Announcements

CVE-2026-16610 (matched: wordpress)

  • 30th July 2026
A critical security flaw has been identified in the ASE Pro (Admin and Site Enhancements) plugin for WordPress, affecting all versions up to and including 8.9.0. This vulnerability lets unauthenticated third parties run arbitrary code directly on your website's server, which can give attackers full control of your site, access to sensitive visitor ...
Continue reading

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 30th July 2026
A security flaw has been identified in the Arista VeloCloud Orchestrator On-Prem, a system some users rely on to manage cloud and network resources. This is an operating system command injection vulnerability, which means a remote attacker could send unauthorized commands to the system to run restricted, privileged operations it is not supposed to ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 30th July 2026
A security flaw has been identified in Fortinet FortiOS, a network security operating system commonly used to manage access and protection for servers and websites. This flaw could allow unauthorized actors to access sensitive information stored on affected systems.To exploit this issue, an attacker would first need to have already gained ...
Continue reading

Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

  • 30th July 2026
A security flaw has been identified in Cisco Secure Firewall Management Center, a tool used to manage Cisco firewall security systems that was previously called Firepower Management Center. The vulnerability stems from a hard-coded password, a password permanently embedded in the system that cannot be adjusted or removed by users.This issue could ...
Continue reading