Sunday, April 26, 2026
HomeTagsVulnerability

Tag: Vulnerability

New Microsoft Exchange Vulnerability Grants Attackers Admin Access

Microsoft and CISA have issued urgent security alerts regarding a newly discovered high-severity vulnerability in Exchange Server hybrid deployments that could enable attackers to escalate privileges and potentially compromise both on-premises and cloud infrastructure. The vulnerability, tracked as CVE-2025-53786, affects organizations running hybrid configurations...

Cursor IDE Vulnerability in MCP Validation Enables MCPoison Command Execution Attack

A critical vulnerability in Cursor, the rapidly growing AI-powered code editor, that enables persistent remote code execution through manipulation of the Model Context Protocol (MCP) validation system. The vulnerability, tracked as CVE-2025-54136 and dubbed "MCPoison," exploits a trust bypass mechanism that allows attackers to...

ADOdb SQLite3 Driver Vulnerability Enables Arbitrary SQL Statement Execution

A critical SQL injection vulnerability affecting the widely-used ADOdb PHP database abstraction library has been discovered and patched, posing significant security risks to applications using the SQLite3 driver. The vulnerability, tracked as CVE-2025-54119, carries the maximum CVSS score of 10.0, highlighting its severity and...

New Streamlit Vulnerability Enables Cloud Account Takeover Attacks

A critical vulnerability in Streamlit's file upload feature that could enable attackers to execute cloud account takeover attacks on misconfigured instances. The vulnerability, which client-side file type restrictions, was exploited in a proof-of-concept demonstration showing how financial market dashboards could be manipulated to influence...

FUJIFILM Printer Vulnerability Exposes Devices to Denial-of-Service Attacks

A newly disclosed vulnerability in FUJIFILM’s Internet Printing Protocol (IPP) and Line Printer Daemon (LPD) processing logic allows malicious actors to send specially crafted packets that can freeze affected printers, causing a denial-of-service (DoS) condition. FUJIFILM has released firmware updates to address the...

Researchers Exploit 0-Day Vulnerability in Google kernelCTF and Debian 12

Security researchers have successfully exploited a critical zero-day vulnerability in the Linux kernel, compromising multiple Google kernelCTF instances and Debian 12 systems with a near-perfect success rate. The vulnerability, now designated as CVE-2025-38001, represents a sophisticated Use-After-Free vulnerability in the Linux network packet scheduler...