Cyber Alerts
Verified· Officially confirmed
Recently, Zoom has released a security update to address a critical vulnerability (CVE-2026-53412) affecting the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and the Zoom Meeting SDK for Windows.
Cyber Alerts
Verified· Officially confirmed
Recently, Microsoft has released security updates on a missing authentication for critical function vulnerability in on-premises Microsoft SharePoint Server.
Cyber Alerts
Verified· Officially confirmed
Recently, Microsoft has released security updates on a high-severity local elevation-of-privilege vulnerability (CVE-2026-56155) in Microsoft Active Directory Federation Services (AD FS).
Cyber Alerts
Verified· Officially confirmed
Recently, the Cybersecurity and Infrastructure Security Agency (CISA) released a security alert warning organisations of the active exploitation of multiple vulnerabilities affecting on-premises Microsoft SharePoint Server. The vulnerabilities, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, could allow cyber threat actors to gain unauthorised access to vulnerable systems, execute arbitrary code remotely, and conduct malicious post-exploitation activities.
Cyber Alerts
Verified· Officially confirmed
On 17 July 2026, WordPress released versions 6.9.5 and 7.0.2 to address a critical, unauthenticated Remote Code Execution (RCE) vulnerability in WordPress core, publicly referred to as "wp2shell". The flaw resides in the REST API batch-route handling and involves a route-confusion condition combined with an SQL injection weakness, allowing an anonymous attacker to execute arbitrary code on a default WordPress installation with no plugins required. The vulnerability was discovered and responsibly disclosed by a researcher at Assetnote (Searchlight Cyber) through the official WordPress HackerOne program. WordPress has enabled forced auto-updates to push the patch to affected sites, though sites with auto-updates disabled must verify and patch manually. 2.0 Technical DetailsVulnerability class: REST API batch-route confusion combined with SQL Injection, leading to Remote Code Execution. Attack vector: Unauthenticated / anonymous HTTP request — no prior access or credentials required.Affected component: WordPress REST API batch endpoint (/wp-json/batch/v1 and the rest_route=/batch/v1 query-string equivalent).Files modified in the fix: wp-includes/rest-api/class-wp-rest-server.php, wp-includes/class-wp-query.php, wp-includes/rest-api.php.CVE-2026-63030 — the REST API batch-route confusion / RCE chain; CVSS 7.5 per the official GitHub Security Advisory (GHSA-ff9f-jf42-662q), rated Critical severity by WordPress; some third-party exploit-tracking listings report scores as high as 9.8. Affects WordPress 6.9 and later.CVE-2026-60137 — the underlying SQL injection (in the author__not_in parameter of WP_Query), affecting WordPress 6.8 and later; fixed in 6.8.6 for the 6.8 branch.Per Cloudflare's analysis, the RCE path is reachable specifically when a persistent object cache is not enabled on the target site.The two CVEs must be chained together to achieve full remote code execution; CVE-2026-60137 alone permits blind SQL injection but not code execution. Full technical exploitation details have not been publicly released by the discovering researcher; a self-service checker has been made available to allow site owners to test their own instances. 3.0 Affected Versions Affected Branch Fixed In 6.9.0 – 6.9.4 6.9.5 7.0.0 – 7.0.1 7.0.2 7.1 (beta) 7.1 beta2 (fix included) 6.8.x (unrelated SQLi) 6.8.6
Cyber Alerts
Verified· Officially confirmed
Recently, the Joomla Content Editor (JCE) maintainers has released a security update in the JCE extension tracked as CVE-2026-48907, an unauthenticated remote code execution vulnerability.
Cyber Alerts
Verified· Officially confirmed
Recently, F5 has released an out-of-band security update to address a use-after-free vulnerability in the ngx_http_v3_module (CVE-2026-42530) and a heap-based buffer overflow vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module (CVE-2026-42055) affecting NGINX.
Cyber Alerts
Verified· Officially confirmed
Recently, MariaDB has released security updates to address multiple vulnerabilities (CVE-2026-49261, CVE-2026-48165, CVE-2026-48163, and CVE-2026-44168) affecting MariaDB Community Server with Galera Cluster (wsrep) enabled.
Cyber Alerts
Verified· Officially confirmed
Recently, Oracle released has released security updates to address vulnerabilities in the Remote Administration Daemon component (CVE-2026-46978), the Filesystem component (CVE-2026-46914), and the Libraries component (CVE-2026-35233) of Oracle Solaris.
Cyber Alerts
Verified· Officially confirmed
MyCERT is observing an active malware campaign that delivers malicious Visual Basic Script (.vbs) files directly through WhatsApp. This campaign is highly targeted at individuals using WhatsApp Desktop or WhatsApp Web on Microsoft Windows operating systems. The risk is entirely confined to Windows environments. VBS files do not execute on iOS, Android, macOS, or Linux devices, and WhatsApp mobile applications will not download or process .vbs attachments as executable files. 2.0 Modus OperandiAttackers contact victims via WhatsApp and attempt to socially engineer them into opening a malicious attachment. The payload is a .vbs file deliberately disguised as a routine financial or administrative document to trick the user into executing it. Recent examples of this social engineering tactic demonstrate the attackers using varied filenames to create urgency or relevance: A legal or debt-themed lure named "Acknowledgment of Debt.vbs"An invoice-themed lure named “Sila semak bil anda..vbs”A financial statement lure named “December statement of account.vbs”A financial reconciliation statement themed lure named "Reconciliation.vbs" If a user clicks and opens these .vbs files on a Windows machine, the script executes and begins the infection process.
Cyber Alerts
Verified· Officially confirmed
Recently, a large dataset containing credentials and configuration information associated with approximately 73,000 Fortinet VPN and firewall devices has been publicly disclosed. This dataset was collected through a campaign conducted by threat actors to obtain these credentials, while this does not appear to be linked to a newly discovered Fortinet vulnerability. The exposed data reportedly includes usernames, passwords, VPN configuration details, and other device information. Organisations whose devices have internet-facing management interfaces and credentials may be included in the leaked dataset. This may pose a risk of compromise and should prompt organisations to take immediate action to determine whether there is any evidence of unauthorised access in their organisations.
Cyber Alerts
Verified· Officially confirmed
Recently, LiteSpeed cPanel has released a security updates to address a high-severity LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following vulnerability tracked as CVE-2026-54420.