Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. [...]
A vulnerability classified as very critical has been found in Cilium up to 1.17.13/1.18.7/1.19.1. The affected element is an unknown function of the file admin.sock of the component Admin Endpoints. The manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-49445. The attack can only be performed from a local environment. No exploit is available.
A vulnerability described as problematic has been identified in Absolute Security Secure Access up to 14.54. Impacted is an unknown function of the component Certificate Parsing. Executing a manipulation can lead to heap-based buffer overflow.
The identification of this vulnerability is CVE-2026-40953. The attack can only be executed locally. There is no exploit available.
A vulnerability marked as problematic has been reported in Absolute Security Secure Access up to 14.54. This issue affects some unknown processing of the component Installer. Performing a manipulation results in improper authentication.
This vulnerability was named CVE-2026-40952. The attack needs to be approached locally. There is no available exploit.
A vulnerability labeled as critical has been found in DataEase up to 2.10.22. This vulnerability affects the function doFilter of the component Token Handler. Such manipulation of the argument X-DE-TOKEN leads to improper verification of cryptographic signature.
This vulnerability is uniquely identified as CVE-2026-46684. The attack can be launched remotely. No exploit exists.
A vulnerability identified as critical has been detected in DataEase up to 2.10.22. This affects the function SqlparserUtils.handleVariableDefaultValue of the component Data Visualization. This manipulation causes sql injection.
This vulnerability is handled as CVE-2026-45535. The attack can be initiated remotely. There is not any exploit available.
A vulnerability categorized as critical has been discovered in DataEase up to 2.10.22. Affected by this issue is the function delete of the component Export Center Cleanup. The manipulation results in path traversal.
This vulnerability is known as CVE-2026-45533. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in DataEase up to 2.10.22. It has been rated as critical. Affected by this vulnerability is the function Save of the file /de2api/templateManage/save of the component Template Manage. The manipulation of the argument staticResource name leads to path traversal.
This vulnerability is traded as CVE-2026-45419. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in DataEase up to 2.10.22. It has been declared as problematic. Affected is the function SqlparserUtils.transFilter of the component DataEase dashboard. Executing a manipulation of the argument deptId can lead to injection.
This vulnerability appears as CVE-2026-45320. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in DataEase up to 2.10.22. It has been classified as critical. This impacts the function connect of the file rsjdbc.ini of the component Redshift Datasource Connection Handler. Performing a manipulation results in deserialization.
This vulnerability is reported as CVE-2026-45534. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in DataEase up to 2.10.22 and classified as critical. This affects the function checkStatus of the file CalciteProvider of the component Datasource Connection Status Check. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-45417. The attack can be executed remotely. There is not any exploit available.
The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, prioritize and patch cybersecurity vulnerabilities, officials said.
A vulnerability has been found in taosdata TDengine up to 3.4.1.14 and classified as problematic. The impacted element is the function mndProcessKillSsMigrateReq of the component Shared-Storage Migration. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2026-62348. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as very critical, was found in taosdata TDengine up to 3.4.1.14. The affected element is an unknown function of the component UDF Management. The manipulation results in permission issues.
This vulnerability is cataloged as CVE-2026-62355. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in taosdata TDengine 3.4.1.5/3.4.1.6/3.4.1.14. Impacted is the function transDecompressMsg of the file source/libs/transport/src/transComm.c of the component Transport. The manipulation of the argument comp leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-62351. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as critical was found in cap-js cap-js and cds-dbs 2.2.2/2.2.2/2.10.1. This issue affects some unknown processing of the component Database Service. Executing a manipulation can lead to sql injection.
This vulnerability is tracked as CVE-2026-46421. The attack can be launched remotely. No exploit exists.
A vulnerability classified as critical has been found in taosdata TDengine up to 3.4.1.14. This vulnerability affects the function eval. Performing a manipulation results in unrestricted upload.
This vulnerability is identified as CVE-2026-62350. The attack can be initiated remotely. There is not any exploit available.
A vulnerability described as critical has been identified in taosdata TDengine up to 3.4.1.13. This affects the function tGetToken of the file source/libs/parser/src/parTokenizer.c of the component SQL Parser. Such manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-62353. It is possible to launch the attack remotely. No exploit is available.