Aggregator
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
2 months ago
A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases.
Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database
The Hacker News
21 модель iPhone под угрозой. Рассказываем, как работает коммерческое шпионское ПО нового поколения
2 months ago
Обновитесь до iOS 17 или готовьтесь к слежке.
Hackers Hide Backdoor in Trusted WordPress Plugins for 8 Months Before Activating Malware
2 months ago
A group of trusted WordPress plugins quietly carried a hidden backdoor for eight full months, and nobody noticed until the damage had already been done. The attack, uncovered in April 2026, did not begin with a dramatic breach. It started with the silent purchase of a legitimate plugin business on a public marketplace, setting the […]
The post Hackers Hide Backdoor in Trusted WordPress Plugins for 8 Months Before Activating Malware appeared first on Cyber Security News.
Tushar Subhra Dutta
CVE-2026-28741 | Mattermost up to 10.11.12/11.3.2/11.4.2/11.5.0 cross-site request forgery
2 months ago
A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.12/11.3.2/11.4.2/11.5.0. The affected element is an unknown function. This manipulation causes cross-site request forgery.
This vulnerability is registered as CVE-2026-28741. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-40778 | Majestic Support Plugin up to 1.1.2 on WordPress authorization (EUVD-2026-22905)
2 months ago
A vulnerability classified as critical was found in Majestic Support Plugin up to 1.1.2 on WordPress. Impacted is an unknown function. The manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2026-40778. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-40764 | Syed Balkhi Contact Form by WPForms Plugin up to 1.10.0.2 on WordPress cross-site request forgery (EUVD-2026-22903)
2 months ago
A vulnerability classified as problematic has been found in Syed Balkhi Contact Form by WPForms Plugin up to 1.10.0.2 on WordPress. This issue affects some unknown processing. The manipulation leads to cross-site request forgery.
This vulnerability is listed as CVE-2026-40764. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-27769 | Mattermost up to 10.11.12/11.4.x Conntexted Workspaces Feature authorization
2 months ago
A vulnerability described as problematic has been identified in Mattermost up to 10.11.12/11.4.x. This vulnerability affects unknown code of the component Conntexted Workspaces Feature. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-27769. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-1852 | WooBeWoo Product Pricing Table Plugin up to 1.1.0 on WordPress updateLabel cross-site request forgery (EUVD-2026-22911)
2 months ago
A vulnerability marked as problematic has been reported in WooBeWoo Product Pricing Table Plugin up to 1.1.0 on WordPress. This affects the function updateLabel. Performing a manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2026-1852. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-40734 | Zahlan Categories Images Plugin up to 3.3.1 on WordPress cross site scripting
2 months ago
A vulnerability labeled as problematic has been found in Zahlan Categories Images Plugin up to 3.3.1 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-40734. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-40763 | WP Royal Royal Elementor Addons Plugin up to 1.7.1056 on WordPress authorization (EUVD-2026-22902)
2 months ago
A vulnerability identified as critical has been detected in WP Royal Royal Elementor Addons Plugin up to 1.7.1056 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes missing authorization.
The identification of this vulnerability is CVE-2026-40763. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-40784 | Mahmudul Hasan Arif FluentBoards Plugin up to 1.91.2 on WordPress authorization
2 months ago
A vulnerability categorized as critical has been discovered in Mahmudul Hasan Arif FluentBoards Plugin up to 1.91.2 on WordPress. Affected is an unknown function. The manipulation results in authorization bypass.
This vulnerability was named CVE-2026-40784. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-40786 | Long Watch Studio MyRewards Plugin up to 5.7.3 on WordPress authorization (EUVD-2026-22910)
2 months ago
A vulnerability was found in Long Watch Studio MyRewards Plugin up to 5.7.3 on WordPress. It has been rated as critical. This impacts an unknown function. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-40786. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-40745 | bdthemes Element Pack Elementor Addons Plugin up to 8.4.2 on WordPress sql injection
2 months ago
A vulnerability was found in bdthemes Element Pack Elementor Addons Plugin up to 8.4.2 on WordPress. It has been declared as critical. This affects an unknown function. Executing a manipulation can lead to sql injection.
This vulnerability is handled as CVE-2026-40745. The attack can be executed remotely. There is not any exploit available.
vuldb.com
Any Color You Like: NIST Scientists Create ‘Any Wavelength’ Lasers in Tiny Circuits for Light
2 months ago
NIST scientists and collaborators have pioneered a way to make integrated circuits for light by depositing complex patterns of specialized materials onto silicon wafers.
Sarah Henderson
Вы нажали «отказаться от слежки через куки». Google нажал «игнорировать». В 87% случаев
2 months ago
Они проверили 7000 сайтов и поняли: выбора у нас нет. Лишь его иллюзия.
CVE-2026-40729 | bPlugins 3D viewer Plugin up to 1.8.5 on WordPress authorization
2 months ago
A vulnerability was found in bPlugins 3D viewer Plugin up to 1.8.5 on WordPress. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in missing authorization.
This vulnerability is known as CVE-2026-40729. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
Retaining defensive advantage in the age of frontier AI cyber capabilities
2 months ago
As AI accelerates vulnerability discovery, organisations must raise their security baselines to safeguard their cyber security.
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
2 months ago
Two recently fixed prompt injections in Salesforce Agentforce and Microsoft Copilot would have enabled an external attacker to leak sensitive data.
Alexander Culafi
CVE-2026-33805 | fastify reply-from/http-proxy prior 12.6.2 Header rewriteRequestHeaders Connection http headers for scripting syntax
2 months ago
A vulnerability was found in fastify reply-from and http-proxy and classified as critical. The affected element is the function rewriteRequestHeaders of the component Header Handler. Such manipulation of the argument Connection leads to improper neutralization of http headers for scripting syntax.
This vulnerability is traded as CVE-2026-33805. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com