Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands Source: The Hacker News SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-si Read original

July 15, 2026 Updated: October 10, 2026 1 min

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Source: BleepingComputer SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […] Read original

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Source: BleepingComputer SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […] Read original

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days Source: BleepingComputer Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. […] Read original

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days Source: BleepingComputer Today is Microsoft’s July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. […] Read original

Cursor 0day: When Full Disclosure Becomes the Only Protection Left

Cursor 0day: When Full Disclosure Becomes the Only Protection Left Source: Hacker News Points: 336 Discussion: Hacker News Comments Read original

July 14, 2026 Updated: October 10, 2026 1 min

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown Source: BleepingComputer Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. […] Read original

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown Source: BleepingComputer Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. […] Read original

CISA warns of actively exploited RCE flaws in Joomla extensions

CISA warns of actively exploited RCE flaws in Joomla extensions Source: BleepingComputer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. […] Read original

Hackers exploit critical auth bypass in Gitea Docker image

Hackers exploit critical auth bypass in Gitea Docker image Source: BleepingComputer Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. […] Read original