A vulnerability was found in CoreDNS up to 1.14.2. It has been classified as problematic. This issue affects the function longestMatch of the file plugin/transfer/transfer.go. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-33489. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Masa CMS up to 7.2.9/7.3.14/7.4.9/7.5.2. It has been classified as critical. The impacted element is the function getQuery of the file beanFeed.cfc. The manipulation of the argument sortBy leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-40329. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in NeoRazorX facturascripts up to 2025.92. The impacted element is an unknown function of the component User Interface. This manipulation of the argument nick causes external control of assumed-immutable web parameter.
This vulnerability is registered as CVE-2026-32699. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Masa CMS up to 7.2.9/7.3.14/7.4.9/7.5.2 and classified as critical. The affected element is the function getQuery of the file beanFeed.cfc. Executing a manipulation of the argument sortDirection can lead to sql injection.
This vulnerability is handled as CVE-2026-40330. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in FluentCMS 1.2.3. It has been rated as problematic. This impacts an unknown function of the component TextHTML Plugin. This manipulation causes HTML injection.
The identification of this vulnerability is CVE-2026-38947. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in ProFTPd up to 1.3.9a. It has been declared as critical. This affects the function sqltab_fetch_clients_cb of the file contrib/mod_wrap2_sql.c. The manipulation results in sql injection.
This vulnerability was named CVE-2026-44331. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.
A vulnerability categorized as critical has been discovered in Masa CMS up to 7.2.9/7.3.14/7.4.9/7.5.2. Affected is the function setAltTable of the file feedGateway.cfc. Such manipulation of the argument altTable leads to sql injection.
This vulnerability is referenced as CVE-2026-40331. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
Security Leaders From Equifax, Rapid7 on Identity Security and Visibility Failures In part one of the Anatomy of a Breach series, Equifax's Jeremy Koppen and Rapid7's Christiaan Beek examine why familiar security gaps still lead to breaches. Experts discuss ways to improve readiness in the face of identity-driven attacks, visibility failures and governance weaknesses.
Mythos a Turning Point, Say Lawmakers in Missive to European Commission Dozens of European lawmakers are pressing the European Commission to act quickly to protect the continent's cybersecurity, due to the advent of new AI models that have considerable hacking prowess.
Critical Infrastructure Operators Urged to Fortify Against Nation-State Attacks The Cybersecurity and Infrastructure Security Agency launched CI Fortify, urging critical infrastructure operators to adopt isolation and rapid recovery capabilities to maintain essential services under cyberattacks, amid warnings that nation-state actors are already embedded in operational systems.
Security Leaders Face Gaps, Not in Their Org Charts, But in Their Team's Skills Concerns about the skills and capabilities of cybersecurity teams have for the first time overtaken worries about headcount and unfilled vacancies among CISOs, according to a new SANS survey.
Applied Quantum's Kawin Boonyapredee, SpeQtral's Cyril Tan on Hybrid Security Hybrid cryptography is emerging as a practical path to quantum safety. Kawin Boonyapredee from Applied Quantum and Cyril Tan from SpeQtral said combining QKD and PQC builds resilience against future threats while balancing performance and security needs.
Security Leaders From Equifax, Rapid7 on Identity Security and Visibility Failures In part one of the Anatomy of a Breach series, Equifax's Jeremy Koppen and Rapid7's Christiaan Beek examine why familiar security gaps still lead to breaches. Experts discuss ways to improve readiness in the face of identity-driven attacks, visibility failures and governance weaknesses.
Mythos a Turning Point, Say Lawmakers in Missive to European Commission Dozens of European lawmakers are pressing the European Commission to act quickly to protect the continent's cybersecurity, due to the advent of new AI models that have considerable hacking prowess.
Security Leaders Face Gaps, Not in Their Org Charts, But in Their Team's Skills Concerns about the skills and capabilities of cybersecurity teams have for the first time overtaken worries about headcount and unfilled vacancies among CISOs, according to a new SANS survey.
Info is scant, but such breaches can reveal where a security product's controls are located and how detections are designed, giving attackers a leg up.