ScanForge Security Digest 2635-02

200 items
18 critical73 high10 news

This week's security digest includes 0 actively exploited vulnerabilities (CISA KEV), 18 critical CVEs, and 73 high-severity CVEs. Review the details below and prioritize patching for any affected systems.

Critical

18

High Severity

73
8.8 ColdFusion versions 2023.19, 2025.8 and earlier are affected 4 CVEs CVE-2026-47932, CVE-2026-47931, CVE-2026-47929, CVE-2026-47930
8.7 Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2. 4 CVEs CVE-2026-21290, CVE-2026-21361, CVE-2026-21284, CVE-2026-21311
8.6 Dreamweaver Desktop versions 21.7 and earlier are affected b 3 CVEs CVE-2026-47907, CVE-2026-47906, CVE-2026-47908

+22 more products affected

Security News

10
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network The Hacker News

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island Schneier on Security

Ugh: A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable The Hacker News

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain fund

Hundreds of OpenAI Agents Invaded Hugging Face Servers Dark Reading

The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a

PaperCut releases second emergency patch for exploited flaws Bleeping Computer

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG a

Offensive Security Investments Surge as AI Threats Increase Dark Reading

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for

GiveWP WordPress donation plugin flaw lets hackers execute server commands Bleeping Computer

A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitr

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication The Hacker News

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on suscept

Content aggregated from NIST/NVD, CISA, CERT/CC, and public security news sources. External articles are linked to their original source.