MikeTrendsTrends right now

search

CVE

Trends

  1. 1

    Cenovus Energy, the Canadian oil and gas producer listed on the TSX under ticker CVE, is being discussed for its strategies to improve efficiency and capture synergies across its operations. Coverage, including from Kalkine Media, examines how the company is targeting cost savings and integration gains as it works to strengthen returns for investors.

  2. 2
    Bitget reportedly loses $350M in Bitcoin to North Korean hackers●Severity: CRITICAL β€” Bitget exchange lost $350M+ in Bitcoin to a suspected North Korean breach. No CVE or technical detaMmastodonBusinessCrypto16 d ago

    Crypto exchange Bitget is reported to have lost more than $350 million in Bitcoin in a breach attributed to North Korean hackers. No technical details or CVE have been released about how the attack was carried out. The exchange has reportedly resumed withdrawals, but security watchers are urging caution while the full picture remains unclear.

  3. 3
    Apple patches CoreGraphics flaw exploited in targeted attacksβ—πŸ€– Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics affecting older iOS/iPadOS/macOS versions. ProcesMmastodonTechnologyCybersecurity36 d ago

    Apple has released patches for CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting older versions of iOS, iPadOS and macOS. Processing a maliciously crafted file could allow arbitrary code execution. Apple says the flaw may already have been exploited in targeted attacks, prompting users of older devices to update promptly.

  4. 4
    GCVE updates BCP-07 to add NKEV vulnerability assessments●We don't sleep at @ gcve and we updated the BCP-07 to support NKEV in addition to KEV. Version 3.0 additionally definesMmastodonTechnologyCybersecurity21 d ago

    The Global CVE Allocation System (GCVE) has published version 3.0 of its BCP-07 guidance, extending it beyond Known Exploited Vulnerability (KEV) assessments to a new No Known Exploitable Vulnerability (NKEV) format. An NKEV assessment provides a product-level, time-bounded technical evaluation of whether known exploitable vulnerabilities affect a product, giving vendors and users a standardized way to state exposure status.

  5. 5
    Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Raise Alarmβ–ΌCitrix NetScaler Zero-Days (CVE-2026-88771 and CVE-2026-88772): A Skeleton Key at the Network Edge If your organisationMmastodonTechnologyCybersecurity130 min ago

    Security researchers are warning about two zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, described as a 'skeleton key' at the network edge. Organisations running internet-facing NetScaler appliances are being urged to assume possible compromise if the devices were exposed in the past month. Administrators are advised to patch immediately and review access logs.

  6. 6
    Critical Command Injection Flaw Disclosed in Fortra BoKS Privileged Access Managerβ–ΌCVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Securityβœ‰newsTechnologyCybersecurity10 h ago

    A critical vulnerability tracked as CVE-2026-9862 has been disclosed in Fortra's BoKS Core Privileged Access Manager, an OS command injection flaw that could let attackers run arbitrary commands on affected systems. Security teams are being urged to patch or restrict exposure, given that privileged access management tools sit at the heart of enterprise infrastructure and a compromise would hand attackers keys to entire environments.

  7. 7
    ASUS Patches Critical Router Firmware Vulnerabilitiesβ–ΌASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files ASUS patched two vulnerabilitiMmastodonTechnologyCybersecurity18 h ago

    ASUS has released firmware updates fixing two critical vulnerabilities in its routers, tracked as CVE-2026-14157 and CVE-2026-13313. The flaws allow authenticated attackers to execute arbitrary commands and gain root privileges by exploiting malicious VPN files. Users are urged to update their routers promptly.

  8. 8
    Ather Konar electric scooter pitched as game-changer for Indian commuters●# transportation # electricvehicles # outdoors # innovation # technology # business https:// inyerself.com/post/ather-koMmastodonBusiness23 h ago

    Ather Energy's Konar electric scooter is being promoted as a potential game-changer for commuters in India, where electric two-wheelers are a fast-growing alternative to petrol bikes. The discussion highlights Ather's technology, design and its role in India's shift to electric mobility. Attention on the model comes as Indian buyers weigh range, price and charging infrastructure before switching to electric scooters.

  9. 9
    Progress Software discloses SSRF flaw in Sitefinity Next.js SDK●CVE-2026-92931: Progress Software reports a server-side request forgery flaw in its Sitefinity Next.js SDK npm package.MmastodonTechnologyCybersecurity13 h ago

    Progress Software has disclosed CVE-2026-92931, a server-side request forgery vulnerability in the Sitefinity Next.js SDK npm package. According to the advisory, a remote attacker could trick the server into making requests to an attacker-controlled host, potentially exposing sensitive information. Affected versions reportedly begin with 15.1.8326, and developers using the package are being urged to review their installations.

