CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities catalog, warning of unauthenticated security bypass affecting Check Point, Arista, and F5 products.
CISA’s KEV catalog now includes CVE-2025-39682, an actively exploited Linux kernel bug, pushing federal civilian agencies to patch quickly or defer only lower-risk systems.
The Cybersecurity and Infrastructure Security Agency has added Linux kernel vulnerabilities to its catalog of flaws known to be exploited in the wild, urging rapid patching.
Unknown attackers are actively exploiting CVE-2026-85102 in Check Point's Security Gateway, a pre-auth flaw in VPN certificate handling that can lead to remote code execution.
Cisco's Identity Services Engine contains a critical authentication bypass vulnerability, CVE-2026-76460, with a CVSS score of 10.0, allowing attackers to circumvent API endpoint authentication.
Malicious actors are actively probing and exploiting a high-severity WordPress vulnerability, CVE-2026-87902, to write files and run shell commands on unpatched sites.
CISA says malicious actors are already abusing a trio of Linux kernel bugs, including a severe one, and urges defenders to patch exposed systems quickly.
A weekly roundup highlights Cisco-related threats including a zero-day, remote code execution, browser takeovers, and ClickFix attacks, with no CVE IDs assigned.
cPanel has patched a vulnerability that could allow attackers to run code as root, seize full server control, and modify databases across hosting accounts.
WordPress and Wordfence are highlighting a high-severity WordPress Core issue that could let attackers include local files and run remote code, making immediate core updates essential.
A Chinese-language threat group leveraged flaws in ZyXEL GS1900 switches and WordPress to compromise government databases, with 996 devices affected and 18,500 records stolen.
A single WordPress site was compromised in mid-June when unknown attackers planted a malicious must-use plugin that self-heals and resists removal, Wordfence reports.
Attackers can abuse a cross-site request forgery weakness in WordPress Core to run PHP and compromise servers; no CVE has been assigned and a proof-of-concept is public.
Security researchers at pwn.ai revealed a WordPress core vulnerability that allows an attacker to force a theme installation and achieve code execution when an administrator clicks a crafted link. Patches are available.
Siemens has issued updates and mitigations for CVE-2026-31431, a medium-severity flaw dubbed Copy Fail that touches several Siemens industrial offerings.
Researchers say phishing operators use fake giveaways and spoofed sign-in pages to steal Google and Microsoft 365 credentials, with Claude Max also targeted.
A medium-severity vulnerability in Check Point security products allows unauthenticated remote attackers to execute arbitrary code via improper certificate validation.
A newly detailed malware family, CLOSEDQUORUM, leverages up to four AI models to control voting and select malicious commands, targeting Windows credentials, browser passwords, and crypto wallets.
Adobe has issued updates to fix nine critical vulnerabilities in its Connect and AEM Forms products that could allow code execution and privilege escalation.