SonicWall SMA1000 RCE Vulnerability: Patch Now

SonicWall SMA1000 RCE vulnerability

A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…

Read More

JFrog Artifactory Authentication Bypass Exploited

JFrog Artifactory Authentication Bypass Exploited

A JFrog Artifactory authentication bypass is now under active exploitation: attackers are minting themselves unauthenticated administrator tokens on self-hosted Artifactory instances just days after JFrog disclosed the flaw. Tracked as CVE-2026-82329 (CVSS 9.8), the bug sits in Artifactory’s default, out-of-the-box configuration — no misconfiguration required, no credentials needed. What Happened JFrog disclosed the JFrog Artifactory…

Read More

Exchange Authentication Bypass Vulnerability Now Exploitable

A public exploit for an Exchange authentication bypass vulnerability is live, and 85% of German on-prem servers remain unpatched, BSI warns.

A working exploit for an Exchange authentication bypass vulnerability is now public on GitHub, and heise.de reports that roughly 85% of on-premises Exchange servers in Germany remain vulnerable three weeks after Microsoft shipped a fix. The catch: for organizations still running Exchange 2016 or 2019, that fix is locked behind Microsoft’s paid Extended Security Update…

Read More

PaperCut RCE Vulnerability Actively Exploited

A PaperCut RCE vulnerability chain is under active exploitation on PaperCut NG and MF servers. Two flaws let attackers run code with no login. Patch now.

A newly disclosed PaperCut RCE vulnerability is already being exploited against PaperCut NG and PaperCut MF print management servers worldwide. PaperCut confirmed active attacks on August 27, 2026, shipped an emergency patch within hours, then replaced it with a hardened second patch the next morning after researchers found the first fix incomplete. Every organization running…

Read More

miniOrange SAML SSO Bypass Vulnerability

A miniOrange SAML SSO bypass (CVE-2026-61979, CVE-2026-15981) lets attackers forge admin logins on WordPress — and most scanners miss it.

A miniOrange SAML SSO bypass is under active exploitation against WordPress sites, and most vulnerability scanners cannot detect whether a given site is actually affected. Two chained authentication bugs, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8 each), let an unauthenticated attacker forge a SAML login and access wp-admin as any existing user, including administrators. DigitalOcean confirmed exploitation…

Read More