  10. 10
    Roundcube Webmail SQL Injection Flaw Actively Exploitedβ–ΌRoundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity SMmastodonTechnologyCybersecurity21 d ago

    A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.

  11. 11
    GitLab Patches Critical AI Gateway Vulnerability CVE-2026-90970β–ΌCVE-2026-90970: Critical GitLab AI Gateway Flaw Fixedβœ‰newsTechnologyCybersecurity1 d ago

    GitLab has fixed a critical vulnerability, tracked as CVE-2026-90970, affecting its AI Gateway component. Security outlets are urging users to update their deployments promptly, as flaws in AI gateway infrastructure could expose sensitive data or allow unauthorized access. Administrators are advised to review the advisory and apply the patch as soon as possible.

  12. 12
    MediaTek October 2026 security update patches 31 flaws●MediaTek security bulletin for October 2026 fixes 31 flaws, including critical MediaTek modem vulnerability CVE-2026-205MmastodonTechnologyMobile17 h ago

    MediaTek has released its October 2026 security bulletin, fixing 31 vulnerabilities across its chipsets. The most serious is a critical flaw in the company's modem, tracked as CVE-2026-20519, which could be exploited remotely. Security researchers are urging users of MediaTek-powered Android phones to install the latest patches as soon as possible.

  13. 13
    CISA Flags Actively Exploited Critical FortiMail Flaw●CISA adds CVE-2026-104286 (CVSS 9.8) to KEVβ€”critical flaw in Fortinet FortiMail allowing unauthenticated attackers to wrMmastodonTechnologyCybersecurity18 h ago

    CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog after reports of active attacks. The flaw, rated 9.8 out of 10 in severity, affects Fortinet's FortiMail and lets unauthenticated attackers write arbitrary files on vulnerable servers. Security teams are urged to patch immediately, as the flaw is described as a zero-day already being exploited in the wild.

  14. 14
    Security flaw disclosed in AhsayCBS backup software●AhsayCBS https:// radar.offseq.com/threat/a-flaw -has-been-found-in-ahsay-ahsaycbs-up-to-1032-cve-2026-105134-a9f0def985MmastodonTechnologyCybersecurity310 h ago

    A vulnerability, tracked as CVE-2026-105134, has been reported in AhsayCBS, the backup software from Ahsay, affecting versions up to 10.3.2. The flaw was published on a threat-tracking service and is circulating among infosec communities, with security professionals flagging it for administrators who run Ahsay backup infrastructure. Details on severity and exploitation remain limited so far.

  15. 15
    Kit patches missing authorization flaw in WooCommerce plugin●CVE-2026-105421: Kit has patched a missing authorization vulnerability in its Kit (formerly ConvertKit) for WooCommerceMmastodonTechnologyCybersecurity130 min ago

    Kit, the email marketing service formerly known as ConvertKit, has patched a missing authorization vulnerability tracked as CVE-2026-105421 in its Kit for WooCommerce WordPress plugin. Versions through 2.2.0 are affected, and the fix is available in version 2.2.1. No exploitation in the wild has been confirmed, but security researchers are urging users of the plugin to update promptly.

  16. 16
    Zammad warns of session hijacking flaw enabling remote code execution●Zammad security alert: session hijacking and remote code execution CVE-2026-102489 concerns session hijacking that can lMmastodonTechnologyCybersecurity21 d ago

    Zammad has issued a security alert for CVE-2026-102489, a session hijacking vulnerability that can lead to remote code execution as the Zammad service account on affected older installations. DIVD reports that the flaw has already been exploited in a real-world incident, prompting urgent calls for administrators to update their systems.

  17. 17
    Critical RCE flaw disclosed in Totolink A3002MU router●Totolink A3002MU (v1.0.0-B20230403.1455) hit by CRITICAL stack buffer overflow (CVE-2026-105285). Remote, unauthenticateMmastodonTechnologyCybersecurity15 h ago

    A critical stack buffer overflow, tracked as CVE-2026-105285, has been disclosed in the Totolink A3002MU router running firmware v1.0.0-B20230403.1455. The flaw allows remote, unauthenticated attackers to execute arbitrary code, and a public exploit is already available. Security researchers are urging users to restrict management access to affected devices while awaiting a patch.

