Cisco rates Unified CM SSRF flaw critical over root takeover risk
CVE-2026-20230 lets unauthenticated attackers abuse Unified CM's WebDialer to write files and escalate to root; the bug is now in CISA's KEV…
CVE-2026-20230 lets unauthenticated attackers abuse Unified CM's WebDialer to write files and escalate to root; the bug is now in CISA's KEV…
CVE-2026-10520 lets unauthenticated attackers gain root on Ivanti Standalone Sentry; researchers say exposed appliances are already being backdoored.
An unauthenticated file-upload flaw (CVE-2026-48908) in SP Page Builder is being exploited to run PHP web shells and create hidden Joomla Super…
Oracle’s July update patches five critical bugs — one reportedly exploited in PeopleSoft — while Adobe ships ColdFusion fixes for six CVSS…
Microsoft SharePoint Server has an actively exploited remote-code-execution flaw now on CISA’s must-patch list, with a July 4 federal patch deadline.