Skip to main content

Adobe Commerce and Magento Unauthenticated Customer Account Hijacking Now Under Active Exploitation (CVE-2026-71362)

Scope: Adobe Commerce and Magento Open Source (All Supported Versions Prior to August 2026

CISA Orders Emergency Patching of Four Critical Flaws Including Microsoft IKE, SharePoint, VMware, and macOS by August 21 (CVE-2026-33824 and Others)

Scope: Microsoft IKE Service Extensions, Microsoft SharePoint Server, VMware vCenter, Appl

Microsoft SharePoint Complete Unauthenticated RCE Chain Now Fully Patched Across Two Patch Tuesdays (CVE-2026-55040 / CVE-2026-63520)

Scope: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and Share

Microsoft Officially Assigns CVE to ShieldBreak Zero-Day as Patch Development Confirmed (CVE-2026-69414)

Scope: Microsoft Defender for Windows (All Versions on Windows 10, Windows 11, Windows Ser

Forminator Forms WordPress Plugin Critical RCE Flaw Affects 600,000 Active Installations (CVE-2026-15748)

Scope: Forminator Forms WordPress Plugin (All Versions Prior to Patched Release)

Zoom Workplace for Windows Critical Authentication Flaw Enables Unauthenticated Account Takeover (CVE-2026-53412)

Scope: Zoom Workplace for Windows Prior to Version 7.0.0 and Zoom Workplace VDI Client for

GitLab CE and EE Emergency Out-of-Band Patch Addresses Critical Unauthenticated Data Deletion Flaw (CVE-2026-19478)

Scope: GitLab Community Edition and Enterprise Edition Self-Managed Installations Versions

Subscribe to Advisories