Skip to main content

Microsoft Exchange Server Elevation of Privilege Flaw Is October's Only Patch Tuesday Fix (CVE-2026-96940)

Scope: Microsoft Exchange Server, all supported on-premises versions

Ninja Forms and WPC Product Bundles Flaws Being Used to Plant Backdoors on WordPress Sites (CVE-2026-94504 / CVE-2026-93836)

Scope: Ninja Forms WordPress plugin versions 3.15.3 and earlier, and WPC Product Bundles f

Atlassian Patches Unauthenticated File Access Flaw Across Eight Data Center Products (CVE-2026-21589)

Scope: Atlassian Data Center products, including Jira, Confluence, Bitbucket, Bamboo, Crow

TeamViewer Patches Five Flaws Including a Remote Access Control Bypass That Can Lead to Code Execution (CVE-2026-92370 and Others)

Scope: TeamViewer Full Client and Host for Windows, Linux, and macOS, versions before 15.8

Citrix NetScaler Gets Another Exploited Zero-Day, and Last Week's Patches Do Not Cover It (CVE-2026-88779)

Scope: Citrix NetScaler ADC and NetScaler Gateway appliances using SAML authentication wit

Dell Container Storage Modules Flaws Expose Storage Admin Credentials Without Any Login (CVE-2026-63688 / CVE-2026-63692)

Scope: Dell Container Storage Modules (CSM) prior to version 1.17.0, including CSM Authori

FortiMail Zero-Day Lets Unauthenticated Attackers Write Files to the Mail Gateway and Is Already Exploited (CVE-2026-104286)

Scope: Fortinet FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2

WordPress Core Path Traversal Flaw Remains Under Active Scanning a Week After Disclosure (CVE-2026-87902)

Scope: WordPress Core, All Versions Prior to 7.1.2 (Fix Backported to 4.7)

Subscribe to