
VMware vCenter flaw exploited by ransomware groups
The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.

The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware gangs are now targeting a critical remote-code-execution vulnerability in VMware vCenter, patched in July 2026.

The Dutch National Cyber Security Centre has issued an alert about two critical vulnerabilities in Check Point VPN products, warning that exploitation is expected shortly.

GitLab has urged users to apply an immediate patch for a critical path traversal vulnerability affecting its self-managed instances, warning of potential unauthorized access risks.

WHMCS released fixes for a critical remote code execution vulnerability (CVE-2026-67399) and a separate data-exposure flaw in its billing and automation platform. Administrators must upgrade to 9.0.8 or 8.13.7 to mitigate risks.

Cisco has acknowledged that attackers are actively exploiting a critical authentication bypass vulnerability in Secure Firewall Management Center, tracked as CVE-2026-20079.

G7 cybersecurity agencies have issued a call to action for governments and businesses to begin immediate planning for post-quantum cryptography migration, citing risks to authentication, DNSSEC, TLS, and routing security. The transition is expected to take years and requires coordinated action across digital infrastructure.

Adobe released an emergency security update on Tuesday to address CVE-2026-75650, a max-severity zero-day vulnerability in Magento and Adobe Commerce actively exploited to install backdoors on e-commerce servers. The flaw, dubbed StyleSmuggler, was under active attack prior to patching.

Hosting providers and merchants face active exploitation of a Magento zero-day (StyleSmuggler) that bypasses all current patches. The first confirmed victim ran the latest security updates, and Adobe has yet to release a fix or CVE. Mitigation requires disabling GraphQL or deploying third-party blocking tools.

Attackers are exploiting two recently disclosed RouterOS flaws to compromise MikroTik routers with internet-exposed SSH services, security researchers report.

ConnectWise has shared interim steps to reduce risk from a new vulnerability in its ScreenConnect remote-access software, with a fix due later this week.

Cloudflare's early-access Vulnerability Discovery and Remediation service uses OpenAI models to detect and prioritize code vulnerabilities based on production exposure, proposing tailored patches and WAF rules for customer review.

Hewlett Packard Enterprise has released a security update for ArubaOS-CX to address a critical remote code execution vulnerability, mitigating potential network compromise risks.

Hackers are exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and gain remote code execution on affected systems.

Security teams detected active exploitation of CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory, shortly after the vendor released a fix. Attackers are generating administrative credentials and probing internal topologies on internet-facing systems.

Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability, leaving all user mailboxes open to hijacking.

Security researchers have identified a new technique used by the Chinese state-linked Fire Ant hacking group to turn Cisco IOS XR routers into covert data exfiltration channels via undocumented GRE tunnels.

PaperCut has released a second emergency security update for its NG and MF software after researchers discovered ways to bypass the initial patch for two actively exploited vulnerabilities.

cPanel released patches for a critical vulnerability allowing authenticated users with domain permissions to execute arbitrary code as root, affecting all supported versions of its control panel software.

PaperCut has issued an urgent warning after attackers exploited an unpatched vulnerability in its NG and MF print management platforms, with no fix yet available.

CISA has ordered federal agencies to patch a critical Citrix NetScaler remote code execution vulnerability being actively exploited in attacks, with a deadline of this Saturday.