Critical Switchvox Vulnerability Enables Unauthenticated Remote Code Execution
Attackers are exploiting CVE-2026-9586 in Sangoma Switchvox, allowing unauthenticated remote code execution and deployment of reverse shells on affected systems.
Attackers are exploiting CVE-2026-9586 in Sangoma Switchvox, allowing unauthenticated remote code execution and deployment of reverse shells on affected systems.
Security researchers have observed attackers chaining two PaperCut vulnerabilities to bypass authentication and execute remote code, prompting urgent patching and access restriction recommendations.
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public projects and user data on self managed installations.
A critical Gitea vulnerability tracked as CVE 2026 59774 allows unauthenticated attackers to read server files on affected self hosted instances. The issue is fixed in Gitea 1.27.1.
Researchers uncovered a sandbox escape vulnerability in Claude Cowork that could allow AI agents running locally on macOS to access files outside the virtual machine through a Linux kernel privilege escalation flaw.
Researchers discovered a flaw in Microsoft Azure DevOps MCP Server that allows hidden pull request comments to manipulate AI review agents and access sensitive project data.
Google is preparing a fix for a Gemini vulnerability that allows attackers with physical access to locked Android 16 devices to send SMS and WhatsApp messages without authentication.
Threat actors are actively exploiting the critical ServiceNow AI Platform vulnerability CVE 2026 6875, prompting organizations to apply available security updates to prevent unauthorized code execution.
Newly disclosed WordPress core vulnerabilities tracked as CVE 2026 63030 and CVE 2026 60137 could allow unauthenticated code execution on vulnerable websites. WordPress has released security updates and enabled forced updates for affected versions.
SonicWall has confirmed active exploitation of two zero day vulnerabilities affecting SMA 1000 appliances, including a critical flaw that could allow attackers to execute administrator level commands.