
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS

CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS

CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging

CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.

Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.

Researcher James Arnott disclosed severe flaws in the Connective eID extension exposing PINs, enabling forged signatures, and allowing drive-by code

BIT’s SharePoint intrusion compromised credentials for about 200 Swiss federal accounts, likely via Microsoft flaws fixed in the July Patch

Novee Security found flaws in Claude Code and Google Gemini CLI that let an attacker-controlled GitHub issue reach CI workflow

PortSwigger’s AI-assisted HTTP Terminator found roughly 30,000 HTTP desync vectors and a live Apache Traffic Server zero-day affecting roughly 700

Coinspect traced roughly $5.7 million in cryptocurrency theft to a 12-year-old weak random number generator in the CryptoJS library and

Huntress traced credential-theft alerts to attackers who compiled the khunt toolkit inside Oracle to reach SYSTEM-level code execution on a
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.