Vulnerability Cyber Security News.
Vulnerability Archives – Cyber Security News World’s #1 Premier Cybersecurity and Hacking News Portal
- CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacksby Guru Baran on September 8, 2026 at 4:25 pm
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks. CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that The post CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.
- ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Stepsby Abinaya on September 7, 2026 at 2:14 pm
ConnectWise has warned customers about a newly identified security issue affecting file transfer behavior in ScreenConnect Remote Access Support and Access sessions. The issue impacts both cloud-hosted and on-premises ScreenConnect deployments, and the company has released interim mitigation guidance while it develops a permanent fix. The advisory, published on September 3, 2026, does not yet The post ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps appeared first on Cyber Security News.
- Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypassby Abinaya on September 7, 2026 at 10:49 am
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks. The new releases, Roundcube 1.6.19 and 1.7.4, address flaws in how the open-source webmail platform processes email The post Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass appeared first on Cyber Security News.
- Telerik Flaw Chain Lets Unauthenticated Attackers Turn Padding Oracle Into Remote Code Executionby Abinaya on September 7, 2026 at 10:01 am
Security researchers have uncovered a significant vulnerability chain in Telerik UI for ASP.NET AJAX, allowing unauthenticated attackers to execute remote code in vulnerable enterprise web applications. The issue primarily affects Telerik’s RadAsyncUpload component, a widely used file-upload control in ASP.NET WebForms applications. Progress Software has indicated that the flaw impacts versions from 2010.1.309 to 2026.2.519. The post Telerik Flaw Chain Lets Unauthenticated Attackers Turn Padding Oracle Into Remote Code Execution appeared first on Cyber Security News.
- Critical Chrome 0-Day Vulnerability Actively Exploited in the Wildby Abinaya on September 4, 2026 at 6:17 am
Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks. The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content. The company confirmed that it is aware of an exploit for the vulnerability existing in the The post Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.
- Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacksby Abinaya on September 3, 2026 at 10:59 am
A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics. The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on vulnerable systems without needing valid credentials. Horizon3.ai researchers observed valid exploitation attempts against internet-exposed Switchvox The post Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks appeared first on Cyber Security News.
- Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Codeby Abinaya on September 3, 2026 at 7:08 am
Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges. Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of 10 and affects Nexus 9000 models that use a Silicon One ASIC. The security issue, The post Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code appeared first on Cyber Security News.
- Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerabilityby Abinaya on September 3, 2026 at 5:35 am
A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local privilege escalation, which means it could give unauthorized users higher access rights. The project, named FalconFlank, The post Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability appeared first on Cyber Security News.
- Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerabilityby Abinaya on September 1, 2026 at 1:52 pm
Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry. The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations. VulnCheck observed The post Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability appeared first on Cyber Security News.
- JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Accessby Abinaya on September 1, 2026 at 1:06 pm
A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges. WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin tokens.” An attacker with a valid administrator token could control the affected Artifactory environment, including The post JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access appeared first on Cyber Security News.














