Vulnerabilities Archives - Information Security /uit/infosec/category/vulnerabilities/ Tue, 28 Jul 2026 14:10:54 +0000 en-CA hourly 1 https://wordpress.org/?v=6.9.5 WordPress RCE Vulnerability (CVE-2026-63030) /uit/infosec/2026/07/28/wordpress-rce-vulnerability-cve-2026-63030/ Tue, 28 Jul 2026 14:10:52 +0000 /uit/infosec/?p=2796 A recently discovered vulnerability (CVE-2026-63030) that affects WordPress Core and allow an unauthenticated remote attacker to achieve remote code execution (RCE). Severity level:CVSS Score: 9.8/Critical. Description: WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. CVE-2026-63030 is a critical REST […]

The post WordPress RCE Vulnerability (CVE-2026-63030) appeared first on Information Security.

]]>
A recently discovered vulnerability (CVE-2026-63030) that affects WordPress Core and allow an unauthenticated remote attacker to achieve remote code execution (RCE).

Severity level:
CVSS Score: 9.8/Critical.

Description:

WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. CVE-2026-63030 is a critical REST API batch endpoint route confusion vulnerability in WordPress Core. The flaw causes a mismatch between request validation and execution within the WordPress REST API batch processing mechanism, allowing specially crafted requests to bypass expected security controls. When chained with CVE-2026-60137, an SQL injection vulnerability in WP_Query, an unauthenticated attacker can achieve remote code execution and fully compromise a vulnerable WordPress site.


Affected Versions:

  • WordPress 6.9.0 through 6.9.4
  • WordPress 7.0 through 7.0.1
  • WordPress 7.1 beta releases prior to 7.1 beta 2

Impact:

Successful exploitation may allow attackers to execute arbitrary code on the affected server.

Resolution:

Upgrade affected WordPress installations to:-

  • WordPress 6.9.5 or later.
  • WordPress 7.0.2 or later.
  • WordPress 7.1 beta 2 or later.

Reference:

UIT Information Security

The post WordPress RCE Vulnerability (CVE-2026-63030) appeared first on Information Security.

]]>
Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412) /uit/infosec/2026/07/17/zoom-workplace-for-windows-improper-input-validation-cve-2026-53412/ Fri, 17 Jul 2026 17:59:09 +0000 /uit/infosec/?p=2780 A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access. Severity level:CVSS Score: 9.8/Critical. Description: CVE-2026-53412 is a critical vulnerability caused by improper input validation in Zoom Workplace for Windows and […]

The post Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412) appeared first on Information Security.

]]>
A recently disclosed vulnerability (CVE-2026-53412) that affects Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows and may allow an unauthenticated remote attacker to take over a user account via network access.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE-2026-53412 is a critical vulnerability caused by improper input validation in Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows. An unauthenticated attacker can exploit the flaw remotely over a network to perform an account takeover.

Affected Versions:

  • Zoom Workplace for Windows before 7.0.0.
  • Zoom Workspace VDI client for Windows before (7.0.10, 6.6.15, 6.5.18)

Impact:

Successful exploitation may allow attackers to take over affected Zoom account.

Resolution:

Upgrade affected software to the latest supported versions.

Reference:

UIT Information Security

The post Zoom Workplace for Windows - Improper Input Validation (CVE-2026-53412) appeared first on Information Security.

]]>
Linux kernel vulnerability (CVE-2026-43503) /uit/infosec/2026/07/17/linux-kernel-vulnerability-cve-2026-43503/ Fri, 17 Jul 2026 17:56:40 +0000 /uit/infosec/?p=2778 A recently disclosed vulnerability (CVE-2026-43503), also known as DirtyClone, affects the Linux kernel and may allow a local unprivileged user to gain root privileges on vulnerable systems. Severity level:CVSS Score: 8.8/High. Description: CVE-2026-43503 (DirtyClone) is a high-severity Linux kernel privilege escalation vulnerability caused by improper handling of shared memory fragments in the networking subsystem. A […]

The post Linux kernel vulnerability (CVE-2026-43503) appeared first on Information Security.

