Cisco released fixes for CVE-2026-76461, a critical flaw in AsyncOS Software for Secure Email Gateway that lets unauthenticated attackers run root-level commands by sending crafted emails with malicious SQL statements. The company confirmed it detected active exploitation of the bug in September 2026 and issued indicators of compromise for defenders to check mail logs and network traffic. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch.
bleepingcomputer.com
· 2026-09-15
Security firm Horizon3 says hackers are exploiting CVE-2026-9586, an unauthenticated SQL injection bug in Sangoma Switchvox's /pa endpoint that allows remote code execution. Honeypot data shows a single source IP rapidly hitting multiple exposed systems, deploying reverse shells and exfiltrating process data. Sangoma patched the flaw, one of 12 reported by Horizon3, in version 8.4.0.2 released July 14.
bleepingcomputer.com
· 2026-09-02
Researcher Jack Taylor found a second-order SQL injection flaw, CVE-2026-19949, in the All-in-One WP Migration and Backup WordPress plugin, used on over five million sites. Attackers can plant malicious data via trackbacks that activates when an admin exports or imports a site, exposing a secret key that lets them upload a malicious archive containing executable code and seize control of the website.
bleepingcomputer.com
· 2026-09-02
ServiceNow issued fixes for three critical vulnerabilities in its AI Platform that could let unauthenticated attackers run arbitrary code, escalate privileges, or manipulate data via SQL injection, all without user interaction. The company also patched a separate high-severity sandbox escape bug that could allow low-privileged users to achieve remote code execution. ServiceNow says it has no evidence of active exploitation but is urging customers to apply the updates immediately.
bleepingcomputer.com
· 2026-08-28