Check Point CVE-2026-50751: Patch the VPN Authentication Bypass
CISA added Check Point Security Gateway CVE-2026-50751 to KEV on June 8, 2026. Patch affected VPN gateways, review IKEv1 exposure, audit logs, and verify remote access.
Learn More
CISA added Check Point Security Gateway CVE-2026-50751 to KEV on June 8, 2026. Patch affected VPN gateways, review IKEv1 exposure, audit logs, and verify remote access.
Learn MoreAdvanced Custom Fields: Extended CVE-2026-8809 affects versions through 0.9.2.5. Update to 0.9.2.6 or newer, then review WordPress admin users and public user forms.
Learn MoreKirki CVE-2026-8206 affects versions 6.0.0 through 6.0.6 and is reportedly under active attack. Update to 6.0.7 or newer, then review WordPress admin accounts.
Learn MorePatch WooCommerce Custom Product Addons Pro CVE-2026-4001, verify product options, review WooCommerce orders, and inspect the site after a critical plugin update.
Learn MoreWordPress.org added a temporary 24-hour cooldown before plugin and theme releases flow through auto-updates. Here is what site owners, agencies, and hosts should do.
Learn MoreCIFSwitch CVE-2026-46243 is a high-severity Linux local privilege escalation affecting CIFS client configurations. Patch kernels, reboot hosts, and review TrueNAS and hosting exposure.
Learn MoreCISA added SolarWinds Serv-U CVE-2026-28318 to KEV on June 5, 2026. Update to Serv-U 15.5.4 Hotfix 1 or the current fixed SolarWinds build.
Learn MorePatch CVE-2026-48837 by updating Unlimited Elements for Elementor to 2.0.9 or newer. WordPress.org currently lists version 2.0.10.
Learn MoreCISA added Mirasvit Full Page Cache Warmer CVE-2026-45247 to KEV. Magento 2 stores should update to 1.11.12 or newer, or disable the module until patched.
Learn MoreCISA added Oracle WebLogic Server CVE-2024-21182 to KEV on June 1, 2026. Patch affected WebLogic 12.2.1.4.0 and 14.1.1.0.0 systems and restrict T3/IIOP exposure.
Learn More