  18. 18
    NextChat vulnerability allows unauthenticated SSRF attacksβ—πŸ”΄ NextChat CVE-2026-105238 β€” CVSS 7.3 SSRF Single unauthenticated request β†’ server fetches any internal URL or cloud metMmastodonTechnologyCybersecurity130 min ago

    A newly disclosed vulnerability, CVE-2026-105238, affects NextChat and carries a CVSS score of 7.3. Security researchers report a server-side request flaw that lets a single unauthenticated request make the server fetch arbitrary internal URLs or cloud metadata endpoints, bypassing access-code protection. No patched version has been confirmed; mitigations include blocking the x-base-url header at reverse proxies and restricting server egress.

  19. 19
    Hackers exploit Citrix NetScaler zero-day to deploy web shells●"Hackers exploit Citrix NetScaler zero-day to deploy web shells" "[...] Cybersecurity firms say attackers exploited theMmastodonTechnologyCybersecurity15 d ago

    Cybersecurity firms report attackers are exploiting a previously unknown vulnerability in Citrix NetScaler, tracked as CVE-2026-88772, to deploy custom web shells and tunneling malware. The attackers reportedly gain root access, steal credentials, and move into victims' internal networks. Security teams are urged to check exposed NetScaler appliances for signs of compromise and apply patches as they become available.

  20. 20
    ZITADEL hit by seven vulnerabilities enabling account takeover●ZITADEL cluster β€” 7 CVEs, peak CVSS 9.3 CVE-2026-105209: forge x-zitadel-orgid header β†’ issue passkey enrollment for anyMmastodonTechnologyCybersecurity210 h ago

    Security researchers disclosed a cluster of seven vulnerabilities in ZITADEL, an open-source identity and access management platform. The most severe, CVE-2026-105209 with a CVSS score of 9.3, involves forging the x-zitadel-orgid header to trigger passkey enrollment for arbitrary users, potentially allowing full account takeover across tenants. Another flaw, CVE-2026-105215 (9.1), enables pre-hijacking accounts via forged identity provider callbacks. Administrators are urged to patch promptly.

  21. 21
    Citrix NetScaler SAML zero-day actively exploited, added to CISA KEVβ—πŸš¨ Citrix NetScaler SAML zero-day (CVE-2026-88779, CVSS 8.7) in CISA KEV. Actively exploited. Memory overflow in SAML hanMmastodonTechnologyCybersecurity214 h ago

    A zero-day vulnerability in Citrix NetScaler, tracked as CVE-2026-88779 with a CVSS score of 8.7, has been added to CISA's Known Exploited Vulnerabilities catalog amid reports of active exploitation. The flaw is a memory overflow in the SAML handler that can crash the appliance, disrupting VPN and SSO services for organizations using SAML SP or IdP configurations. Researchers warn it may bypass the previous patch. Fixed builds are 14.1-73.41 and 13.1-64.28, and administrators are urged to update immediately.

  22. 22
    EU Reporting Rules Put Linux Vulnerability Management Under Pressure●The # EU Is About to Make # Linux 's # Vulnerability Management Problem Harder to Ignore More # CVE , sprawling deploymeMmastodonWorldEU Politics22 d ago

    The EU's upcoming cybersecurity reporting requirements are set to expose long-standing weaknesses in how Linux vulnerabilities are tracked and patched. The number of published CVEs has grown sharply, and sprawling deployments make it harder for organisations to prove which systems are affected. Under the new rules, patching alone may not suffice: teams will need documented evidence of their vulnerability handling, turning compliance into a pressing operational challenge for Linux users across Europe.

  23. 23
    Fortra Patches Command Injection Flaw in BoKS Core PAM●Fortra Patches Command Injection Flaw in BoKS Core PAM Fortra fixed a command injection vulnerability (CVE-2026-9862) inMmastodonTechnologyCybersecurity17 h ago

    Fortra has released a fix for a command injection vulnerability, tracked as CVE-2026-9862, in its BoKS Core privileged access management product. The flaw sits in the autoregistration service and allows unauthenticated remote code execution, potentially leading to full system compromise. Security professionals are circulating the advisory and urging administrators to patch affected deployments promptly.

  24. 24
    Critical Capacitor vulnerability CVE-2026-103922 rated CVSS 9.3●Critical Capacitor vulnerability CVE-2026-103922 (CVSS 9.3) affects a package with 5.5M weekly downloads. Update to a paMmastodonTechnologyMobile23 d ago

    A critical vulnerability tracked as CVE-2026-103922, with a CVSS score of 9.3, has been disclosed in Capacitor, the Ionic framework package with around 5.5 million weekly downloads used to build Android and iOS apps. Security researchers urge developers to update to a patched release immediately, warning that affected apps could be at serious risk until remediated.

