Announcements

CVE-2026-18351 (matched: php)

  • 10th September 2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in ...
Continue reading

CVE-2026-18351 (matched: wordpress)

  • 10th September 2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in ...
Continue reading

Microsoft Windows: Microsoft Windows Heap-Based Buffer Overflow Vulnerability

  • 10th September 2026

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-85880

Continue reading

N-able N-central: N-able N-central Static Code Injection Vulnerability

  • 10th September 2026
Continue reading