CVE Vulnerability Alerts

CVE Vulnerability Alerts
SonicWall Patches CVSS 10.0 Pre-Auth SSRF in SMA1000 Appliances
SonicWall fixed four SMA1000 flaws, led by CVE-2026-102255, a CVSS 10.0 unauthenticated SSRF in the WorkPlace portal. No exploitation has been reported.
Application Security
Unpatched LMCache Flaw Allows Unauthenticated Remote Code Execution
JFrog disclosed CVE-2026-105192, a CVSS 9.8 pickle deserialization flaw in LMCache that lets one network message run code. No patched version exists yet.
Application Security
Chrome 155 Patches 247 Vulnerabilities, Including Four Critical
Google released Chrome 155 with fixes for 247 vulnerabilities, four of them critical use-after-free flaws. Google reports no in-the-wild exploitation.
Application Security
Atlassian CVE-2026-21589 Exploited Within Two Hours of PoC Details
Attackers probed Atlassian Data Center flaw CVE-2026-21589 within two hours of watchTowr publishing details; Previdian logged 15 attempts from three IPs.
Application Security
Ninja Forms, WPC Product Bundles XSS Flaws Used to Backdoor Sites
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake plugin with four persistence mechanisms on WordPress.
CVE Vulnerability Alerts
Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
Researchers demonstrated 32 unique zero-day exploits on day one of Pwn2Own Ireland 2026, earning $388,500 against phones, routers, printers and AI platforms.
Application Security
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Scanning has begun for CVE-2026-61500 in Rejetto HFS, a flaw that lets attackers forge admin cookies and reach remote code execution on versions 3.0.0-3.2.0.
CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
Application Security
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice let malicious spreadsheets run code through JDBC drivers with no macro warning shown.