Cisco Secure Workload CVE-2026-20223: Max Severity Site Admin Bypass
May 21, 2026 Cisco has patched a maximum severity vulnerability in Cisco Secure Workload that lets unauthenticated attackers gain full Site Admin privileges. The flaw, tracked as CVE-2026-20223, impacts the product’s internal REST APIs and carries…
Ghost CMS SQL Injection CVE-2026-26980: ClickFix Campaign Hits 700+ Domains
May 24, 2026 A large-scale campaign is actively exploiting a critical SQL injection vulnerability in Ghost CMS to inject malicious JavaScript that drives ClickFix attack flows. The campaign has already compromised more than 700 domains, including…
Ubiquiti Patches Three Maximum Severity UniFi OS Vulnerabilities
May 24, 2026 Ubiquiti has released urgent security updates for three maximum severity UniFi OS vulnerabilities that allow remote attackers to compromise systems without authentication. These flaws affect the core operating system powering UniFi Consoles…
Drupal Critical SQL Injection Flaw CVE-2026-9082 Now Under Active Attack
May 23, 2026 Drupal has confirmed that a highly critical SQL injection vulnerability (CVE-2026-9082) in its core database abstraction API is now under active attack. Disclosed on May 18, 2026, the flaw allows unauthenticated remote attackers to execute…
Trend Micro Apex One Zero-Day Under Active Exploit
May 22, 2026 On May 22, 2026, Trend Micro disclosed a zero-day vulnerability in its enterprise endpoint protection platform, Apex One. The flaw is actively being exploited in the wild. Tracked as CVE-2026-34926, it is a directory traversal vulnerability…
Apache HTTP Server Double-Free Vulnerability
May 10, 2026 The Apache Software Foundation released an emergency security patch on May 5, 2026, to address CVE-2026-23918, a critical HTTP/2 double-free vulnerability in the Apache HTTP Server that enables remote code execution (RCE). With a CVSS v3.1…
Dirty Frag Linux Kernel Vulnerability Grants Root Access
May 8, 2026 A critical local privilege escalation vulnerability known as Dirty Frag (CVE-2026-43284) has been disclosed, affecting the Linux kernel’s xfrm-ESP subsystem. First reported to the Linux kernel maintainers on April 30, 2026, this…