Aggregator
CVE-2026-11583 | CodeAstro Student Attendance Management System 1.0 createClass.php className sql injection
CVE-2026-11582 | CodeAstro Student Attendance Management System 1.0 index.php Username sql injection
Submit #836800: codeastro Student Attendance Management System V1.0 SQL Injection [Accepted]
Submit #836799: codeastro Student Attendance Management System V1.0 SQL Injection [Accepted]
Submit #836798: codeastro Student Attendance Management System V1.0 SQL Injection [Accepted]
Submit #836796: codeastro Student Attendance Management System V1.0 SQL Injection [Accepted]
CVE-2026-50752 | Check Point Quantum Security Gateway/Spark Firewalls certificate validation
CVE-2026-50751 | Check Point Quantum Security Gateway/Spark Firewalls IKEv1 Key Exchange improper authentication
CVE-2026-11569 | Red Hat Quay 3 Filedrop Endpoint cross site scripting (WID-SEC-2026-1816)
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability
- CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CVE-2026-3011 | wpzoom Recipe Card Blocks Lite Plugin up to 3.4.13 on WordPress deserialize_block_attributes summary/notes cross site scripting
CVE-2026-9506 | Webkul Bagisto 2.4.1 ImageCacheController filename path traversal (CIVN-2026-0292)
The Hardest Fork
Без взлома, без вируса, только голос. Вымогатели Pink рушат корпоративную безопасность одним телефонным разговором
RidgeBot 7.0 automates Active Directory attack simulations for security validation
Ridge Security has announced the release of RidgeBot 7.0, an update to its automated security validation platform that introduces automated Windows Active Directory penetration testing capabilities. The new version enables organizations to conduct end-to-end domain compromise simulations, helping security teams identify attack paths and prioritize exploitable risks. RidgeBot 7.0 delivers automated Active Directory penetration testing scenarios that include enumeration, credential extraction, lateral movement, and Domain Admin path validation. All attack activities are mapped to the … More →
The post RidgeBot 7.0 automates Active Directory attack simulations for security validation appeared first on Help Net Security.
Instagram Recovery Tool Bug Exposed 20,225 Accounts to Password Reset Abuse
ConnectSecure’s Patch 360 gives MSPs control over patch testing and deployment
ConnectSecure has announced the launch of Patch 360, a patch management solution built for managed service providers (MSPs) to reduce deployment risk while accelerating vulnerability remediation. Patch management has long followed a “deploy-and-hope” model, with teams addressing critical issues only after users are impacted. Patch 360 replaces that approach with a rigorous test-and-trust framework that allows MSPs to validate patches before broad deployment, with visibility from prioritization and pilot testing through rollout and rollback. “As … More →
The post ConnectSecure’s Patch 360 gives MSPs control over patch testing and deployment appeared first on Help Net Security.