Critical Adobe Campaign Classic Flaw Found
A critical template engine vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution with a maximum CVSS score of 10.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A critical template engine vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution with a maximum CVSS score of 10.
A critical vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without requiring user interaction.
A severe RCE vulnerability in GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands.
Apple has filed a formal challenge against a U.K. government directive seeking access to encrypted iCloud user data.
A missing authentication vulnerability in Krayin CRM version 2.2.4 allows remote attackers to hijack the administrator account and gain full system access.
A critical remote code execution vulnerability in OpenEMR allows authenticated administrators to run arbitrary OS commands via the document category tree.
Expert consensus indicates that foundational cybersecurity hygiene remains the most effective defense against AI-driven threats.
A severe vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to execute arbitrary SQL commands.
A critical vulnerability in SiYuan software allows unauthorized database manipulation via the searchDocs API endpoint.
A critical stack-based buffer overflow in the Wavlink WL-NU516U1 allows remote attackers to execute arbitrary code via a manipulated CONTENT_LENGTH header.
Google's upcoming update aims to stop malware from using enterprise policy keys to seize control of user browser settings.
SecurityA critical flaw in the Active Storage framework allows for unauthorized file access and potential remote code execution.
A heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows remote attackers to execute code via malicious clipboard operations.
A severe vulnerability in FreeRDP allows attackers to inject arbitrary headers into HTTP proxy requests via malicious redirection.
Threat actors are hijacking hotel network gateways to push fraudulent software updates and capture user credentials via deceptive portals.
Anthropic reports three incidents where AI models accessed production infrastructure during unauthorized cybersecurity testing.
Security concerns over hijacked packages have forced a temporary freeze on adopting AUR contributions to protect the ecosystem.
A critical deserialization vulnerability in ComfyUI allows unauthenticated attackers to execute arbitrary code on affected systems.
A severe vulnerability in Apostrophe allows authenticated users to bypass authorization globally, affecting all REST API endpoints for the entire process.
Researchers are tracking a sophisticated campaign against Central Asian governments involving custom OctLurk and SilkLurk malware.