Check Point's Fifth Critical Flaw Since July
A new 9.8-severity stack overflow lets unauthenticated attackers hit Security Management Servers as root, and it's not the first this summer.
26 results for “servers”
A new 9.8-severity stack overflow lets unauthenticated attackers hit Security Management Servers as root, and it's not the first this summer.
cPanel warns a LiteSpeed Web Server Enterprise bug could let one hosting account gain root on shared servers, with no CVE assigned.
Unpatched flaw lets attackers plant persistent backdoors on Magento and Adobe Commerce servers without login.
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
Reco report: 80% of AI tools lack IT oversight; MCP servers and rising vulnerabilities amplify risk.
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets, ASSET reports.
LexisNexis took Diligence, Metabase API, and Newsdesk offline after detecting unusual activity on third-party servers.
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
New research reveals widespread security flaws in baseboard management controllers across major global server manufacturers.
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
Researchers have identified a threat actor using the DeepSeek AI model to automate the lifecycle of cyberattacks on exposed servers.
A missing authentication vulnerability in Spikster allows unauthenticated attackers to remotely access API routes and perform administrative actions.
A legacy vulnerability in IPMI 2.0 leaves over 24,000 servers vulnerable to offline password cracking and potential remote control.
A critical pre-authentication vulnerability allows attackers to execute arbitrary code on unpatched OpenAM instances.
A severe vulnerability in the node-tar library allows attackers to crash servers and exhaust storage through maliciously crafted archive files.
New architectural approaches to age verification aim to satisfy global mandates while keeping biometric data off centralized servers.
Copyright enforcement by adult content creators is inadvertently neutralizing infrastructure vulnerabilities across the public sector.
A hard-coded JWT secret in self-hosted clawvet API servers allows remote attackers to bypass authentication and harvest sensitive data.
Federal agencies must secure SharePoint servers against active exploitation of three critical remote code execution vulnerabilities.
A widely used extension for developers and testers was found harboring spyware that sent user traffic data to remote servers.
Authorities seized 800 servers in a probe targeting individuals accused of facilitating cyberattacks through sanctioned networks.
As Progress Software forces ShareFile servers offline, a sudden threat exposes the vulnerabilities inherent in hybrid storage systems.