  25. 25
    GitLab warns of critical RCE flaw in AI Gatewayβ–Όβš οΈ CRITICAL: GitLab warns of critical RCE vulnerability in AI Gateway service GitLab disclosed CVE-2026-90970, a criticaMmastodonTechnologyCybersecurity21 d ago

    GitLab has disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service. The flaw allows authenticated users with Duo Agent Platform access to escape the prompt sandbox and execute arbitrary commands. Self-hosted instances are affected, and security teams are being urged to patch promptly.

  26. 26
    High-severity flaw reported in NetScaler ADC and Gatewayβ–ΌCVE-2026-88779 (HIGH, CVSS 8.7) impacts NetScaler ADC & Gateway https:// radar.offseq.com/threat/cve-20 26-88779-vulneraMmastodonTechnologyCybersecurity31 d ago

    A new vulnerability tracked as CVE-2026-88779 has been disclosed affecting Citrix NetScaler ADC and NetScaler Gateway, with a high severity rating of 8.7 on the CVSS scale. The finding is circulating among cybersecurity professionals, who are monitoring the flaw for details on exploitation and the availability of patches from Citrix.

  27. 27
    Citrix NetScaler zero-day memory flaw added to CISA KEVβ—πŸ€– CVE-2026-88779 (CVSS 8.7): memory corruption (CWE-119) in Citrix NetScaler ADC/Gateway, reachable unauthenticated overMmastodonTechnologyCybersecurity118 h ago

    A high-severity memory corruption vulnerability, CVE-2026-88779 (CVSS 8.7), in Citrix NetScaler ADC and Gateway can be exploited unauthenticated over the network to cause denial of service. The flaw was attacked as a zero-day and has been added to CISA's Known Exploited Vulnerabilities catalog. Citrix has issued emergency fixes, and security teams are urged to patch immediately.

  28. 28
    Update fixes kernel flaws enabling DoS and privilege escalation●There's a headline going around saying "Massive Update Leading to DoS and Privilege Escalation Attacks". It reads as ifMmastodonTechnologyCybersecurity223 h ago

    A headline circulating among security professionals suggests a recent kernel update itself caused denial-of-service and privilege escalation attacks. Security engineers are pushing back, clarifying that the update actually patches vulnerabilities that could enable such attacks. Since 2024 the Linux kernel project acts as its own CVE Numbering Authority, assigning identifiers for flaws directly, which has changed how fixes and disclosures are labeled and reported.

  29. 29
    Cisco zero-day in Catalyst SD-WAN Manager exploited via single encoded character●Discover how a single encoded character exploited a critical Cisco zero-day vulnerability in the Catalyst SD-WAN ManagerMmastodonTechnologyCybersecurity21 d ago

    A critical zero-day vulnerability, tracked as CVE-2026-76504, in Cisco's Catalyst SD-WAN Manager reportedly allowed attackers to gain administrative access by sending a single encoded character. Security commentators are highlighting how minimal the exploit requirement was, raising concerns about unpatched SD-WAN deployments and urging administrators to apply fixes and review exposure.

  30. 30
    CISA adds exploited NetScaler flaw CVE-2026-88779 to KEV list●If you're spending your Sunday night anywhere near a terminal, start with the NetScaler gear. CISA put CVE-2026-88779 onMmastodonTechnologyCybersecurity119 h ago

    CISA has added CVE-2026-88779, a vulnerability in Citrix NetScaler appliances, to its Known Exploited Vulnerabilities list after evidence of active exploitation. Federal agencies must apply patches by October 7. Security practitioners are urging admins to prioritise patching internet-facing NetScaler devices immediately, as such appliances have historically been frequent targets for attackers.

  31. 31
    Critical flaw in Apache OpenOffice lets documents run codeβ–ΌCVE-2026-59265: A critical flaw in Apache OpenOffice's Java integration lets a crafted untrusted document execute arbitrMmastodonTechnologyCybersecurity22 d ago

    A critical vulnerability, tracked as CVE-2026-59265, has been found in Apache OpenOffice's Java integration. Opening a crafted untrusted document can allow arbitrary code execution on the affected machine. Versions 4.1.16 and earlier are affected, and no exploitation has been confirmed so far. A fix is expected in version 4.1.17; users are advised to disable the Java runtime as an interim measure.

