News
Oracle Ships 943 Patches: CVE-2026-61241 Hits Max CVSS 10.0
InfrastructureSecurity
Oracle's August 2026 monthly update brings 943 patches, 3 at CVSS 10.0 and 467 exploitable without login, concentrated in Hyperion and Fusion Middleware.
2026.08.1925 views
News
CVE-2026-70408: acmailer Flaw Lets Staff Accounts Become Admins
Japanese CompaniesSecurity
acmailer CVE-2026-70408 (CVSS 8.8) lets a sub-account create an admin. Fixed in CGI 4.1.2 / DB 1.2.2 — and if you no longer use acmailer, delete it entirely.
2026.08.1916 views
News
VMware vCenter CVE-2026-59310 Exploited: Patch Now, No Workaround
SecurityInfrastructure
CISA added VMware vCenter CVE-2026-59310 (CVSS 9.8) to KEV after 361 intrusions in 47 countries. No workaround — update to 8.0 U3k/U2f, 9.0.2.0100, 9.1.0.0300.
2026.08.1973 views
News
ManageEngine Password Manager Pro CVE-2026-11840: mind the build
InfrastructureSecurity
A CVSS 8.8 SQL injection hits ManageEngine Password Manager Pro and PAM360. The Japanese build line differs: 13232 does not exist there, and 13234 is the fix.
2026.08.1315 views
News
LXD hit by 11 flaws including CVE-2026-63294, only 4 affect solo hosts
SecurityLinux
Canonical's LXD picked up 11 CVE entries on August 12, nine rated 9.9. Fixes shipped August 2, seven need multi-tenant setups, and LXD 6.10 does not exist.
2026.08.1332 views
News
Ransomware at 157 Japanese retail stores: all reopened, points still down
SecurityJapanese Companies
REXT Corporation, which runs WonderGOO, Shinseido and WonderREX, was hit by ransomware on August 9. Registers, points and buybacks are still down on day five.
2026.08.1334 views
News
SAP August 2026: A 10.0 Flaw (CVE-2026-58231) and No Japanese Advisory
InfrastructureSecurity
SAP shipped its August 2026 fixes: a 10.0 in Commerce Cloud and a 9.8 in NetWeaver ABAP, both unauthenticated. The 9.8 has no workaround and needs downtime.
2026.08.1241 views
News
Cisco VPN Gateways Knocked Offline: CVE-2026-20349, Scope and Fixes
SecurityInfrastructure
Cisco ASA and FTD let anyone reboot the device with no login, cutting VPN access. Already exploited, no workaround, and CISA set an August 14 deadline.
2026.08.1259 views
News
Fluent Forms Pro shipped a backdoored update for five hours: CVE-2026-73532
DevelopmentSecurity
MonsterInsights Pro shipped malware after its update bucket was hijacked. The version it rolled back to was poisoned too. Three CVEs, 9.8+. Paid versions only.
2026.08.0756 views
News
Apache CXF's 12 flaws get scored — 'low' became 9.8, and Red Hat has not moved
SecurityDevelopment
Apache CXF, the Java layer enterprises use for data exchange, has six new flaws. One lets a single message take over the server. Upgrade to 4.2.3/4.1.8/3.6.12.
2026.08.0640 views
News
Nine quiet days for Cisco IOS XE's ten flaws, and a correction on CVE-2026-20310
SecurityInfrastructure
Cisco disclosed ten IOS XE vulnerabilities at once, the worst rated 9.8, none with a workaround. They did not surface through attacks — Cisco found them in its own internal review.
2026.08.0655 views
News
TeamCity CVE-2026-63077 Is Being Exploited, Exploit Code Public
DevelopmentSecurity
CISA gave US agencies three days to patch a TeamCity flaw that lets anyone take over the build server with no login. Self-hosted only; fixed since July 27.
2026.08.0632 views