● On the wire
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability//CRLF-Powered Desync Attacks: Beheading HTTP Streams//Debian openjdk-21 Important Cert Issues DoS Risk DSA-6425-1//Debian dnsdist High Severity DoS CVE-2026-52682 DSA-6419-1//Debian libde265 Major Exec Threat Memory Exhaustion DoS Notice DSA-6413-1//Debian DSA-6421-1 pdns-recursor Denial of Service CVE-2026-52682//Cisco IOS XE Software Security Hardening Release: August 2026//When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers//Debian Caddy Important Access Control Breaches DSA-6429-1 CVE-2026-27585//What the Recent Water Systems Cyber Attacks Reveal About Critical Infrastructure Security//Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)//Debian Thunderbird Significant Code Execution Vulnerabilities DSA-6418-1//Debian pdns Critical DoS Issue CVE-2026-52682 Fixed in DSA-6420-1//ClamAV Vulnerabilities Affecting Cisco Products: August 2026//Ubuntu ImageMagick Heap Overflow and Code Execution Security Flaws//Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability//CRLF-Powered Desync Attacks: Beheading HTTP Streams//Debian openjdk-21 Important Cert Issues DoS Risk DSA-6425-1//Debian dnsdist High Severity DoS CVE-2026-52682 DSA-6419-1//Debian libde265 Major Exec Threat Memory Exhaustion DoS Notice DSA-6413-1//Debian DSA-6421-1 pdns-recursor Denial of Service CVE-2026-52682//Cisco IOS XE Software Security Hardening Release: August 2026//When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers//Debian Caddy Important Access Control Breaches DSA-6429-1 CVE-2026-27585//What the Recent Water Systems Cyber Attacks Reveal About Critical Infrastructure Security//Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)//Debian Thunderbird Significant Code Execution Vulnerabilities DSA-6418-1//Debian pdns Critical DoS Issue CVE-2026-52682 Fixed in DSA-6420-1//ClamAV Vulnerabilities Affecting Cisco Products: August 2026//Ubuntu ImageMagick Heap Overflow and Code Execution Security Flaws//
Check Point SmartConsole: bypass di autenticazione attivamente sfruttato
Top story — News

Check Point SmartConsole: authentication bypass actively exploited

Check Point has fixed a critical vulnerability in the SmartConsole login process, tracked as CVE-2026-16232, which allows an unauthenticated attacker to obtain an application token and gain access with full administrative privileges. Reports indicate that the bug is already being exploited in the wild, although the direct impact currently concerns only a limited number of customers. The flaw affects Security…

Read the article →
From the newsroom
Spotlight
More news