Announcements

CVE-2026-4703 (matched: wordpress)

  • 24th August 2026
A security flaw has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, a popular tool for adding custom contact forms to websites without coding experience. The flaw impacts all versions of the plugin up to 1.10.80, and allows unauthenticated attackers (people who do not have access to your site’s admin area) ...
Continue reading

CVE-2026-78003 (matched: wordpress)

  • 24th August 2026
A security vulnerability has been identified in the Mailgun for WordPress plugin, impacting all versions up to and including 2.2.0. This flaw lets outside attackers trick your WordPress site into sending unauthorized requests to Mailgun's services using your site's own stored Mailgun account credentials, without needing to log into your WordPress ...
Continue reading

Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  • 24th August 2026
A security vulnerability has been identified in Zimbra Collaboration Suite (ZCS), a popular platform used for email, shared calendars, and team collaboration tools that many businesses rely on for their operations.The flaw is an operating system command injection issue. It allows an unauthenticated attacker (someone who does not need a valid ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 24th August 2026
A cybersecurity advisory has been released alerting Microsoft SharePoint users to newly reported active exploits targeting the platform. The advisory recommends implementing security hardening measures for SharePoint deployments to reduce the risk of unauthorized access or service disruption. If you use SharePoint for team sites, document storage, ...
Continue reading