Skip to main content

Forminator Forms WordPress Plugin Critical RCE Flaw Affects 600,000 Active Installations (CVE-2026-15748)

Scope: Forminator Forms WordPress Plugin (All Versions Prior to Patched Release)

Zoom Workplace for Windows Critical Authentication Flaw Enables Unauthenticated Account Takeover (CVE-2026-53412)

Scope: Zoom Workplace for Windows Prior to Version 7.0.0 and Zoom Workplace VDI Client for

GitLab CE and EE Emergency Out-of-Band Patch Addresses Critical Unauthenticated Data Deletion Flaw (CVE-2026-19478)

Scope: GitLab Community Edition and Enterprise Edition Self-Managed Installations Versions

Windows Server 2022 Reaches End of Mainstream Support in 60 Days — Begin Migration to Windows Server 2025 Now

Scope: Organizations Running Windows Server 2022 (On-Premises and Hosted Environments)

Apple macOS Screen Sharing Logic Flaw Actively Exploited to Deploy Monero Miner via Root Command Execution (CVE-2026-43760)

Scope: macOS Systems with Screen Sharing or Remote Management Enabled and VNC Password Aut

VMware vCenter China-Nexus APT Actively Exploiting Directory Traversal to Deploy Babuk Ransomware on ESXi Hosts (CVE-2026-59310)

Scope: VMware vCenter Server All Versions Prior to VMSA-2026-0006.1 Patched Releases

Windows Container Isolation Driver Publicly Disclosed Zero-Day Grants Administrator Privileges (CVE-2026-72971)

Scope: Windows 10, Windows 11, Windows Server 2019, 2022, and 2025

Subscribe to Advisories