Sunday 19 July 2026 18:32:34 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#active exploitation


Two FortiSandbox Bugs Turn a Defensive Tool Into an Attack Surface

Published: 17 July 2026 12:33Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

CISA’s KEV listing of two Fortinet flaws shows how a security appliance can become a remote-command foothold when command input is not properly controlled.

FortiSandbox in the Hot Seat: When a Defender Becomes a Command Path

Published: 17 July 2026 12:16Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Two exploited command-injection flaws put Fortinet’s sandbox appliance in the uncomfortable role of attack surface, not inspection shield.

Oracle’s Payment Path Becomes the New Front Door for Attackers

Published: 17 July 2026 02:03Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical Oracle E-Business Suite flaw tied to Oracle Payments is being treated as an urgent patching problem because exploitation is already underway.

Edge Devices Under Siege: SonicWall SMA1000 Turns a Login Box Into a High-Risk Command Surface

Published: 16 July 2026 17:14Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Two newly disclosed zero-days in the SMA1000 line combine SSRF and code injection into a chain that can lead to root-level command execution, pushing defenders toward forensic triage, not just patching.

Oracle Payments Flaw Lands in KEV as Defenders Race the Patch Clock

Published: 16 July 2026 12:08Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

CISA’s addition of CVE-2026-46817 turns an Oracle E-Business Suite Payments issue into an urgent remediation problem, not a routine maintenance item.

Firefox Zero-Days Turn the Browser Into the Weakest Link

Published: 14 July 2026 18:06Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Mozilla has pushed security updates for two critical Firefox flaws that are reportedly being exploited online, putting patch speed and endpoint visibility at the center of defense.

Two Joomla Add-ons, One Old Web Trap: File Uploads That Can Cross Into Code Execution

Published: 13 July 2026 18:09Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

Active exploitation against iCagenda and Balbooa Forms shows how a routine upload feature can become a dangerous server-side trust boundary when controls are too loose.

Two Joomla Upload Bugs Just Moved Onto CISA’s Active-Exploit List

Published: 13 July 2026 12:28Category: Vulnerabilities & Patch ManagementAuthor: SECURESPECTER

File-upload flaws in iCagenda and Balbooa Forms show how a routine form feature can become a serious server-side risk when untrusted files are handled too loosely.

ColdFusion Under the Clock: Why a Federal Patch Order Signals More Than Routine Maintenance

Published: 08 July 2026 10:35Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A maximum-severity Adobe ColdFusion flaw has moved into emergency patch territory, showing how quickly an internet-facing server bug can become a compliance and exposure problem.

ColdFusion’s 10/10 Warning: Why a Patched Bug Can Still Become an Active Breach Path

Published: 07 July 2026 16:50Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A critical Adobe ColdFusion flaw is drawing attacker interest because the real danger is not only severity, but whether exposed servers were patched before exploitation began.

When a Click-to-Dial Shortcut Becomes an Attack Path

Published: 02 July 2026 14:36Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A Cisco Unified CM flaw tied to WebDialer shows how a small, enabled feature can turn a communications platform into a live target once a public exploit appears.

CISA Flags a SharePoint RCE as Active Exploitation Pushes Past Patch Day

Published: 02 July 2026 14:34Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A May Microsoft fix has already become a live defensive problem, with public vulnerability records pointing to a high-severity SharePoint server flaw now under attack.

SharePoint Flaw Lands in CISA’s Crosshairs as Active Exploitation Raises the Stakes

Published: 02 July 2026 14:17Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A new KEV entry for a Microsoft SharePoint Server vulnerability shifts the issue from routine patching to urgent exposure control for on-prem defenders.

Cisco’s Early-June Fix Is Now in the Wild - and Unified CM Admins Need to Move Fast

Published: 02 July 2026 14:07Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Cisco has confirmed active exploitation of a Unified Communications Manager flaw patched in early June, turning a routine update into an urgent inventory and patching problem for enterprise voice teams.

SharePoint’s Silent Trap: Why a KEV Listing Turns One Bug Into an Emergency

Published: 02 July 2026 12:24Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CISA’s addition of CVE-2026-45659 to its exploited-vulnerability catalog puts Microsoft SharePoint Server operators on a short clock, with deserialization risk now treated as an active threat rather than a routine patch item.

Oracle EBS Exposure Turns a Critical Payments Bug into a Perimeter Problem

Published: 02 July 2026 06:16Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Multiple internet-reachable E-Business Suite instances are drawing scrutiny as a critical Oracle Payments flaw is described as actively exploited.

PTC PLM Systems Under Active Fire as CVE-2026-12569 Moves Into Exploitation

Published: 30 June 2026 18:56Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A patched flaw in Windchill PDMLink and FlexPLM is being actively abused in the wild, turning a product-data platform into an urgent patch-and-hunt problem.

Oracle E-Business Suite’s Payments Layer Draws Fire as Attackers Move In Fast

Published: 30 June 2026 14:31Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A recent critical flaw in Oracle E-Business Suite has crossed from disclosure into active exploitation, putting payment workflows in the crosshairs of opportunistic attackers.

SimpleHelp’s Control Panel Became the Target: A Tiny Flaw, a Big Malware Path

Published: 30 June 2026 12:32Category: Vulnerabilities & Patch ManagementGeo: Europe / United KingdomAuthor: NEONPALADIN

A critical weakness in remote-support software shows how one privileged login path can become a launch point for malware, secret theft, and broader endpoint risk.

Oracle EBS Payment Path Turns Into a Live Target

Published: 29 June 2026 16:21Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical Oracle E-Business Suite flaw tied to payment processing has moved into the exploitation phase, turning patch urgency into an operational risk for exposed enterprise systems.