#bug


CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

Jun 9, 2026 // 11:36

CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day […]

Critical UniFi OS bug lets hackers gain root without authentication

Jun 8, 2026 // 19:57

Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. The security […]

WP Maps Pro bug exploited to create admin accounts on WordPress sites

May 31, 2026 // 17:16

Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication. The vulnerability, […]

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

May 23, 2026 // 10:49

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) […]

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

May 23, 2026 // 10:46

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) […]

Drupal critical update to fix bug with high exploitation risk

May 20, 2026 // 15:56

Drupal has announced a “core security release” scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure. Administrators […]

Funnel Builder WordPress plugin bug exploited to steal credit cards

May 15, 2026 // 23:56

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. The flaw […]

Microsoft fixes Windows Autopatch bug installing restricted drivers

May 13, 2026 // 17:36

Microsoft has fixed a Windows Autopatch bug that caused driver updates restricted by administrative policies to be deployed on some Autopatch-managed Windows devices in the […]

Critical vm2 sandbox bug lets attackers execute code on hosts

May 7, 2026 // 00:37

A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system. The security issue […]

Weaver E-cology critical bug exploited in attacks since March

May 5, 2026 // 01:56

Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands. The attacks started five days […]