Skip to main content

14,530 Dahua CCTV Cameras and NVRs Compromised in Active Campaign Using Authentication Bypass Flaws

Scope: Dahua IP Cameras, NVRs, and DVRs (All Models Running Unpatched Firmware)

Adobe Commerce and Magento Unauthenticated Customer Account Hijacking Now Under Active Exploitation (CVE-2026-71362)

Scope: Adobe Commerce and Magento Open Source (All Supported Versions Prior to August 2026

CISA Orders Emergency Patching of Four Critical Flaws Including Microsoft IKE, SharePoint, VMware, and macOS by August 21 (CVE-2026-33824 and Others)

Scope: Microsoft IKE Service Extensions, Microsoft SharePoint Server, VMware vCenter, Appl

Microsoft SharePoint Complete Unauthenticated RCE Chain Now Fully Patched Across Two Patch Tuesdays (CVE-2026-55040 / CVE-2026-63520)

Scope: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and Share

Microsoft Officially Assigns CVE to ShieldBreak Zero-Day as Patch Development Confirmed (CVE-2026-69414)

Scope: Microsoft Defender for Windows (All Versions on Windows 10, Windows 11, Windows Ser

Forminator Forms WordPress Plugin Critical RCE Flaw Affects 600,000 Active Installations (CVE-2026-15748)

Scope: Forminator Forms WordPress Plugin (All Versions Prior to Patched Release)

Zoom Workplace for Windows Critical Authentication Flaw Enables Unauthenticated Account Takeover (CVE-2026-53412)

Scope: Zoom Workplace for Windows Prior to Version 7.0.0 and Zoom Workplace VDI Client for

Subscribe to Advisories