]]>
A recently disclosed vulnerability (CVE-2026-43503), also known as DirtyClone, affects the Linux kernel and may allow a local unprivileged user to gain root privileges on vulnerable systems.

Severity level:
CVSS Score: 8.8/High.

Description:

CVE-2026-43503 (DirtyClone) is a high-severity Linux kernel privilege escalation vulnerability caused by improper handling of shared memory fragments in the networking subsystem. A local attacker can exploit the flaw to modify file-backed page-cache memory and alter the behavior of privileged executables, potentially gaining root privileges on the affected system. The attack occurs in memory without modifying files on disk, making detection more difficult.

Affected Versions:

  • Major Linux distributions.
  • Linux systems running kernel versions prior to vendor-provided fixes for CVE-2026-43503.

Impact:

Successful exploitation may allow attackers to escalate privileges from local user account to root.

Resolution:

Apply the latest security updates provided by the Linux distribution and upgrade the kernel.

Reference:

UIT Information Security

The post Linux kernel vulnerability (CVE-2026-43503) appeared first on Information Security.

]]>
Oracle PeopleSoft Remote Code Execution Vulnerability (CVE-2026-35273) /uit/infosec/2026/06/16/oracle-peoplesoft-remote-code-execution-vulnerability-cve-2026-35273/ Tue, 16 Jun 2026 18:35:04 +0000 /uit/infosec/?p=2766 A recently disclosed vulnerability (CVE‑2026‑35273) affects Oracle PeopleSoft Enterprise PeopleTools and may allow a remote, unauthenticated attacker to execute arbitrary code and take full control of affected systems. Severity level:CVSS Score: 9.8/Critical. Description: CVE‑2026‑35273 is a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. The flaw allows an unauthenticated attacker with […]

The post Oracle PeopleSoft Remote Code Execution Vulnerability (CVE-2026-35273) appeared first on Information Security.

]]>
A recently disclosed vulnerability (CVE‑2026‑35273) affects Oracle PeopleSoft Enterprise PeopleTools and may allow a remote, unauthenticated attacker to execute arbitrary code and take full control of affected systems.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE‑2026‑35273 is a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. The flaw allows an unauthenticated attacker with network access over HTTP to exploit the application due to missing or improper access controls. An attacker can send specially crafted requests to the vulnerable component to execute arbitrary code, potentially leading to full application takeover without requiring credentials or user interaction.

Affected Versions:

Oracle PeopleSoft Enterprise PeopleTools.

  • Version 8.61.
  • Version 8.62.

Impact:

Successful exploitation may allow attackers to gain complete control of the PeopleSoft application.

Resolution:

Install the latest available Oracle PeopleTools patches.

Reference:

UIT Information Security

The post Oracle PeopleSoft Remote Code Execution Vulnerability (CVE-2026-35273) appeared first on Information Security.

]]>
Windows Netlogon RCE Vulnerability (CVE-2026-41089) /uit/infosec/2026/06/11/windows-netlogon-rce-vulnerability-cve-2026-41089/ Thu, 11 Jun 2026 15:03:44 +0000 /uit/infosec/?p=2763 A recently discovered critical vulnerability (CVE‑2026‑41089) affects Microsoft Windows Server and may allow a remote, unauthenticated attacker to execute arbitrary code on affected systems by targeting the Netlogon service. Severity level:CVSS Score: 9.8/Critical. Description: CVE‑2026‑41089 is a stack‑based buffer overflow vulnerability in the Windows Netlogon service. The flaw occurs due to improper handling of specially […]

The post Windows Netlogon RCE Vulnerability (CVE-2026-41089) appeared first on Information Security.

