Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Wed 15 Jul

F5 BIG-IP HTTP/2 TMM memory exhaustion (CVE-2026-59762)

F5 CNA advisory K000162231 (NVD published 15 July 2026) says that when an HTTP/2 profile is configured on a virtual server, undisclosed requests can raise TMM memory until the process restarts. That is a data-plane denial of service; F5 says there is no control-plane exposure. F5 scores it 8.7 (CVSS 4.0) and 7.5 (CVSS 3.1). Affected classic BIG-IP: 21.1.0 before 21.1.0.1, 21.0.0 before 21.0.0.3, 17.5.0 before 17.5.1.8, 17.1.0 before 17.1.3.4. Also BIG-IP Next for Kubernetes 2.3 before 2.3.2 and 2.0 before 2.2.3, Next CNF 2.3 before 2.3.2 / 2.0 before 2.2.3 / 1.1 before 1.4.3, and Next SPK 1.7 before 1.7.18 (NVD also lists Next SPK 1.9.0 as affected with no upper bound). Not in CISA KEV at last check. The NVD record does not state in-the-wild exploitation.

F5 K000162231

vulnerabilities network

Vulnerabilities

Tue 14 Jul

Sangoma Switchvox unauthenticated SQLi to RCE exploited (CVE-2026-9586); CISA KEV

Horizon3 published on 1 September 2026 that Defused Cyber honeypots saw valid in-the-wild exploitation of CVE-2026-9586 on 30 August 2026 (attacker IP 176.65.148.184 in the published honeypot traffic). The flaw is an unauthenticated SQL injection in Sangoma Switchvox SMB Edition: the /pa PhoneAppsHandler.pm endpoint concatenates the PhoneIP field from an XML body into a PostgreSQL query, which Horizon3 says can be turned into remote code execution as the database superuser. Sangoma released Switchvox 8.4.0.2 on 14 July 2026. Horizon3 reported the issues in April; Security Risk Advisors independently reported them in May and published on 17 July. GitHub CVE advisory (17 July) rates it Critical 9.3. The CNA record cites Switchvox SMB Edition 8.3 (build 104997); Horizon3 notes Sangoma 8.4.0.2 release notes also mention 8.2.2.1 — upgrade to 8.4.0.2 rather than assuming an older build is safe. Horizon3 cites about 4,000 internet-exposed Switchvox devices on Shodan, mostly in the United States. CISA added CVE-2026-9586 to the KEV catalog on 2 September 2026. Restrict /pa to trusted phone networks until patched. IoC path if SSH is available: /var/log/switchvox/db-quirks.log.

Sangoma Switchvox 8.4.0.2 release notes (14 Jul 2026)

vulnerabilities network

Vulnerabilities

Wed 8 Jul

Juniper SRX/MX flowd crash from malformed TCP (CVE-2026-57023)

Juniper's 8 July 2026 security bulletin (JSA110083): an improper validation issue in the TCP proxy plugin of Junos OS on SRX Series and MX Series with SPC3 lets an unauthenticated, network-based attacker cause a complete denial of service. When TCP proxy is in use (ALGs, Advanced Anti-Malware, ICAP or UTM), a TCP packet with a specifically malformed header crashes flowd, causing a full service outage until the process restarts. CVSS 3.1 is 7.5; CVSS 4.0 is 8.7. Affected: 23.4 before 23.4R2-S7, 24.2 before 24.2R2-S4, 24.4 before 24.4R2-S3, 25.2 before 25.2R2. Not before 23.4R1. Juniper SIRT says it is not aware of malicious exploitation; the issue was seen during production usage. No workaround. This was part of Juniper's 8 July 2026 bulletin round (Canadian Centre for Cyber Security AV26-675).

Juniper JSA110083 (CVE-2026-57023)

vulnerabilities network

Vulnerabilities

Fri 1 May

cPanel/WHM authentication bypass, exploited in Australia

ASD's ACSC is aware of active exploitation in Australia of a critical authentication-bypass in cPanel/WHM that can lead to control-panel access and remote code execution. The vendor and the ACSC advisory body identify the issue as CVE-2026-41940 (ACSC listing text also used CVE-2026-4194). Affects versions after 11.40. Vendor patches were published from 28 April 2026; ACSC noted patches as of 30 April 2026.

ASD's ACSC advisory

vulnerabilities australia

Vulnerabilities

Fri 27 Mar

Langflow path traversal to arbitrary file write and RCE (CVE-2026-5027)

Tenable's advisory says Langflow's POST /api/v2/files endpoint does not sanitise multipart filenames, allowing a logged-in attacker to use path traversal to write files outside the upload directory. The CNA rates it 8.8 (CVSS 3.1). Exploit-DB published a working exploit on 31 August for Langflow 1.8.4 and earlier that uses the default auto-login path, writes a cron file and reaches remote code execution; active-exploitation reporting also appeared on the wire. Upgrade to Langflow 1.9.0 or later. Disabling auto-login and restricting network access reduce exposure but do not fix the underlying arbitrary file write.

Tenable Research TRA-2026-26

tech ai

Vulnerabilities

Fri 9 Jan

Langflow unauthenticated code injection exploited (CVE-2026-0768); credential harvest on honeypots

Trend Micro ZDI advisory ZDI-26-034 (public 9 January 2026; CVE-2026-0768) rates an unauthenticated code-injection flaw in Langflow at CVSS 9.8: the validate endpoint executes a user-supplied code string as Python, which ZDI says can run as root. NVD published the CVE on 23 January 2026 and records affected Langflow 1.4.2. On 1 September 2026 VulnCheck told BleepingComputer and SecurityWeek it had seen exploitation against U.K. honeypots over the prior weekend (about 50 attempts at first report, later more than 360), mainly from Russia, with attackers querying LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS* and AWS_SECRET* environment variables and reading Langflow secret material. Distinct from desk card cve-2026-9198 (separate Langflow code-injection CVE on CISA KEV). ZDI's published mitigation is to restrict interaction with the product; this desk does not invent a single fixed build number for CVE-2026-0768. Do not internet-expose unauthenticated Langflow.

Trend Micro ZDI-26-034 (CVE-2026-0768)

tech ai cloud