Announcements

CVE-2026-13439 (matched: wordpress)

  • 21st July 2026
The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, and including, 4.0.11 This is due to the password recovery flow using the publicly-visible session identifier ('sid') as the password reset token stored in wp_emsfb_temp_links, combined with a ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st July 2026
On July 20, 2026, cybersecurity authority MyCERT published a new security advisory focused on Microsoft SharePoint. The advisory was released following confirmed reports of new active exploitation attempts targeting the SharePoint platform. If your hosted services include Microsoft SharePoint deployments for team collaboration, document ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 21st July 2026
On 20 July 2026, cybersecurity agency MyCERT released a security advisory focused on Microsoft SharePoint, a popular platform many businesses use to host internal team sites, shared document storage, and collaborative workspaces. The advisory was issued following reports of new exploitation methods targeting the platform.The advisory outlines ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 20th July 2026
A MyCERT security advisory was published on 20 July 2026 focused on Microsoft SharePoint, a common tool many businesses use for team collaboration, document sharing, and internal site management. The advisory was released in response to new active attempts by bad actors to exploit security gaps in the SharePoint platform, which could lead to ...
Continue reading