VYPR
Latest stories
6,093 stories · 2,757 sources
Top stories · 7d roundup
Synthesized by Vypr AI

Top Vulnerability Stories

Cisco FMC Exploitation Leads to Credential Theft and Ransomware Deployment

Organizations are warned about the exploitation of Cisco Secure FMC vulnerabilities, which have been used to steal credentials and deploy the Qilin ransomware. This highlights the critical need for timely patching of network infrastructure to prevent sophisticated attacks. GovInfoSecurity The Hacker News SecurityWeek CVEs: CVE-2026-20079, CVE-2026-20316

Active Exploitation of PaperCut Servers for Command Execution

Hackers are actively exploiting vulnerabilities in PaperCut servers, enabling command execution. This widespread exploitation underscores the urgency for organizations using PaperCut to apply patches immediately to mitigate the risk of system compromise. Cyber Security News CVEs: CVE-2023-27350, CVE-2023-27351, CVE-2026-81578, CVE-2026-82078

Adobe Commerce and Magento Zero-Day Vulnerability "StyleSmuggler"

The "StyleSmuggler" vulnerability in Adobe Commerce and Magento allows for zero-day exploitation, posing a significant risk to e-commerce platforms. This flaw enables attackers to compromise sensitive data and disrupt online operations. Tenable Blog CVEs: CVE-2022-24086, CVE-2024-34102, CVE-2025-54236, CVE-2026-75650

NextGen Mirth Connect Flaws Lead to Exposure of Downstream System Logins

Vulnerabilities in NextGen Mirth Connect have been identified that could expose sensitive login credentials for downstream systems. This highlights the importance of securing healthcare integration engines, which often handle critical patient data. GovInfoSecurity CVEs: CVE-2023-37679, CVE-2023-43208

Most critical
Sorted by risk + recency
Critical · last 30 days
CVSS ≥ 9, by news mentions
All →
  1. 01CVE-2026-82078KEV0.64
    Papercut/Papercut Mf

    An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an…

  2. 02CVE-2026-81578KEV0.69
    Papercut/Papercut Mf

    An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access…

  3. 03CVE-2026-83548KEV0.77
    SonicWall/SMA100 appliance

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and…

  4. 04CVE-2026-194780.62
    GitLab Inc./GitLab

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user…

  5. 05CVE-2026-82329KEV0.76
    Jfrog/Artifactory

    JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

  6. 06CVE-2026-19490KEV0.76
    Netscaler/NetScaler Gateway

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

  7. 07CVE-2026-86218KEV0.76
    N-able/N-central

    N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Recently published
Last 24-48 hours
All →
  1. 01CVE-2026-852000.42
    WordPress/Geo My Wp

    The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on…

  2. 02CVE-2026-851980.42
    WordPress/MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO

    The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  3. 03CVE-2026-781750.57
    WordPress/Tutor Lms

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler…

  4. 04CVE-2026-781590.57
    WordPress/The Events Calendar

    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the…

  5. 05CVE-2026-780060.64
    WordPress/The Events Calendar

    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires…

  6. 06CVE-2026-771610.42
    WordPress/Smart Marketing SMS and Newsletters Forms

    The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  7. 07CVE-2026-175850.34
    WordPress/Royal Elementor Addons

    The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to…