remote code execution

オランダのNCSC:チェック・ポイント社のVPNに存在する重大な脆弱性の悪用が差し迫っている News

オランダのNCSC:チェック・ポイント社のVPNに存在する重大な脆弱性の悪用が差し迫っている

オランダの国家サイバーセキュリティセンター(NCSC)は、Check Point VPNの2つの重大な脆弱性(CVE-2026-85102およびCVE-2026-85103として追跡されている)が、まもなく悪用される恐れがあるとして警告を発...
CISA:WatchGuardのRCE脆弱性が、現在ランサムウェア攻撃で悪用されている News

CISA:WatchGuardのRCE脆弱性が、現在ランサムウェア攻撃で悪用されている

米国サイバーセキュリティ・インフラセキュリティ庁(CISA)は、ランサムウェア集団がWatchGuard Fireboxファイアウォールの重大な脆弱性も悪用していることを確認した。同庁は12月、この脆弱性が積極的に悪用されていると警告してい...
ハッカーがF5 BIG-IP APMデバイスに侵入し、Linux用ルートキットを配布 News

ハッカーがF5 BIG-IP APMデバイスに侵入し、Linux用ルートキットを配布

F5 BIG-IP APM 環境内のデバイスを標的とする Linux ルートキットは、PHP ファイルの読み込みを傍受し、ファイルレスな Web シェルをメモリに直接注入することができ、悪意のあるコードをディスクに書き込む必要がありません。...
アドビ、サーバーへのバックドア侵入に悪用されていたMagentoの重大なゼロデイ脆弱性を修正 News

アドビ、サーバーへのバックドア侵入に悪用されていたMagentoの重大なゼロデイ脆弱性を修正

アドビは、MagentoおよびAdobe Commerceの複数のバージョンに影響を及ぼし、「StyleSmuggler」と呼ばれる、現在積極的に悪用されている最大深刻度のゼロデイ脆弱性「CVE-2026-75650」に対する緊急修正プログ...
N-ableのパッチは、現在も続く攻撃の中で、最大深刻度Nの中心的な脆弱性を修正 News

N-ableのパッチは、現在も続く攻撃の中で、最大深刻度Nの中心的な脆弱性を修正

N-able社は、同社のリモート監視・管理(RMM)プラットフォーム「N-central」に影響を及ぼす、最大深刻度のリモートコード実行(RCE)の脆弱性に対する緊急ホットフィックスをリリースしました。 IT部門やマネージドサービスプロバイ...
HPE patches critical ArubaOS-CX remote code execution flaw News

HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that co...
Critical Elementor Pro flaw exploited to take over WordPress sites News

Critical Elementor Pro flaw exploited to take over WordPress sites

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited ...
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells News

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox...
WordPress backup plugin flaw exposes millions of sites to takeover attacks News

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticate...
SonicWall warns of actively exploited SMA1000 zero-day flaws News

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execu...