Announcements

CVE-2026-14484 (matched: wordpress)

  • 16th August 2026
A security flaw has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, which impacts all versions up to and including 1.0.4. This flaw allows anyone who does not have login access to your website to delete any files stored on your site's server.If an attacker deletes a critical core WordPress ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 16th August 2026
MyCERT released a security advisory on July 20, 2026, focused on Microsoft SharePoint, a popular tool for team collaboration, document management, and internal business workflows. The notice cites newly reported exploitation activity targeting the SharePoint platform. If you run Microsoft SharePoint sites or services on your hosting account, this ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 16th August 2026
A security advisory has been issued for a vulnerability in Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage secure access to online accounts and services. The issue stems from the service’s access control settings lacking sufficient granularity, meaning permissions cannot be set finely enough to ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 16th August 2026
A security advisory from MyCERT has been released for Microsoft SharePoint Server, flagging a vulnerability where a critical function of the software does not require proper user authentication to access. For users running SharePoint Server for their public website or internal business tools, this gap could allow unauthorized people to view, ...
Continue reading