News
Super Forms CVE-2026-14894: working PoCs are now public
SecurityDevelopment
A flaw (CVE-2026-14894, severity 9.8) in the popular premium WordPress form builder Super Forms lets anyone, with no login, upload a malicious file and run programs on the server to hijack the site. Versions 6.3.313 and earlier are affected. The vendor has released a fix, and updating to the latest version stops it. We explain the scope and what to do now.
2026.07.1024 views
News
Popular AI Agent UI 'Hermes WebUI' Server-Takeover Flaw CVE-2026-58123 — No Password Needed, Plus API-Key Theft; Update Now
DevelopmentAISecurity
A flaw (CVE-2026-58123, severity 9.8) in the popular tool Hermes WebUI—which runs your own AI agent from a browser (15,000+ GitHub stars)—lets attackers take over the server with no password. A second flaw, CVE-2026-58122, strips out paid LLM API keys and messaging credentials. Fixes are out for both, and updating to the latest stops them. We explain the scope and the fix.
2026.07.1082 views
News
UsersWP's Second Flaw CVE-2026-13690 Bypasses 2FA; Update to 1.2.70
SecurityDevelopment
A flaw (CVE-2026-13492) in the WordPress plugin UsersWP—used on over 20,000 sites to add member registration—lets an ordinary user who merely registered delete key files and push toward a full site takeover. Severity is 8.8 out of 10. The fixed version 1.2.66 is already out, and updating stops it. We explain the affected versions and what to do right now.
2026.07.1017 views
News
Metabase CVE-2026-72898 (CVSS 10.0) Leaked Customer Data — Patch Now
SecurityPrivacyDevelopment
A serious flaw (CVE-2026-59827, severity 9.9) in the analytics tool Metabase—used by roughly 50,000 companies—lets attackers take over the server. In many default setups, just an ordinary account able to run SQL can seize the in-house server and steal the credentials of every connected database. A second admin-exploitable hole, CVE-2026-59826, was disclosed at the same time. We explain the affected versions and how to update now.
2026.07.1064 views
News
No-Code App Builder 'Adalo' Flaw CVE-2026-10706 Exposes User Data Across 1M+ Apps — No Patch Yet, Avoid Storing Sensitive Data
SecurityPrivacyDevelopment
A flaw in the popular no-code app builder Adalo (CVE-2026-10706) lets any authenticated user pull the full sign-up data—emails and more—of other people's apps. Over one million apps are affected, and because it is a platform-level flaw, users cannot fix it themselves. With no patch yet, avoid storing sensitive data. We explain the scope, the mechanism, and what to do now.
2026.07.1026 views
News
Popular AI Coding Tool Cline Hijackable by Any Website (CVE-2026-59723): Command Execution and API Key Theft — Update to 3.0.30
AISecurityDevelopment
Cline, an AI coding tool used by over 5 million people, has a critical flaw (CVE-2026-59723, CVSS 8.8). Simply opening a malicious website can hijack the Cline on your machine, run commands, and steal API keys and source code. It is the second same-shaped hole after May. Update to the latest version (3.0.30 or later) now.
2026.07.0966 views
News
Critical SSRF in Repomix (CVE-2026-59702): The Popular AI Code-Packing Tool's Server Could Leak Cloud Keys — Update to 1.14.1
AIDevelopmentSecurity
Repomix, the popular tool that bundles a codebase into one file for AI, has a critical flaw (CVE-2026-59702, CVSS 9.3). A crafted URL could turn its public server into a proxy and steal internal data such as cloud credential keys. The official site is patched; if you self-host, update to 1.14.1 now.
2026.07.0931 views
News
Five unauthenticated FortiSandbox flaws, two exploited in the wild
SecurityInfrastructure
Fortinet FortiSandbox, the appliance handling corporate malware defense, has four unauthenticated severity-9.8 takeover flaws. CVE-2026-39808 has a public PoC and confirmed exploit evidence, and another is under observed attack. The device meant to defend could become the way in, so operators should update to the latest fix immediately.
2026.07.0830 views
News
Citrix NetScaler Leaks Data Before Login (CVE-2026-8451): 'CitrixBleed' Is Back and Under Active Attack
InfrastructureSecurity
Citrix NetScaler, the appliance many companies use to connect staff to internal systems, has a flaw (CVE-2026-8451, severity 8.8) that leaks internal data before login. A comeback of the 2023 'CitrixBleed' that caused mass breaches, it was exploited within 24 hours of disclosure. Stolen keys let attackers impersonate employees, so update and terminate all sessions.
2026.07.0832 views
News
Oracle E-Business Suite Can Be Hijacked Without a Password (CVE-2026-46817): Actively Exploited, Patch Now
InfrastructureSecurity
Oracle E-Business Suite, the core business software running accounting, payments and HR for large enterprises and governments, has an unauthenticated takeover flaw (CVE-2026-46817, severity 9.8) that is already under active attack. About 950 instances are exposed worldwide. It can leak payment and personal data, so apply Oracle's May 2026 fix immediately.
2026.07.0838 views
News
July 7, 2026 Security Vulnerability Roundup: Dell, Red Hat, Kubernetes Infra and More — Does It Affect You?
InfrastructureSecurity
A one-day roundup of the July 7, 2026 vulnerabilities we did not cover individually. Six items including Dell PowerProtect Data Domain and Red Hat SSSD, organized so you can judge relevance by whether a login is required. This day was enterprise-server focused with no consumer-facing emergency; we explain what operators should prioritize.
2026.07.0825 views
News
July 8, 2026 Security Vulnerability Roundup: Plesk, ArcGIS, Self-Hosted AI Tools and More — Does It Affect You?
DevelopmentSecurity
A one-day roundup of the July 8, 2026 vulnerabilities we did not cover individually. Eleven items including 9Router and Plesk, organized so you can judge relevance by whether a login is required. Actively exploited and KEV-listed items are flagged, and we explain what ordinary users must act on now.
2026.07.0850 views