Cyber.TechVoid
Read latestCT
HomeLibraryCVEThreatsMalwareResearch

Following

Find topics and threat categories to follow

LatestBreakingVulnerabilitiesThreatsBreachesMalwareCVEResearch
See suggestions
Latest newsCVE trackerRSSllms.txt© 2026

Cyber.TechVoid

Know what happened in cybersecurity today. Source-driven cybersecurity coverage with attribution. Content may be AI-assisted from external feeds and advisories.

Sections

Latest cybersecurity newsData breach newsVulnerability updatesCVE trackerThreat intelligenceMalware watch

Feeds

RSSSitemapNews sitemapllms.txt

© 2026 Cyber.TechVoid. Accuracy over SEO.

CCISA AdvisoriesinVulnerability·Oct 7high

Critical Vulnerabilities Discovered in Johnson Controls EasyIO FG Firmware; Product Reaches End-of-Life

CISA and Johnson Controls have disclosed two vulnerabilities, CVE-2026-27872 and CVE-2026-27873, affecting EasyIO FG firmware versions 2.0b52 and below. The flaws stem from the use of hard-coded credentials and improper privilege management, which could allow an attacker to gain full unauthorized access to the device. Johnson Controls has confirmed that the EasyIO FG Series has reached End-of-Life (EOL) and End-of-Support (EOS) status; the product has not been manufactured or sold since prior to 2019, and the source code is no longer available, meaning no firmware patch will be issued. Users are strongly advised to migrate to supported current-generation products such as the EasyIO Neo R1 Series. In the absence of a patch, the vendor and CISA recommend deploying devices within isolated Building Automation System (BAS) / Operational Technology (OT) networks, ensuring no direct Internet exposure, enforcing strict VLAN segmentation, restricting remote login access, and implementing IP whitelisting and traffic blocking measures.

12m
  • Latest
  • Breaking
  • Vulnerabilities
  • Threats
  • Breaches
  • Malware
  • CVE
  • Research
TThe Hacker NewsinVulnerability·Oct 6high

Microsoft Exchange Server Flaw CVE-2026-96940 Allows Privilege Escalation

Microsoft has released out-of-band security updates to address CVE-2026-96940, a high-severity vulnerability in Microsoft Exchange Server rated 8.8 on the CVSS scale. The flaw involves weak authorization mechanisms that could allow an authenticated attacker to elevate privileges and access other users' mailboxes. Administrators are urged to apply the updates promptly.

21m
TThe Hacker NewsinVulnerability·Oct 5high

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The vulnerability, tracked as CVE-2026-73570, is an unauthenticated operating system command injection flaw with a CVSS score of 8.9 that can lead to remote code execution when exploited via the Simple Network Management Protocol (SNMP) vector.

21m
CCISA AdvisoriesinVulnerability·Oct 4critical

CISA Issues Advisory for Four Critical Vulnerabilities in Monta monta.app Charging Station Software

The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-274-02 disclosing four vulnerabilities in Monta monta.app, a widely used electric vehicle charging station management platform. The flaws span missing authentication, lack of rate limiting on WebSocket endpoints, predictable session identifiers, and insufficiently protected credentials. All versions of the software are affected. While no active exploitation has been confirmed, the CVSS scores range from 7.5 to 9.4, classifying three as Critical and one as High severity. The advisory urges operators to enable OCPP 1.6 Security Profile 2 and apply interim mitigations such as rate limiting.

22m
DDark readinginVulnerability·Oct 4info

Vulnerability Backlogs Rooted in Asset Ownership Gaps, Not Detection Shortfalls

A recent Dark Reading article argues that organizations struggling with vulnerability backlogs do not need enhanced scanning tools. Instead, the piece emphasizes that the core problem lies in identifying asset owners, establishing remediation authority, and planning remediation capacity. The analysis suggests that without clear ownership structures, even the best detection tools will produce unmanageable backlogs.

11m
TThe Hacker NewsinVulnerability·Oct 4critical

Dell Container Storage Modules Critical Flaws Enable Unauthenticated Admin Access to Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM). The most severe, tracked as CVE-2026-63688 with a CVSS score of 10.0, involves a missing authentication vulnerability in the csm-authorization-storage gRPC server. This flaw could allow unauthenticated attackers to gain admin access and root-level compromise on Kubernetes nodes running vulnerable Dell CSM versions. Additional flaws were also identified and patched in this release. Exploitation details remain under investigation, but the nature of the vulnerability suggests active risk for exposed deployments.

