A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious ...
Drupal CVE-2026-9082 exploitation hit 15,000 attempts across 65 countries, forcing urgent patches by May 27, 2026.
Ghost CMS SQL injection campaign has compromised 700+ websites — including Harvard University, Oxford University, and DuckDuckGo — using a CVSS 9.4 flaw to inject ClickFix malware lures that trick ...
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier ...
In its warning, Drupal said a vulnerability in this API allows an attacker to send specially crafted requests resulting in ...
Drupal released security updates for a highly critical Drupal Core vulnerability affecting sites that use PostgreSQL.
Drupal has patched CVE-2026-9082, a highly critical vulnerability that could allow threat actors to hack websites.
SAP has released 15 new security notes, including two addressing critical code injection flaws in S/4HANA and Commerce.
India's software supply chain security challenge is deepening as AI expands the attack surface while many enterprises lack ...
Shannon Lite, the autonomous white-box penetration testing tool built by San Francisco-based Keygraph, shipped version 1.2.0 ...
Admins with Dynamics 365 on-prem should also take note of a “severe” vulnerability that allows remote code execution.