← Back
VulnerabilitySecurityWeek·2 hours ago

CISA Warns of Exploited Gitea Vulnerability

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.

Read full article at SecurityWeek

Related Articles

VulnerabilityHelp Net Security·3 hours ago

AI vulnerability discovery scores the highest impact of 20 emerging risks

Gartner's survey of 316 companies ranked AI-driven vulnerability discovery as the highest-impact emerging cybersecurity risk, a significant shift from the previous quarter when information integrity risk topped the list. The change reflects growing concern among risk managers and executives about AI systems' capability to identify previously unknown flaws at scale. This marks a notable reassessment of threat priorities as organizations grapple with the dual-edged nature of AI in both attack and defense scenarios.

VulnerabilityDark Reading·12 hours ago

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

Attackers can exploit a networking vulnerability in NVIDIA's OpenClaw tool to gain unauthenticated access to the local model server via the Ollama API, enabling persistent corruption of AI agents. The flaw allows threat actors to conduct LLM poisoning attacks by manipulating the underlying model through this unprotected interface. This attack vector poses significant risks to organizations deploying NVIDIA's AI tools in production environments.

VulnerabilitySecurity Affairs·15 hours ago

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981), both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin are being actively exploited in the wild. Notably, the paid editions of the plugin were never listed as vulnerable in any CVE database despite being affected, and affected organizations require manual patching to remediate these flaws.