Announcements

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 22nd July 2026
A SQL injection security flaw exists in WordPress core. This vulnerability is triggered when a plugin or theme you have installed passes untrusted, unvetted input to a specific site parameter. This flaw can be chained with the separate known vulnerability CVE-2026-63030 to allow attackers with no login access to your site to run their own code on ...
Continue reading

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 22nd July 2026
We’re sharing a security notice related to Microsoft SharePoint, a common platform many organizations use for document management, team collaboration, and internal content hosting. The service has a known flaw where it improperly processes untrusted, unvetted data sent to it. If a bad actor successfully exploits this flaw, they can run ...
Continue reading

Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in Check Point SmartConsole, a tool used to manage network security systems for websites and online services.This is an improper authentication flaw. It allows an unauthenticated remote attacker to obtain a valid login token for the SmartConsole application, which they can then use to access the tool ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 22nd July 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT issued a security advisory for Microsoft SharePoint, following reports of new active exploitation attempts targeting the platform. SharePoint is a common tool used by organizations to host websites, share internal files, and manage collaborative work content. These newly observed ...
Continue reading