Aggregator
CVE-2026-27406 | Joe Dolson My Tickets Plugin up to 2.1.0 on WordPress insertion of sensitive information into sent data
CVE-2026-27428 | Eagle-Themes Eagle Booking Plugin up to 1.3.4.3 on WordPress sql injection
Shadows in the Inbox: Ukraine’s CERT-UA Unmasks the UAC-0252 Phishing Blitz and its “PalachPro” Ties
In early 2026, malicious actors initiated a mass dissemination of emails masquerading as official communications from Ukrainian state
The post Shadows in the Inbox: Ukraine’s CERT-UA Unmasks the UAC-0252 Phishing Blitz and its “PalachPro” Ties appeared first on Penetration Testing Tools.
CVE-2026-27396 | e-plugins Directory Pro Plugin up to 2.5.6 on WordPress authorization
CVE-2026-28089 | ThemeREX Daiquiri Plugin up to 1.2.4 on WordPress filename control (EUVD-2026-9744)
CVE-2026-28088 | ThemeREX Aqualots Plugin up to 1.1.6 on WordPress filename control (EUVD-2026-9743)
CVE-2026-28087 | ThemeREX Filmax Plugin up to 1.1.11 on WordPress filename control (EUVD-2026-9742)
CVE-2026-28086 | ThemeREX Run Gran Plugin up to 2.0 on WordPress filename control (EUVD-2026-9741)
CVE-2026-28085 | ThemeREX Mahogany Plugin up to 2.9 on WordPress filename control (EUVD-2026-9740)
CVE-2026-28084 | ThemeREX Bazinga Plugin up to 1.1.9 on WordPress filename control
CVE-2026-28081 | ThemeREX Windsor Plugin up to 2.5.0 on WordPress filename control
CVE-2026-28079 | axiomthemes Conquerors Plugin up to 1.2.13 on WordPress filename control
CVE-2026-25702 | SUSE Linux Enterprise Server 12 SP5 nftables access control (EUVD-2026-9793)
CVE-2026-28038 | Brainstorm_Force Ultimate Addons for WPBakery Page Builder Plugin up to 3.21.1 on WordPress authorization
CVE-2026-27386 | DesignThemes Directory Addon Plugin up to 1.8 on WordPress authorization
CVE-2026-27390 | DesignThemes WeDesignTech Ultimate Booking Addon Plugin up to 1.0.1 on WordPress authentication bypass
Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers
Researchers have uncovered a critical zero-click vulnerability in FreeScout, a widely used open-source help desk and shared mailbox application. Dubbed “Mail2Shell,” this flaw allows attackers to hijack mail servers without any user interaction or authentication. The vulnerability, tracked as CVE-2026-28289, bypasses a recently patched Remote Code Execution (RCE) flaw, escalating it into an unauthenticated zero-click […]
The post Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers appeared first on Cyber Security News.
2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk
GitGuardian partnered with Google to answer: what happens when private keys leak? Using Certificate Transparency, we mapped about 1M leaked keys to 140k certificates. Result: 2,622 were valid as of September 2025, exposing major organizations. Our disclosure campaign achieved 97% remediation.
The post 2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk appeared first on Security Boulevard.