GitLab has released an emergency patch addressing a critical code-injection vulnerability that allows unauthenticated attackers to delete or modify publicly accessible projects. The flaw poses a significant risk to organizations using GitLab, as it can be exploited without requiring valid credentials to compromise project integrity and availability.
Rapid7's Q2 2026 Quarterly Threat Landscape Report reveals that vulnerability disclosure volume has doubled year-over-year to 8,539 high- and critical-severity CVEs, while attackers increasingly leverage AI-assisted automation to exploit vulnerabilities faster than traditional patch cycles can address them. The report identifies that 62% of exploited vulnerabilities require no user interaction, with missing-authentication flaws surging 247% year-over-year, and highlights persistent nation-state activity from Iranian, North Korean, and Russian clusters alongside continued ransomware campaigns led by Qilin. Organizations can no longer rely on patching volume alone; success requires understanding which exposures are actually reachable and prioritizing risk reduction based on exploitability rather than severity scores.
CISA Malcolm, a network traffic analysis tool suite, contains multiple vulnerabilities across versions prior to 26.08.0 that could allow authenticated attackers to execute arbitrary code, bypass access controls, or cause denial-of-service conditions. The flaws span archive extraction without resource limits, path traversal in file handling, unsafe file uploads with inadequate type validation, RBAC bypasses via path normalization issues, and insufficient protections against compressed data bombs. Users should upgrade to the patched versions (26.06.1, 26.07.0, or 26.08.0 depending on the vulnerability) to mitigate exploitation risks.
A stack overflow vulnerability in Siemens Simcenter Nastran and Simcenter Femap versions prior to V2606 could allow remote code execution when a user is tricked into running an affected application binary with a malicious string argument. The vulnerability carries a CVSS score of 7.8 and affects critical infrastructure sectors including manufacturing, defense, energy, healthcare, and transportation systems worldwide. Siemens has released patched versions and recommends users update immediately.
CISA has added four vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: a Microsoft IKE service double free vulnerability, a Microsoft SharePoint weak authentication flaw, a Broadcom VMware vCenter path traversal issue, and an Apple macOS improper authentication vulnerability. Under Binding Operational Directive 26-04, federal agencies must prioritize rapid remediation of these KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices and address high-risk exploited vulnerabilities as a priority.
The U.S. government's Gold Eagle coordination program aims to help organizations prioritize patching and mitigation efforts, though cybersecurity experts express significant skepticism about the initiative's ambitions and promised capabilities. Despite concerns that the government's claims may be overstated, the program could still provide practical value in vulnerability management if executed effectively.
CISA has added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw in this open-source Python-based distributed computing framework can enable remote code execution through browsers, posing a significant risk to organizations using Ray for AI and machine learning workloads.
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Microsoft Internet Key Exchange (IKE) Service Extensions.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Broadcom VMware vCenter.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.1 (Critical). Affects Microsoft SharePoint.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects Apple macOS.
Researchers have discovered an exploit chain combining two separate vulnerabilities in Unisoc modems that allows attackers to compromise Android devices through a simple phone call. The attack requires only that a victim answer the incoming call, after which an attacker can deliver a malicious payload to gain device control.
A critical GraphQL vulnerability in GitLab Community and Enterprise editions (CVE-2026-19478, CVSS 9.4) could allow unauthenticated attackers to remotely delete or modify public projects and user data under certain conditions. GitLab has released security updates to address the flaw, which represents a significant risk to instances exposed to untrusted networks.
VulnerabilitySANS Internet Storm Center·6 days ago
Apple released updates for iOS/iPadOS and macOS addressing 108 vulnerabilities across the platforms, arriving roughly two weeks after a targeted macOS patch for a screen-sharing flaw. The screen-sharing vulnerability patched in the previous update did not impact iOS/iPadOS devices.
Wiz researchers discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could allow attackers to execute arbitrary commands through a crafted GitHub issue, potentially exposing internal Jira credentials stored in the affected workflow. The flaw existed in the jira_issue.yml workflow file, which was triggered by GitHub issues, creating an attack vector for credential theft and unauthorized command execution.
A critical vulnerability in the widely-deployed Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files and achieve remote code execution on affected sites. Tracked as CVE-2026-15748 with a CVSS score of 9.8, the flaw poses a severe risk to the plugin's 600,000+ active installations. The vulnerability was discovered by a security researcher and demands immediate patching to prevent exploitation.
A vulnerability in UNISOC modems allows attackers to achieve kernel-level code execution by exploiting video call functionality. This remote code execution capability represents a significant risk to devices using UNISOC chipsets, as the attack vector operates at a fundamental system level.