Posts

Fortinet Patches Released!

Image
  Fortinet announced fixes for eight vulnerabilities on August 12-13, 2026 . Key items for administrators FortiWeb CVE-2026-26035 (High): Improper authentication vulnerability that could allow an unauthenticated attacker to log in with arbitrary credentials when specific non-default wildcard admin settings are enabled. Fixed in: FortiWeb 8.0.3 FortiWeb 7.6.7 FortiWeb 7.4.12 FortiWeb 7.2.13 FortiManager CVE-2026-70468 (High): Authentication bypass that could allow an attacker to impersonate a managed FortiGate under specific conditions. FortiClient for Windows CVE-2026-70465 (High): Buffer overflow vulnerability that could allow remote code execution if an attacker can manipulate DNS responses. FortiOS Fortinet also addressed additional medium and low severity vulnerabilities in FortiOS as part of the advisory set. Recommended action Review exposed FortiWeb , FortiManager , and FortiClient Windows deployments first. Verify current firmware versions. Follow Fortinet's recommende...

WordPress RCE (Remote Code Execution) Update to 7.0.4!

Image
  A WordPress RCE (Remote Code Execution) vulnerability is a security flaw that allows an attacker to execute arbitrary code on the web server hosting a WordPress site. Successful exploitation can lead to full site compromise, malware installation, data theft, account creation, or complete server takeover. Recent WordPress RCE Examples 1. WP2Shell (CVE-2026-63030 + CVE-2026-60137) In July 2026, WordPress disclosed a critical attack chain dubbed WP2Shell . The chain combined a REST API flaw and a SQL injection vulnerability, allowing unauthenticated attackers to achieve remote code execution on affected WordPress Core installations. Active exploitation was later confirmed, and CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog. Affected versions: WordPress 6.9.0 through 6.9.4 WordPress 7.0.0 through 7.0.1 Fixed in: WordPress 6.9.5 WordPress 7.0.2 2. Imagick/Ghostscript RCE (CVE-2026-65640) In August 2026, WordPress released version 7.0.4 to address an au...

CVE-2026-59310 Critical Exploit VMware vCenter Server

Image
  CVE-2026-59310 is a critical VMware vCenter Server directory traversal vulnerability affecting the vCenter Syslog Server component. It has a CVSS score of 9.8 (Critical) . An attacker with network access to a vulnerable vCenter instance can exploit the flaw to achieve arbitrary code execution on the vCenter server. Key Details CVE: CVE-2026-59310 Severity: Critical (CVSS 9.8) Type: Directory Traversal (Path Traversal) Affected Component: VMware vCenter Syslog Server Impact: Remote Code Execution (RCE) Attack Prerequisites: Network access to the vulnerable vCenter service Authentication Required: No authentication required according to Broadcom's advisory and industry reporting. Affected Products Broadcom lists the following as affected: VMware vCenter VMware Cloud Foundation VMware vSphere Foundation VMware Telco Cloud Platform VMware Telco Cloud Infrastructure Fixed Versions Broadcom released patches in: vCenter 9.1.x → fixed in 9.1.0.0300 vCenter 9.0.x → fixed in ...