Tuesday 28 July 2026 12:34:54 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#active exploitation


SharePoint’s Silent Trap: Why a KEV Listing Turns One Bug Into an Emergency

Published: 02 July 2026 12:24Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CISA’s addition of CVE-2026-45659 to its exploited-vulnerability catalog puts Microsoft SharePoint Server operators on a short clock, with deserialization risk now treated as an active threat rather than a routine patch item.

Oracle EBS Exposure Turns a Critical Payments Bug into a Perimeter Problem

Published: 02 July 2026 06:16Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Multiple internet-reachable E-Business Suite instances are drawing scrutiny as a critical Oracle Payments flaw is described as actively exploited.

PTC PLM Systems Under Active Fire as CVE-2026-12569 Moves Into Exploitation

Published: 30 June 2026 18:56Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A patched flaw in Windchill PDMLink and FlexPLM is being actively abused in the wild, turning a product-data platform into an urgent patch-and-hunt problem.

Oracle E-Business Suite’s Payments Layer Draws Fire as Attackers Move In Fast

Published: 30 June 2026 14:31Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A recent critical flaw in Oracle E-Business Suite has crossed from disclosure into active exploitation, putting payment workflows in the crosshairs of opportunistic attackers.

SimpleHelp’s Control Panel Became the Target: A Tiny Flaw, a Big Malware Path

Published: 30 June 2026 12:32Category: Vulnerabilities & Patch ManagementGeo: Europe / United KingdomAuthor: NEONPALADIN

A critical weakness in remote-support software shows how one privileged login path can become a launch point for malware, secret theft, and broader endpoint risk.

Oracle EBS Payment Path Turns Into a Live Target

Published: 29 June 2026 16:21Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical Oracle E-Business Suite flaw tied to payment processing has moved into the exploitation phase, turning patch urgency into an operational risk for exposed enterprise systems.

SP Page Builder flaw hits the radar as Joomla admins race to close a dangerous gap

Published: 26 June 2026 13:09Category: Vulnerabilities & Patch ManagementGeo: Asia / BangladeshAuthor: DEEPAUDIT

A patched vulnerability in a Joomla page builder is now being seen in active attacks, turning routine extension management into an urgent security problem.

UniFi OS Lands on CISA’s Hit List as Patch Pressure Turns Urgent

Published: 24 June 2026 08:06Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

Multiple UniFi OS vulnerabilities have been placed in the federal exploit-tracking catalog, putting Ubiquiti administrators on an accelerated remediation clock.

Splunk’s Hidden Helper Became the Urgent Patch Nobody Wanted

Published: 19 June 2026 14:30Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical Splunk Enterprise flaw under active exploitation shows how a small management component can turn into an outsized risk when it is reachable, unpatched, or trusted too much.

When a Sidecar Becomes a Door: Splunk’s Critical Bug Draws Active Exploitation Alerts

Published: 19 June 2026 12:38Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A missing-authentication flaw in a PostgreSQL sidecar path has pushed CVE-2026-20253 into urgent territory, showing how quiet helper services can become high-value targets.

When a Joomla Plugin Becomes a Break-In Point

Published: 17 June 2026 17:59Category: Vulnerabilities & Patch ManagementAuthor: DEEPAUDIT

CISA’s deadline on the JCE flaw reflects a familiar emergency in web security: a small extension feature can turn into a pre-auth path to remote code execution.

The PeopleSoft Trapdoor: Why a Missing Login Check Became a High-Value Target

Published: 17 June 2026 10:20Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A critical PeopleTools authentication failure turned a trusted enterprise management layer into a possible takeover path, with defenders warned to treat exposed systems as urgent patch-and-contain cases.

FortiSandbox Under Pressure as New Attack Paths Draw Fire

Published: 16 June 2026 19:43Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Multiple newly disclosed Fortinet appliance flaws have reportedly been targeted in active attempts, putting a trusted malware-analysis layer in the crosshairs.

FortiSandbox Becomes the Target, and the Clock Is Already Ticking

Published: 16 June 2026 15:07Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Three Fortinet FortiSandbox flaws were said to be under active exploitation within a 24-hour window, turning a security appliance into the newest race between disclosure and patching.

FortiSandbox Under Fire: When the Security Box Becomes the Weak Link

Published: 16 June 2026 12:22Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Active exploitation claims around Fortinet’s FortiSandbox show why privileged inspection systems can become attractive targets, even when their job is to catch malicious code.

When a “Medium” Bug Sits on the SD-WAN Console, the Risk Can Multiply Fast

Published: 16 June 2026 10:32Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Cisco’s fix for CVE-2026-20262 shows why an authenticated file-write flaw in a central management system deserves close attention, especially when active exploitation is already in play.

Jenkins Flaw Turns Routine Config Changes into a High-Risk Attack Path

Published: 15 June 2026 18:41Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

A critical deserialization bug in Jenkins places controller-side XML handling under scrutiny, with reported live attack attempts raising the stakes for exposed installations.

When a Content Plugin Becomes a Server Risk

Published: 15 June 2026 16:14Category: Vulnerabilities & Patch ManagementAuthor: DEEPAUDIT

A Joomla editor extension has entered active exploitation, showing how an ordinary admin tool can become a path to remote code execution when access control slips.

Trust Broken: How a VPN Cookie Shortcut Became a GlobalProtect Bypass

Published: 15 June 2026 12:41Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

CVE-2026-0257 turns a remote-access convenience feature into a high-risk entry point, showing how trust tokens can become the weak link in edge security.

When the VPN Front Door Becomes the Weak Link

Published: 15 June 2026 10:29Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A PAN-OS authentication-bypass flaw in GlobalProtect shows how a single edge service can turn remote access into an urgent defensive problem.