Aggregator
CVE-2017-5489 | WordPress 4.7.0 Flash File Upload cross-site request forgery (Nessus ID 96606 / ID 175955)
CVE-2017-5490 | WordPress up to 4.7.0 class-wp-theme.php cross site scripting (EDB-40968 / Nessus ID 96606)
CVE-2017-5491 | WordPress up to 4.7.0 wp-mail.php 7pk security (EDB-40968 / Nessus ID 96606)
Microsoft’s agentic security system found four critical Windows RCE flaws
Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) vulnerabilities. MDASH architecture diagram (Source: Microsoft) Two of the four flaws — CVE-2026-40361 and CVE-2026-40364 — were deemed by Microsoft to be more likely to be exploited. The multi-model agentic scanning harness, codenamed MDASH, was built by Microsoft’s Autonomous … More →
The post Microsoft’s agentic security system found four critical Windows RCE flaws appeared first on Help Net Security.
CVE-2026-40368 | Microsoft SharePoint Server 2.0/16.0.5548.1003 deserialization (Nessus ID 314345)
CVE-2026-40357 | Microsoft SharePoint Server 2.0/16.0.5548.1003 deserialization (Nessus ID 314345)
CVE-2026-40365 | Microsoft SharePoint Enterprise Server prior 16.0.5552.1002 insufficient granularity of access control (Nessus ID 314345)
CVE-2022-50943 | Moodle LMS 4.0 Parameter course/search.php Search cross site scripting (Exploit 51115 / EDB-51115)
CVE-2026-8258 | Squirrel up to 3.2 sqstdlib/sqstdstring.cpp validate_format stack-based overflow (Issue 325 / CNNVD-202605-2395)
CVE-2026-8259 | Tenda AC6 2.0/15.03.06.23 httpd /goform/telnet lan.ip os command injection (EUVD-2026-29015 / CNNVD-202605-2394)
Critical SandboxJS Escape Vulnerability Enables Host Takeover
A critical security flaw has been found in SandboxJS, a widely used JavaScript sandboxing library available on npm. The vulnerability allows attackers to break out of the sandbox entirely and run any code they want directly on the host system. Tracked as CVE-2026-43898, it carries a maximum severity score of 10.0, which is as serious […]
The post Critical SandboxJS Escape Vulnerability Enables Host Takeover appeared first on Cyber Security News.