]]>
A recently discovered critical vulnerability (CVE‑2026‑41089) affects Microsoft Windows Server and may allow a remote, unauthenticated attacker to execute arbitrary code on affected systems by targeting the Netlogon service.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE‑2026‑41089 is a stack‑based buffer overflow vulnerability in the Windows Netlogon service. The flaw occurs due to improper handling of specially crafted network requests in the Netlogon RPC interface.

An attacker can exploit this vulnerability by sending a malicious request to a vulnerable domain controller, causing the service to overwrite memory on the stack. This can result in remote code execution with SYSTEM‑level privileges, without requiring authentication or user interaction.

Affected Versions:

  • Microsoft Windows Server 2012/ 2012 R2.
  • Microsoft Windows Server 2016.
  • Microsoft Windows Server 2019.
  • Microsoft Windows Server 2022 / 2022 23H2.
  • Microsoft Windows Server 2025.

Impact:

Successful exploitation may allow attackers to execute arbitrary code with system privileges.

Resolution:

  • Install the Microsoft’s May 2026 updates immediately.
  • Prioritize Domain Controller and identity Infrastructure systems.

Reference:

UIT Information Security

The post Windows Netlogon RCE Vulnerability (CVE-2026-41089) appeared first on Information Security.

]]>
7-Zip Heap Buffer Overflow (CVE-2026-48095) /uit/infosec/2026/05/29/7-zip-heap-buffer-overflow-cve-2026-48095/ Fri, 29 May 2026 13:17:08 +0000 /uit/infosec/?p=2749 A recently disclosed vulnerability (CVE‑2026‑48095) affects 7-Zip and may allow a remote attacker to execute arbitrary code on vulnerable systems by tricking the users into opening a specially crafted archive file.Severity level:CVSS Score: 8.8/High.Description:CVE‑2026‑48095 is a heap buffer overflow in 7‑Zip’s NTFS handler caused by improper memory allocation when processing crafted archive data. Opening a […]

The post 7-Zip Heap Buffer Overflow (CVE-2026-48095) appeared first on Information Security.

]]>
A recently disclosed vulnerability (CVE‑2026‑48095) affects 7-Zip and may allow a remote attacker to execute arbitrary code on vulnerable systems by tricking the users into opening a specially crafted archive file.

Severity level:
CVSS Score: 8.8/High.

Description:

CVE‑2026‑48095 is a heap buffer overflow in 7‑Zip’s NTFS handler caused by improper memory allocation when processing crafted archive data. Opening a malicious file can trigger memory corruption, potentially leading to remote code execution.

Affected Versions:
All versions up to and including 26.00.

Impact:
Successful exploitation may allow attackers to execute arbitrary code on the system.

Resolution:
Upgrade to fixed 7-Zip version 26.01 or later.

Reference:




UIT Information Security

The post 7-Zip Heap Buffer Overflow (CVE-2026-48095) appeared first on Information Security.

]]>
Linux Kernel Local root Privilege Escalation (CVE-2026-46333) /uit/infosec/2026/05/29/linux-kernel-local-root-privilege-escalation-cve-2026-46333/ Fri, 29 May 2026 13:10:54 +0000 /uit/infosec/?p=2747 A recently discovered vulnerability (CVE‑2026‑46333) affects the Linux kernel and may allow a local, unprivileged attacker to access sensitive files and escalate privileges to root, potentially leading to full system compromise.Severity level:CVSS Score: 7.1/High.Description:CVE‑2026‑46333 is a race condition vulnerability in the Linux kernel’s _ptrace_may_access() function caused by improper handling of process state during termination. When […]

The post Linux Kernel Local root Privilege Escalation (CVE-2026-46333) appeared first on Information Security.

]]>
A recently discovered vulnerability (CVE‑2026‑46333) affects the Linux kernel and may allow a local, unprivileged attacker to access sensitive files and escalate privileges to root, potentially leading to full system compromise.

Severity level:
CVSS Score: 7.1/High.

