Announcements

CVE-2026-15303 (matched: wordpress)

  • 15th August 2026
A security flaw has been discovered in the 6Storage Rentals plugin for WordPress, which affects all versions of the plugin up to and including 2.27.0. This vulnerability allows anyone who does not have an account on your website to log in as any existing WordPress user on your site, including administrator accounts, simply by entering that ...
Continue reading

CVE-2026-14484 (matched: wordpress)

  • 15th August 2026
A security vulnerability has been identified in the RapiSafe – Secure Multi File Upload for Contact Form 7 WordPress plugin, which adds secure file upload features to Contact Form 7 forms. All versions of the plugin up to and including 1.0.4 are affected by this flaw.The issue allows unauthenticated attackers (people who do not have admin login ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 15th August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT released a new security advisory focused on Microsoft SharePoint, a platform many organizations use to host internal team sites, share business documents, and run collaborative web tools. The advisory was issued after new methods for exploiting SharePoint systems were identified. ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 15th August 2026
On 22 July 2026, cybersecurity agency MyCERT released an advisory detailing a vulnerability in Microsoft Active Directory Federation Services (AD FS). AD FS is a common Microsoft tool used to manage user sign-ins for websites, apps, and business services, allowing people to use one set of login credentials across multiple platforms instead of ...
Continue reading