Announcements

CVE-2026-78570 (matched: wordpress)

  • 26th August 2026
A security vulnerability has been identified in the Total Donations plugin for WordPress. The flaw impacts every version of the plugin up to and including version 2.0.5.This is a privilege escalation issue, which means attackers do not need to have an existing account or login for your website to exploit the flaw. If successfully taken advantage ...
Continue reading

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

  • 26th August 2026
A security vulnerability has been identified in the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, tools used to manage web traffic and data for websites. This is an improper access control flaw, meaning the system’s built-in rules for limiting who can view or change data are not working correctly.If your website uses these ...
Continue reading

Gitea Gitea: Gitea Code Injection Vulnerability

  • 26th August 2026
A security flaw has been identified in Gitea, a code repository management tool used by many hosting clients to store and manage project code and development files. This is a code injection vulnerability. To exploit it, an attacker would need to already have write access to a Gitea repository. They could send a specially crafted file change ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 26th August 2026
A security advisory from MyCERT, first published on July 20, 2026, addresses new active attacks targeting Microsoft SharePoint, a popular tool organizations use to store, share, and collaborate on work documents and team resources. The notice shares guidance on securing (referred to as "hardening" in security contexts) SharePoint configurations to ...
Continue reading