News Updated 4 days ago
WordPress plugins shipped malware via official updates: CVE-2026-11976
DevelopmentSecurity
MonsterInsights Pro shipped malware after its update bucket was hijacked. The version it rolled back to was poisoned too. Three CVEs, 9.8+. Paid versions only.
2026.08.0719 views
News Updated 4 days ago
Twelve Flaws in Apache CXF: Seven Skip Checks the Spec Made Mandatory
DevelopmentSecurity
Apache CXF, the Java layer enterprises use for data exchange, has six new flaws. One lets a single message take over the server. Upgrade to 4.2.3/4.1.8/3.6.12.
2026.08.0617 views
News Updated 5 days ago
CISA Gives Three Days to Patch TeamCity Flaw CVE-2026-63077
SecurityDevelopment
CISA gave US agencies three days to patch a TeamCity flaw that lets anyone take over the build server with no login. Self-hosted only; fixed since July 27.
2026.08.0616 views
News Updated 5 days ago
24 WordPress plugin flaws: two-factor authentication itself can be bypassed (CVE-2026-15372)
SecurityDevelopment
Twenty-four WordPress plugin vulnerabilities were published on August 5, 2026, and four of them break two-factor authentication. WP 2FA never validated the second factor; miniOrange 2FA let an attacker re-point it. Four more expose password-protected content and three hand over the whole site. All 24 have fixed releases.
2026.08.0510 views
News Updated 5 days ago
10 WordPress plugin flaws, 200,000-site PrettyLinks included — all already patched (CVE-2026-9273)
DevelopmentSecurity
Ten WordPress plugin vulnerabilities were published on August 5, 2026. The heaviest, in Kadence Memberships, lets an unauthenticated attacker hijack an administrator's password reset. All ten already have released fixes, the oldest from May 20 — only sites that stopped updating are at risk. PrettyLinks on 200,000 sites is included.
2026.08.054 views
News Updated 5 days ago
Five WordPress Plugin Flaws, All Ending in Account Takeover (CVE-2026-9273)
SecurityDevelopment
Five WordPress plugin vulnerabilities were published on August 5, 2026, and all five end in account takeover. Kadence Memberships lets an unauthenticated attacker hijack an administrator's password reset; Dokan lets anyone who can register as a vendor seize an administrator account. All five already have fixed releases, so updating ends it.
2026.08.055 views
News Updated 6 days ago
Jetty auth bypass CVE-2026-10050: non-ASCII passwords collapse to ?
DevelopmentSecurity
A Jetty flaw lets a login through without checking the password when it contains non-Latin characters. Only with Digest auth. Fixes for Jetty 9-11 are not free.
2026.08.0412 views
News Updated 7 days ago
12 flaws in baserCMS, only one is traceable (CVE-2026-65875)
DevelopmentSecurity
baserCMS disclosed 12 flaws on July 30, 2026, three rated Critical. Eleven cannot be looked up by number, and Dependabot warns about none of them.
2026.08.037 views
News Updated 7 days ago
27 WordPress plugin flaws, no-login admin takeover (CVE-2026-15930)
DevelopmentSecurity
27 WordPress plugin flaws landed August 3, 2026. Simple Membership (40,000+ sites) gives up the admin account with no login. Eleven need no login, 7 unfixed.
2026.08.039 views
News Updated 7 days ago
27 WordPress plugin flaws: CVE-2026-15383 hits a Japan-made plugin
SecurityDevelopmentJapanese Companies
27 WordPress plugin flaws went public Aug 3, 2026. One hits a Japan-made plugin on 9,000 sites: any visitor can plant script that runs in the admin dashboard. It was quietly fixed July 31.
2026.08.0312 views
News
Transformers path traversal writes files anywhere (CVE-2026-9856)
SecurityAIDevelopment
Loading and saving a crafted Hugging Face model lets an attacker write files outside its folder. NVD's affected range is wrong — upgrade to 5.10.1 or later.
2026.08.0312 views
News
PyAthena SQL injection can expose other tables (CVE-2026-65321)
DevelopmentInfrastructureSecurity
PyAthena, the standard Python client for Amazon Athena, mishandles quotes in DELETE and CTAS statements, letting untrusted input inject SQL. Update to 3.35.4.
2026.08.0312 views