Announcements

CVE-2026-15303 (matched: wordpress)

  • 17th August 2026
A security vulnerability has been found in the 6Storage Rentals plugin for WordPress, affecting all versions up to and including 2.27.0. This flaw allows people who do not have authorized access to your website to log in to any existing user account on your WordPress site, including full administrator accounts. To carry out this unauthorized ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 17th August 2026
A security flaw has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, impacting all versions up to and including 1.0.4. The vulnerability stems from poor validation of file paths, which allows unauthenticated attackers (people who do not have login access to your website) to delete any files ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 17th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency (MyCERT) issued a security advisory recommending that organizations harden their Microsoft SharePoint deployments, following confirmed new attempts to exploit vulnerabilities in the platform. SharePoint is a common tool used by businesses to host shared document libraries, team ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 17th August 2026
A MyCERT security advisory was published on July 22, 2026, covering a vulnerability in Microsoft Active Directory Federation Services (ADFS), a tool many businesses use to manage secure user access to web applications, internal tools, and other services, often for single sign-on functionality. The issue is classified as an insufficient granularity ...
Continue reading