Announcements

CVE-2026-15303 (matched: wordpress)

  • 16th August 2026
A security flaw has been identified in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. The vulnerability allows anyone without a valid login for your website to access a built-in plugin function that has no required verification steps. If an attacker submits the email address of any existing user on ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 16th August 2026
A security flaw (identified as CVE-2026-14484) affects the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, impacting all versions up to and including 1.0.4. This plugin is designed to let visitors upload multiple files through Contact Form 7 forms on your WordPress site. The issue comes from the plugin not properly ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 16th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency (MyCERT) issued a security advisory warning of newly observed attacks targeting Microsoft SharePoint, a popular platform used to host shared workspaces, document storage, and team collaboration tools for websites and internal business systems.The advisory outlines recommended security ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 16th August 2026
On 22 July 2026, Malaysia’s national cybersecurity agency MyCERT published an advisory identifying a vulnerability in Microsoft Active Directory Federation Services. The issue stems from insufficiently granular access controls: the system lacks fine enough restrictions to ensure only authorized users can access specific resources, functions or ...
Continue reading