News Security CVE-2026-32475: Critical Elementor Pro file upload flaw can enable unauthenticated RCE August 21, 2026 by Alex Mira | Leave a Comment Elementor Pro sites with a File Upload field in a public form are exposed to a critical file upload flaw (CVE-2026-32475) that can enable unauthenticated RCE. Update to 4.2.2+ and audit the Elementor forms upload directory. Read more » CVE-2026-32475 Elementor Pro Patch management Plugin Vulnerabilities Remote code execution WordPress security
News Security Critical authentication bypass reported in User Profile Builder plugin August 18, 2026 by Alex Mira | Leave a Comment Wordfence reports a critical authentication bypass in the User Profile Builder plugin (CVE-2026-15826) that can log attackers in as user ID 1 under specific settings. Update to version 3.16.5 and review autologin configuration. Read more » Authentication bypass CVE-2026-15826 Plugin vulnerability User Profile Builder Website security Wordfence WordPress security
News Security ShieldBreak (CVE-2026-69414): What’s confirmed about the new Microsoft Defender elevation-of-privilege flaw August 18, 2026 by Alex Mira | Leave a Comment ShieldBreak (CVE-2026-69414) is a Microsoft Defender elevation-of-privilege flaw with a patch in progress. Here’s what’s confirmed, what’s still unclear, and what to watch for. Read more » cve Microsoft Defender Patch management Privilege escalation Windows security Zero-day
News Security TP-Link Omada ZTP cryptographic weaknesses: CVE-2025-15544, CVE-2025-15627, CVE-2025-15631 August 8, 2026 by Alex Mira | Leave a Comment Three TP-Link Omada ZTP flaws—CVE-2025-15544, CVE-2025-15627, and CVE-2025-15631—expose weaknesses in adoption-time trust and credential protection. Here’s what to do now. Read more » cve Firmware updates IoT security Network Security Omada TP-Link Zero-touch provisioning
News Security COLDCARD wallet RNG flaw and the rush to migrate funds August 7, 2026 by Alex Mira | Leave a Comment A firmware-level RNG error in certain COLDCARD wallets weakened seed generation. Researchers link it to large-scale Bitcoin thefts. Updating helps only for new seeds—affected users should migrate. Read more » bitcoin cryptocurrency security firmware hardware wallet RNG self-custody vulnerability
News Security CVE-2026-18072: Backdoored ARVE plugin enables admin logins without credentials July 29, 2026 / July 29, 2026 by Alex Mira | Leave a Comment CVE-2026-18072 affects Advanced Responsive Video Embedder (ARVE) 10.8.7, where a hardcoded backdoor can grant admin access without credentials. Check your version and remove 10.8.7 immediately if present. Read more » ARVE plugin Authentication bypass CVE-2026-18072 incident response plugin supply chain WordPress security
AI News Security OpenAI testing uncovers zero-day flaws in JFrog Artifactory: what’s confirmed about the eight CVEs July 29, 2026 / July 29, 2026 by Alex Mira | Leave a Comment OpenAI’s model evaluations led to eight CVEs in JFrog Artifactory being disclosed and fixed. Here’s what’s confirmed, what’s unclear, and what admins can do now. Read more » CVE-2026-65617 JFrog Artifactory openai Privilege escalation Software supply chain SSRF Vulnerability Management
News Security CISA flags active RCE exploitation in Joomla extensions; separate SQLi fix lands for Quix Page Builder July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment CISA added two actively exploited Joomla extension flaws to its KEV catalog, warning of RCE via file uploads in iCagenda and Balbooa Forms. Separately, Quix Page Builder patched an unauthenticated SQL injection in version 6.2.1. Read more » CISA CMS security cve Joomla Joomla extensions Patch management Remote code execution
News Security Zoom patches critical Windows account takeover flaw (CVE-2026-53412) and related privilege escalation issue July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment Zoom fixed a critical Windows account takeover flaw (CVE-2026-53412) and a related privilege escalation issue (CVE-2026-53411). Update Windows clients, VDI deployments, and the Meeting SDK without delay. Read more » CVE-2026-53411 CVE-2026-53412 Enterprise security Patch management VDI Windows security Zoom
News Security CVE-2026-25089 in Fortinet FortiSandbox: active exploitation confirmed, patch now and lock down access July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment CISA confirmed active exploitation of CVE-2026-25089 in Fortinet FortiSandbox. Here’s what’s affected, the fixed versions, and practical steps to patch and lock down access—plus what remains uncertain. Read more » CISA KEV Command Injection CVE-2026-25089 Fortinet FortiSandbox patch tuesday Vulnerability Management