s pull The post Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers appeared first on Cyber Security News.

  • Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
    by Guru Baran on July 20, 2026 at 3:23 pm

    Overview A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030, a REST API batch-route confusion issue, and CVE-2026-60137, a SQL injection vulnerability in the The post Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details appeared first on Cyber Security News.

  • New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
    by Abinaya on July 17, 2026 at 1:26 pm

    A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user profiles and their registry hives during logon and logoff. The public proof‑of‑concept (PoC) from the The post New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access appeared first on Cyber Security News.

  • CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks
    by Abinaya on July 17, 2026 at 8:47 am

    CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems from a weakness in deserializing untrusted data, which can allow remote code execution if the application does not The post CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks appeared first on Cyber Security News.

  • Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access
    by Abinaya on July 16, 2026 at 8:09 am

    Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account takeover attacks via network access. Documented in the Zoom Security Bulletin (ZSB-26014), this vulnerability has The post Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access appeared first on Cyber Security News.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.