11m
BBleepingComputerinVulnerability·Oct 3high

Dell Patches Two Maximum Severity Vulnerabilities in Container Storage Modules

Dell has released security updates to patch two maximum severity vulnerabilities in the Container Storage Modules (CSM) component. The flaws affect Dell enterprise storage arrays connected to Kubernetes environments and could allow attackers with network access to achieve remote code execution and admin-level privileges. Patches have been released and admins are urged to apply them as soon as possible.

11m
BBleepingComputerinVulnerability·Oct 3critical

Kiteworks patches maximum severity code injection vulnerability in Email Protection Gateway

Kiteworks has released security updates to address 126 vulnerabilities, including a maximum severity code injection flaw affecting the Email Protection Gateway (EPG) security solution. The vulnerability could allow remote code execution on affected systems. Users are advised to apply the latest updates immediately.

11m
CCISA AdvisoriesinVulnerability·Oct 2medium

CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.

12m
CCISA AdvisoriesinVulnerability·Oct 2high

Critical Authorization Flaws Discovered in Meari IoT Cloud Platform OpenAPI Service

CISA has issued an industrial control systems advisory warning of two authorization vulnerabilities affecting the Meari IoT Cloud Platform OpenAPI Service. The flaws, tracked as CVE-2026-101104 and CVE-2026-96613, stem from missing authorization checks. CVE-2026-101104 allows authenticated users to manipulate configurations of devices they do not own, while CVE-2026-96613 allows access to the complete device shadow of any device by specifying its ID. Both vulnerabilities affect all product versions (vers:all/*). Notably, Meari has not planned a fix and did not respond to CISA's coordination attempts, leaving users without official remediation.

12m
CCISA AdvisoriesinVulnerability·Oct 2medium

CISA Issues Advisory for ABB PCM600 Privilege Escalation and Path Traversal Vulnerabilities

CISA has published advisory ICSA-26-274-03 detailing two vulnerabilities in ABB Protection and Control IED Manager PCM600. CVE-2026-15952 is a privilege escalation flaw in the Scheduler Service, and CVE-2026-15953 is a path traversal vulnerability in project archive processing. Both affect versions 2.14 and earlier. Exploitation of CVE-2026-15952 could allow a local attacker with valid credentials to elevate to LocalSystem. CVE-2026-15953 could allow writing files outside the intended extraction directory. ABB has not released a patched version beyond 2.14; mitigations are recommended.

12m
CCISA AdvisoriesinVulnerability·Oct 2medium

Johnson Controls EasyIO Neo Series Controllers Vulnerable to Cleartext Data Transmission

Johnson Controls has identified a vulnerability in EasyIO Neo Series EC and CW Controllers that allows cleartext transmission of sensitive information over the network. Exploitation could enable interception of credentials and session data. Fixed firmware versions are now available.

11m
BBleepingComputerinVulnerability·Oct 2high

TeamViewer Urges Immediate Patching of High-Severity Vulnerabilities

TeamViewer has warned customers to immediately patch a set of high-severity vulnerabilities affecting its remote access client and host software. The company stated that security updates have been released and should be applied as soon as possible to mitigate potential risks.

11m
CCISA AdvisoriesinVulnerability·Oct 1critical

Critical Vulnerabilities Affect Lantronix G520 Series Cellular Gateways

CISA has issued an industrial control systems advisory detailing two critical vulnerabilities in the Lantronix G520 Series Cellular Gateway. CVE-2026-84409 involves improper neutralization of input during web page generation (cross-site scripting) combined with a command execution interface, allowing attackers with metadata influence to execute arbitrary code with root privileges. CVE-2026-91191 stems from improper verification of cryptographic signatures and an exposed production private key, enabling unauthorized software packages to be accepted as authentic and executed with root privileges during boot. Both vulnerabilities affect firmware version 2.6.0.4R6_stable.

12m
TThe Hacker NewsinVulnerability·Sep 30high

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

21m
DDark readinginVulnerability·Sep 29high

One Packet Can Crash OT Servers in Industrial Sectors

A high-severity zero-day vulnerability in the TDengine time-series database allows a single malformed packet to crash OT servers, potentially disrupting industrial, IoT, energy, and automotive operations. Details regarding exploitation status and remediation remain limited.