Description:
CVE‑2026‑46333 is a race condition vulnerability in the Linux kernel’s _ptrace_may_access() function caused by improper handling of process state during termination. When a privileged process exits, there is a brief window where its memory context is cleared but its file descriptors remain open. An unprivileged local user can exploit this timing window using system calls such as pidfd_getfd () to access open file descriptors from privileged processes. This allows attackers to bypass security checks and access restricted resources. Exploitation can result in the disclosure of sensitive files such as /etc/shadow and SSH private keys.


Affected Versions:
Linux Kernel:
All kernel versions from November 2016 up to the release of vendor patches are affected.

Impacted Linux Distribution:

  • Ubuntu.
  • Debian.
  • Red Hat Enterprise Linux (RHEL).
  • SUSE Linux Enterprise.
  • Fedora, Arch Linux and other mainstream distributions.

Impact:
Successful exploitation may allow attackers to read sensitive files and escalate privileges to root.

Resolution:
Please update the Linux kernel to the fixed version released by the distribution vendor.

Mitigations:
Where immediate patching is not possible:

  • Disable or restrict untrusted local user access.
  • Restrict ptrace access.

Reference:

UIT Information Security 

The post Linux Kernel Local root Privilege Escalation (CVE-2026-46333) appeared first on Information Security.

]]>
Apache HTTP Server Vulnerability (CVE-2026-23918) /uit/infosec/2026/05/11/apache-http-server-vulnerability-cve-2026-23918/ Mon, 11 May 2026 19:22:27 +0000 /uit/infosec/?p=2718 Apache has released a security update to address a vulnerability (CVE‑2026‑23918) in Apache HTTP Server that may result in denial‑of‑service and potential remote code execution under specific configurations.Severity level:CVSS Score: 8.8/High.Description:CVE‑2026‑23918 is a double‑free vulnerability in the mod_http2 module of Apache HTTP Server that occurs during HTTP/2 stream handling. A specially crafted sequence of HTTP/2 […]

The post Apache HTTP Server Vulnerability (CVE-2026-23918) appeared first on Information Security.

]]>
Apache has released a security update to address a vulnerability (CVE‑2026‑23918) in Apache HTTP Server that may result in denial‑of‑service and potential remote code execution under specific configurations.

Severity level:
CVSS Score: 8.8/High.

Description:
CVE‑2026‑23918 is a double‑free vulnerability in the mod_http2 module of Apache HTTP Server that occurs during HTTP/2 stream handling. A specially crafted sequence of HTTP/2 frames can cause improper memory deallocation, leading to worker process crashes. In certain deployments—particularly those using Apache Portable Runtime (APR) with the mmap allocator—this flaw may be leveraged to achieve remote code execution in addition to denial‑of‑service.

Affected Versions:

  • Apache HTTP Server version 2.4.66 with mod_http2_enabled.

Impact:

Successful exploitation may allow attackers to potentially execute arbitrary code remotely on vulnerable systems.

Resolution:

  • Please upgrade to Apache HTTP Server 2.4.67 or later.

Reference:

UIT Information Security

The post Apache HTTP Server Vulnerability (CVE-2026-23918) appeared first on Information Security.

]]>
Linux Kernel Local Privilege Escalation (CVE-2026-31431) /uit/infosec/2026/05/11/linux-kernel-local-privilege-escalation-cve-2026-31431/ Mon, 11 May 2026 19:00:54 +0000 /uit/infosec/?p=2716 A recently disclosed vulnerability (CVE‑2026‑31431), commonly referred to as “Copy Fail”, affects the Linux kernel and may allow a local, unprivileged attacker to escalate privileges and gain full root access on affected systems. Severity level:CVSS Score: 7.8/High. Description:CVE‑2026‑31431 is a local privilege escalation vulnerability caused by a logic flaw in the Linux kernel’s cryptographic subsystem, […]

The post Linux Kernel Local Privilege Escalation (CVE-2026-31431) appeared first on Information Security.

