Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Microsoft SharePoint Server: Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
A critical code injection vulnerability (CVE-2026-15410) in SonicWall SMA1000 appliances allows remote authenticated attackers with administrator privileges to execute arbitrary OS commands. The flaw, actively exploited in the wild, affects SonicWall's Secure Mobile Access (SMA) 1000 series appliances, which are widely used for secure remote network access.
Langflow, a software product, contains a critical vulnerability (CVE-2026-55255) that allows authenticated attackers to bypass authorization controls. By manipulating a user-controlled key in requests, attackers can execute flows belonging to other users by specifying the victim’s flow ID. This flaw was added to CISA’s Known Exploited Vulnerabilities catalog on July 7, 2026, and is actively being exploited in the wild.
Microsoft Active Directory Federation Services (AD FS) has a critical vulnerability (CVE-2026-56155) that enables authorized attackers to locally escalate privileges due to insufficient access control granularity. The flaw, actively exploited in the wild, was added to CISA’s Known Exploited Vulnerabilities catalog on July 14, 2026, highlighting its immediate threat.
Microsoft SharePoint: Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Fortinet FortiSandbox: Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.