11m
BBleepingComputerinVulnerability·Sep 28medium

Cloudflare Fixes Cross-Tenant Data Exposure Flaw in Workers Containers and Sandboxes

Cloudflare has addressed a cross-tenant vulnerability in its Workers Containers and Sandboxes service that could allow customers with a Paid account to recover residual data from other customers' containers on the same physical host. The issue was identified as a data residual risk rather than a remote code execution flaw. No confirmed active exploitation has been reported.

11m
TThe Hacker NewsinVulnerability·Sep 28high

Linux Kernel KVM ARM64 Vulnerability Exposes Host Memory to Guests

A use-after-free vulnerability in the Linux kernel's KVM subsystem for ARM64 processors has been disclosed as CVE-2026-89775. The flaw affects hosts with nested virtualization enabled, where a guest virtual machine can read and write to previously freed host kernel memory. The discovering researcher indicates this may facilitate guest-to-host code execution, though kernel maintainers have not independently verified exploitation claims at time of reporting.

11m
TThe Hacker NewsinVulnerability·Sep 28critical

MikroTrick: Chained MikroTik RouterOS SSH Vulnerabilities Enable Unauthenticated Router Takeover

Security researchers from CERT Polska have disclosed a chained vulnerability affecting MikroTik RouterOS SSH implementation. The exploit combines CVE-2026-67279, an SSH state-machine flaw, with CVE-2026-86060, an argument-injection bug in the login process. Successful chaining of these vulnerabilities allows attackers to gain full administrative control of Internet-exposed MikroTik routers without requiring a password, SSH key, or completing authentication. MikroTik has addressed the flaws in RouterOS version 7.0.4 and later.

12m
TThe Hacker NewsinVulnerability·Sep 28high

Microsoft SharePoint Server Flaw Reclassified: Authenticated Remote Code Execution Confirmed

A SharePoint Server vulnerability initially classified as a spoofing flaw with a CVSS score of 6.5 has been re-evaluated to enable authenticated remote code execution. Disclosed on September 22, 2026, the flaw affects SharePoint Server 2016, 2019, and Subscription Edition. Security researcher Dinh Ho Anh Khoa of Viettel Cyber Security published detailed technical analysis revealing that attackers with valid credentials can execute arbitrary code on affected systems. Microsoft has released patches; organizations are urged to apply updates immediately.

11m
BBleepingComputerinVulnerability·Sep 28critical

D-Link Warns of Maximum-Severity Zero-Day in Legacy DIR-822A Routers

D-Link has alerted users to a maximum-severity vulnerability in the DIR-822A dual-band Wi-Fi router. The flaw, tracked as CVE-2026-86296, has public proof-of-concept exploit code available but no patch has been released. The affected devices are end-of-life legacy hardware, and D-Link recommends replacing them due to the lack of a fix path.

11m
TThe Hacker NewsinVulnerability·Sep 27critical

Chinese Threat Actor Exploits Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor tracked as UTA0565 has been observed exploiting a chain of three zero-day vulnerabilities - two in Google Chrome and one in Microsoft Windows - to deploy CLEANGULP malware. The attacks, detected in early September 2026, targeted users visiting fake websites and leveraged the exploit chain to achieve remote code execution and malware deployment. Google and Microsoft are expected to release security updates to address the vulnerabilities CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880.

11m
TThe Hacker NewsinVulnerability·Sep 27high

Elementor Website Builder WordPress Plugin CSRF Vulnerability Disclosed

A cross-site request forgery (CSRF) vulnerability in the Elementor Website Builder WordPress plugin has been disclosed. The flaw, which carries a CVSS score of 8.8, could allow unauthenticated attackers to force an administrator to click a crafted link, resulting in the creation of a rogue administrator account and full site takeover. The vulnerability affects current versions of the plugin and remains without a CVE identifier. Exploitation requires administrator interaction, and no patch status has been specified in initial reports.

11m
BBleepingComputerinVulnerability·Sep 26high

Active Exploitation of Critical Roundcube Webmail Vulnerability Detected in the Wild

A high-severity vulnerability in Roundcube Webmail, patched in May 2026, is now being actively exploited in code injection attacks. The Canadian Centre for Cyber Security has issued warnings about attacks targeting unpatched Roundcube installations, potentially leading to unauthorized access and malicious payload execution.

11m