Announcements

CVE-2026-78477 (matched: wordpress)

  • 25th August 2026
A security flaw has been identified in the Jawn theme for WordPress, a popular tool used to customize the design and features of WordPress websites. Every version of this theme up to and including version 1.4.2 is impacted by the vulnerability.This issue allows people who do not have any existing login credentials for your WordPress site to gain ...
Continue reading

CVE-2026-78003 (matched: wordpress)

  • 25th August 2026
A security flaw tracked as CVE-2026-78003 has been found in the Mailgun for WordPress plugin, affecting all versions up to and including 2.2.0. The issue exists because the plugin does not properly validate user-submitted data when processing address lists, creating an opening for attackers.Unauthenticated attackers can exploit this gap to send ...
Continue reading

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

  • 25th August 2026
A security vulnerability has been found in the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. The flaw is an access control issue, meaning these tools do not properly restrict who can access or interact with the data they handle.If exploited, this vulnerability could allow unauthorized parties to create, modify, or delete ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 25th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT released security advisory MA-1471.072026 related to Microsoft SharePoint, a platform many organizations use to share files, manage team projects, and store internal work resources. The advisory provides hardening (security configuration) guidance for SharePoint, and was issued ...
Continue reading