Microsoft Office Zero-Day CVE-2026-21509 Actively Exploited, Allows Attackers to Bypass Built-In Security Protections
CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office that allows an attacker to circumvent Office…
continue reading..
New Linux Kernel Flaws Allow Remote System Crashes and Guest-Triggered Host Denial-of-Service
Product: Linux KernelAffected Scope: Core kernel subsystems, networking, virtualization, storage, and device driversAttack Surface: Local, guest-to-host, network…
continue reading..
WordPress Privilege Escalation Flaw Exposes Sites to Full Admin Takeover (CVE-2025-14866)
CVE-2025-14866 is a high-impact privilege escalation vulnerability affecting the Melapress Role Editor WordPress plugin (versions ≤ 1.1.1).The…
continue reading..
CVE-2026-1364: Missing Authentication Bug Enables Unrestricted Admin Access in JNC Industrial Systems
CVE-2026-1364 is a critical authentication bypass vulnerability affecting JNC IAQS and I6 systems.The core issue is that…
continue reading..
High-Severity Flaw CVE-2026-22273 Exposes Dell Cloud Storage Systems to Privilege Escalation Attacks
CVE-2026-22273 is a high-severity security vulnerability affecting certain versions of Dell’s Elastic Cloud Storage (ECS) and ObjectScale…
continue reading..
Critical Security Vulnerability in ToDesktop Builder Enables Traffic Interception and Data Tampering
CVE-2025-67229 is a critical security vulnerability affecting applications built using ToDesktop Builder versions prior to 0.32.1.The flaw…
continue reading..
IMGspider WordPress Plugin Vulnerability Could Allow Internal Network Access
CVE-2026-22482 is a Server-Side Request Forgery (SSRF) vulnerability found in the IMGspider plugin for WordPress. SSRF flaws…
continue reading..
Critical Linux Kernel Bugs Could Crash Servers and Disrupt Network Services
Product Name: Linux KernelAffected Components: DAMON, xHCI, ip6 tunnel, BPF, idpf, nfsdProduct Type: Operating System KernelAttack Surface:…
continue reading..
CVE-2026-0755: Critical Zero-Auth RCE Flaw in gemini-mcp-tool Exposes Systems to Full Remote Takeover
CVE-2026-0755 – Command Injection in gemini-mcp-tool (Unauthenticated RCE) Overview CVE ID: CVE-2026-0755Affected component: gemini-mcp-tool – execAsync functionalityVulnerability…
continue reading..
