Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > critical-netscaler-vulnerability-exploited-in-attacks

Critical NetScaler Vulnerability Exploited in Attacks

3+ day, 12+ hour ago   (460+ words) Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The US Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday warned that threat actors have been exploiting a critical-severity NetScaler vulnerability in attacks....

SecurityWeek
securityweek.com > mikrotik-patches-critical-flaws-chained-to-hack-routers

MikroTik Patches Critical Flaws Chained to Hack Routers

5+ day, 13+ hour ago   (570+ words) Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. Network equipment maker MikroTik has rolled out patches for six vulnerabilities in RouterOS, urging users to apply them as soon as possible, as two…...

SecurityWeek
securityweek.com > elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

1+ week, 1+ day ago   (589+ words) Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is…...

SecurityWeek
securityweek.com > vmware-workstation-and-fusion-updates-patch-critical-vulnerability

VMware Workstation and Fusion Updates Patch Critical Vulnerability

1+ week, 2+ day ago   (440+ words) The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as…...

SecurityWeek
securityweek.com > servicenow-patches-3-critical-code-injection-vulnerabilities

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

1+ week, 6+ day ago   (566+ words) Attackers could exploit the security defects to execute arbitrary code and access or tamper with data. ServiceNow has announced patches for four vulnerabilities, including three critical code injection flaws in the ServiceNow AI platform, each with a maximum severity (CVSS…...

SecurityWeek
securityweek.com > cisa-warns-of-exploited-oracle-weblogic-vulnerability

CISA Warns of Exploited Oracle WebLogic Vulnerability

2+ week, 5+ day ago   (508+ words) The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The cybersecurity agency CISA has instructed government organizations to immediately patch a critical vulnerability that has been widely exploited in attacks against…...

SecurityWeek
securityweek.com > cisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

3+ week, 2+ day ago   (577+ words) The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf. A secure on-premises video conferencing…...

SecurityWeek
securityweek.com > atlassian-splunk-patch-dozens-of-critical-high-severity-vulnerabilities

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

3+ week, 3+ day ago   (452+ words) The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. Atlassian and Splunk this week announced patches for over 250 vulnerabilities across their products, including dozens of critical- and high-severity flaws. On Tuesday, Atlassian published a…...

SecurityWeek
securityweek.com > 300000-wordpress-sites-potentially-exposed-to-hacking-due-to-form-plugin-flaw

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

3+ week, 5+ day ago   (557+ words) Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. A critical vulnerability in the Forminator Forms plugin for WordPress potentially exposes thousands of websites to remote code execution (RCE), WordPress security firm Defiant warns....