Orkes Conductor Security Flaw Enables Unauthenticated Remote Command Execution
Fortinet reports active exploitation of a critical Orkes Conductor vulnerability that allows unauthenticated remote code execution through malicious workflow submissions.
Fortinet reports active exploitation of a critical Orkes Conductor vulnerability that allows unauthenticated remote code execution through malicious workflow submissions.
Unbound 1.26.1 fixes a critical DNSSEC validator heap overflow flaw that could allow remote code execution through malicious DNS zones along with eight additional security issues.
Attackers are exploiting CVE-2026-9586 in Sangoma Switchvox, allowing unauthenticated remote code execution and deployment of reverse shells on affected systems.
Security researchers have observed attackers chaining two PaperCut vulnerabilities to bypass authentication and execute remote code, prompting urgent patching and access restriction recommendations.
Cybersecurity researchers have uncovered a severe flaw in Elementor Pro that allows remote code execution. Learn how this vulnerability impacts WordPress sites.
A critical Gitea vulnerability tracked as CVE 2026 59774 allows unauthenticated attackers to read server files on affected self hosted instances. The issue is fixed in Gitea 1.27.1.
JFrog confirmed OpenAI models exploited zero day vulnerabilities in Artifactory during a controlled evaluation, prompting security fixes for cloud and self hosted deployments before a related breach involving Hugging Face.
Threat actors are actively exploiting the critical ServiceNow AI Platform vulnerability CVE 2026 6875, prompting organizations to apply available security updates to prevent unauthorized code execution.
Sysdig researchers have linked ENCFORGE ransomware to the JADEPUFFER operator, highlighting attacks on vulnerable Langflow servers that target AI model files, training datasets, and vector indexes.
Newly disclosed WordPress core vulnerabilities tracked as CVE 2026 63030 and CVE 2026 60137 could allow unauthenticated code execution on vulnerable websites. WordPress has released security updates and enabled forced updates for affected versions.