Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.
Chaotic Eclipse has released HardBreacher, a proof-of-concept exploit for a privilege escalation vulnerability in Kaspersky Endpoint Security. The researcher, who operates under multiple aliases including INFINITE NIGHTMARE and MSNightmare, continues to add zero-day disclosures to an expanding portfolio of published exploits.
WatchGuard has released patches addressing three critical vulnerabilities in the Fireware OS iked process that could enable unauthenticated remote code execution. Organizations running affected WatchGuard systems should prioritize applying these updates to prevent potential exploitation by attackers.
CISA has added PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaws affect PaperCut's print management software deployed across schools, hospitals, and office environments globally, including a pre-authentication remote code execution vulnerability. Organizations running PaperCut should prioritize patching given CISA's formal recognition of ongoing exploitation.
Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails to conduct credential-probing and command-and-control activities, with one flaw allowing arbitrary Python code execution with root privileges. The Langflow vulnerability (CVE-2026-0768, CVSS 9.8) stems from improper input validation, enabling remote code execution in a high-privilege context that attackers are leveraging in active campaigns.