  32. 32
    Phproject vulnerability lets API users bypass issue restrictions●CVE-2026-104991 is a missing-authorization flaw in Alanaktion Phproject. Authenticated API key holders can bypass restriMmastodonTechnologyCybersecurity123 h ago

    A missing-authorization vulnerability, CVE-2026-104991, has been disclosed in Alanaktion Phproject. Authenticated users with API keys can bypass restricted-issue controls to read issue contents, comments and email addresses, and post unauthorized comments. Versions 1.1.6 through 1.8.6 are affected. Security communities are sharing the advisory as administrators assess whether their deployments need patching.

  33. 33
    FortiMail zero-day actively exploited with no patch available●2026-W40 β€” Weekly Threat Roundup πŸ”₯ A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patcMmastodonTechnologyCybersecurity31 d ago

    A weekly threat roundup reports that a zero-day vulnerability in Fortinet's FortiMail, tracked as CVE-2026-104286, is being actively exploited while no patch is available, forcing administrators to rely on interim workarounds. The same roundup notes Operation KillSwitch dismantled the KillSec ransomware group, allegedly run by a 16-year-old, with seizures reportedly carried out.

  34. 34
    SourceHut account takeover flaw found in build log rendering●SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973 https:// reddthat.com/post/74210240MmastodonTechnology22 d ago

    A security vulnerability in SourceHut, tracked as CVE-2026-92973, reportedly allowed account takeover through malicious build logs. The flaw involved cross-site scripting in the ansi2html.py script used to render logs, letting attackers inject code that could hijack sessions. Developers and security researchers are discussing the disclosure and how the issue was handled.

  35. 35
    Microsoft tracks unauthenticated command injection flaw in mail serversβ–ΌUnauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570βœ‰newsTechnologyInternet4 d ago

    Microsoft is tracking CVE-2026-73570, a newly disclosed vulnerability that allows unauthenticated command injection on internet-facing mail servers. Because the flaw can be exploited without credentials and targets exposed systems, security teams are watching for signs of exploitation and awaiting patch guidance. Admins of mail infrastructure are being urged to assess exposure while details and fixes are confirmed.

  36. 36
    Cenovus Energy stock outpaces broader market gainsβ–ΌCenovus Energy (CVE) Beats Stock Market Upswing: What Investors Need to Knowβœ‰newsBusinessMarkets3 d ago

    Cenovus Energy shares have risen faster than the wider stock market, drawing attention from investors watching the Canadian oil and gas producer. The move comes amid broader strength in the market, with commentary focused on what the outperformance means for investors, including the company's position in the energy sector and its outlook going forward.

  37. 37
    New Citrix NetScaler flaw lets attackers crash appliances remotely●Citrix NetScaler has a new unauthenticated flaw (CVE-2026-88779) that lets a stranger crash the appliance. It hits boxesMmastodonTechnologyCybersecurity21 d ago

    Citrix NetScaler appliances have a new unauthenticated vulnerability, tracked as CVE-2026-88779, that allows a remote attacker to crash the device. It affects systems configured for SAML single sign-on, a common enterprise gateway setup. No workaround exists, so administrators are urged to update to version 14.1-73.41 immediately. Security professionals are spreading the word to speed up patching.

  38. 38
    Fortinet FortiMail Bug CVE-2026-104286 Actively Exploited●Fortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alertβœ‰newsTechnologyCybersecurity1 d ago

    Fortinet has a critical vulnerability, tracked as CVE-2026-104286, in its FortiMail email security product. The flaw involves path traversal combined with NULL byte handling, and security researchers report it is being actively exploited in the wild. Administrators are being urged to apply patches immediately to prevent attackers from compromising mail servers.

  39. 39
    Three unpatched critical flaws disclosed in LightLLMβ–ΌπŸš¨ LightLLM Mass Disclosure β€” 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) β€” unauthenticated RCE, router profiler RPyC CVEMmastodonTechnologyAI45 d ago

    Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.

  40. 40
    GitLab Rushes Emergency Fixes for Exploited AI Gateway Flaws●GitLab Issues Emergency Patches for Actively Exploited Critical AI Gateway and Path Traversal Flaws GitLab released emerMmastodonTechnologyCybersecurity22 d ago

    GitLab has released emergency security patches addressing two critical vulnerabilities: a remote code execution flaw in its AI Gateway, tracked as CVE-2026-90970, and a maximum-severity path traversal issue. Both flaws are reportedly being actively exploited, prompting the unusually urgent rollout. Security teams are being urged to apply the updates immediately, with the disclosures fueling renewed discussion about securing AI infrastructure.