]]>
A recently disclosed vulnerability (CVE‑2026‑31431), commonly referred to as “Copy Fail”, affects the Linux kernel and may allow a local, unprivileged attacker to escalate privileges and gain full root access on affected systems.

Severity level:
CVSS Score: 7.8/High.

Description:
CVE‑2026‑31431 is a local privilege escalation vulnerability caused by a logic flaw in the Linux kernel’s cryptographic subsystem, specifically the algif_aead module within the AF_ALG interface. Due to improper handling of in‑place cryptographic operations, an unprivileged local user can perform a controlled write to the kernel’s page cache of readable files. The attack vector is local (AV:L) and requires low privileges with no user interaction.

Affected Versions:

Linux Kernel :- All kernel versions released from August 2017 up to the availability of vendor patches.

Impacted Linux Distribution:-

  • Ubuntu (all supported releases prior to patched kernels).
  • Debian.
  • Red Hat Enterprise Linux (RHEL).
  • Amazon Linux.
  • SUSE Linux Enterprise.
  • Fedora, Arch Linux, AlmaLinux, Rocky Linux, Oracle Linux

Impact:

Successful exploitation may allow attackers to escalate from an unprivileged local user to full root access.

Resolution:

Please update the Linux kernel to the fixed version released by the distribution vendor.

Mitigations:

Where immediate patching is not possible:

  • Disable or restrict access to the AF_ALG interface.
  • Prevent loading of the vulnerable algif_aead module where supported.
  • Limit local shell access and enforce least‑privilege controls.

Reference:

UIT Information Security

The post Linux Kernel Local Privilege Escalation (CVE-2026-31431) appeared first on Information Security.

]]>
cPanel Authentication bypass Vulnerability (CVE-2026-41940) /uit/infosec/2026/05/11/cpanel-authentication-bypass-vulnerability-cve-2026-41940/ Mon, 11 May 2026 17:25:30 +0000 /uit/infosec/?p=2713 A critical security vulnerability (CVE-2026-41940) has been identified in cPanel, Web Host Manager (WHM) and WP Squared which may allow unauthenticated attackers to completely compromise affected systems through an authentication bypass in the login process.Severity level:CVSS Score: 9.8/Critical.Description:CVE‑2026‑41940 is a critical authentication bypass vulnerability in cPanel, WHM, and WP Squared caused by improper session handling […]

The post cPanel Authentication bypass Vulnerability (CVE-2026-41940) appeared first on Information Security.

]]>
A critical security vulnerability (CVE-2026-41940) has been identified in cPanel, Web Host Manager (WHM) and WP Squared which may allow unauthenticated attackers to completely compromise affected systems through an authentication bypass in the login process.

Severity level:
CVSS Score: 9.8/Critical.

Description
:
CVE‑2026‑41940 is a critical authentication bypass vulnerability in cPanel, WHM, and WP Squared caused by improper session handling during the login process. Unsanitized user‑controlled input can be injected into pre‑authentication session files, allowing an unauthenticated attacker to escalate privileges. Successful exploitation results in full administrative or root‑level access to the affected server.

Affected Versions
:

  • cPanel & WHM:- All versions after 11.40.
  • WP Squared:- all versions prior to 11.136.1.7.

Impact:
Successful exploitation may allow attackers to bypass authentication without valid credentials and gain full admin access to cPanel/WHM.

Resolution:

Administrators must upgrade immediately to one of the following patched versions or later:

cPanel & WHM patched versions:

  • 11.86.0.41
  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.130.0.19
  • 11.132.0.29
  • 11.134.0.20
  • 11.136.0.5

WP Squared patched version:

  • 11.136.1.7

Reference:

UIT Information Security

The post cPanel Authentication bypass Vulnerability (CVE-2026-41940) appeared first on Information Security.

]]>