Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Fortinet FortiOS has a vulnerability (CVE-2025-68686) that exposes sensitive information to unauthorized actors. A remote attacker can bypass a previously implemented patch for symbolic link persistency by sending crafted HTTP requests, but only after first compromising the system via another filesystem-level exploit.
Oracle E-Business Suite has been identified with a critical vulnerability, CVE-2026-46817, involving improper privilege management. This flaw allows unauthenticated attackers with network access via HTTP to compromise Oracle Payments, potentially leading to a complete takeover of the system.
Cisco IOS 12.4 contains critical cross-site request forgery (CSRF) vulnerabilities (CVE-2008-4128) that allow remote attackers to execute arbitrary commands. The flaws exist in two specific URIs: "/level/15/exec/-" (via a "show privilege" command) and "/level/15/exec/-/configure/http" (via an "alias exec" command).
Check Point SmartConsole, a network security management tool, contains a critical improper authentication vulnerability (CVE-2026-16232) that allows unauthenticated remote attackers to obtain login tokens and gain full administrative privileges. The flaw, actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on July 22, 2026.
Microsoft SharePoint: Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Balbooa Forms, a popular web form builder, has been identified with a critical vulnerability (CVE-2026-56291) that allows unauthenticated users to upload arbitrary files, including executable files, potentially leading to remote code execution (RCE). This unrestricted upload of dangerous file types poses a severe security risk, as attackers could exploit it to gain full control over affected systems.