Alerts

Below, you have the information of all bulletins and alerts we have found from our threat observatory.

Affected product(s): Product Affected versions Fixed version Elementor Website Builder for WordPress 4.3.0 and 4.3.1 4.3.2 or later Elementor Pro Not directly part of this advisory Validate and apply their

Affected product(s): Product Affected versions Fixed version WordPress Core 7.1.0–7.1.1 7.1.2 or higher WordPress Core 7.0.x 7.0.6 or higher WordPress Core 6.9.x 6.9.9 or higher WordPress Core 6.8.x 6.8.10 or

Affected product(s): OVERPASS affects SAP software that uses the vulnerable SAP Kernel code, so the scope may include a significant proportion of SAP landscapes: SAP product / component Possible impact

Affected product(s): Oracle identifies these supported versions as affected: Product Component Affected versions Oracle WebLogic Server Core 12.2.1.4.0 Oracle WebLogic Server Core 14.1.1.0.0 Oracle WebLogic Server Core 14.1.2.0.0 Oracle WebLogic

Affected product(s): Product Affected versions Fixed version Splunk Enterprise 10.0.0 to 10.0.6 10.0.7 or later Splunk Enterprise 10.2.0 to 10.2.3 10.2.4 or later Splunk Enterprise 10.4 Not affected Splunk Cloud

Affected product(s): Product Affected versions Fixed version WordPress Core WordPress 6.0 up to versions prior to the corresponding security patch WordPress 7.1.1 or equivalent security update for the supported branch

Affected product(s): Product / component Status Check Point Security Management Server Affected Check Point Multi-Domain Security Management Server Affected Check Point Log Server Affected Check Point Multi-Domain Log Server Affected

Affected product(s): Product CVE Affected versions Fixed version The Events Calendar for WordPress CVE‑2026‑78159 Up to 6.17.3, inclusive 6.17.3.1 or later The Events Calendar for WordPress CVE‑2026‑78006 Up to 6.17.4,

Affected product(s): The vulnerability affects Cisco ISE and Cisco ISE‑PIC, regardless of device configuration. Cisco has published fixes for the following supported branches: Product Affected Branch Minimum Fixed Version Cisco

Affected product(s): Product / service Vulnerability Impact Status Cisco Secure Firewall Management Center (FMC) Software CVE‑2026‑20079 Authentication bypass and remote execution of scripts/commands as root Confirmed active exploitation Cisco Secure

Affected product(s): The vulnerability affects implementations of Windows DNS Server on supported Windows Server systems, including Windows Server 2012 and later versions, as well as certain versions of Windows 10

Affected product(s): Product Affected versions Fix Adobe Commerce 2.4.4‑2026‑aug, 2.4.5‑2026‑aug, 2.4.6‑2026‑aug, 2.4.7‑2026‑aug, 2.4.8‑2026‑aug, 2.4.9‑2026‑aug and earlier Apply VULN‑39341 hotfix corresponding to the installed version Adobe Commerce B2B 1.3.3‑2026‑aug, 1.3.4‑2026‑aug, 1.4.2‑2026‑aug,

Affected product(s): Product Affected range Minimum fixed version MikroTik RouterOS 6 6.0.0 up to before 6.49.21 6.49.21 MikroTik RouterOS 7 Long-term 7.0.0 up to before 7.23.4 7.23.4; 7.23.5 is recommended

Affected product(s): Product Affected versions Fixed version All-in-One WP Migration and Backup for WordPress All versions up to 7.109, inclusive 7.110 or later Description A second-order SQL injection vulnerability was

Affected product(s): CrowdStrike Falcon Sensor — Endpoint security platform (EDR) Product Vulnerable configuration Operating system CrowdStrike Falcon Sensor Phase 3 — Optimal Protection with “Microsoft Office file malicious macro removal”

Affected product(s): cPanel/WHM: all supported versions prior to: o 11.110.0.141 o 11.134.0.53 o 11.136.0.37 o 11.138.0.2 WP² (WP Squared): o versions prior to 11.138.1.7 Description On August 27, 2026, cPanel

Affected product(s): The three CVEs affect ServiceNow AI Platform. Instances running versions prior to the following patches within their release family must be updated: Description ServiceNow reported and fixed three

Affected product(s): Description Recently, a vulnerability identified as CVE-2026-75604 has been published in Next.js, a React framework used to develop server-rendered web applications. The flaw is classified as critical, with

Affected product(s): Description Recently, Microsoft disclosed vulnerability CVE-2026-62911, reported by Orange Tsai from the DEVCORE Research Team, in Microsoft Exchange Server, an on-premises email, calendar, and enterprise collaboration platform. The

CISA has once again added CVE-2026-21962 to its catalog of actively exploited vulnerabilities, confirming attacks against vulnerable instances of Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The flaw,

Affected product(s): Description NetScaler released a security update to address CVE-2026-8452 (CVSS 9.8), a Memory Overflow vulnerability affecting NetScaler ADC and NetScaler Gateway. The vulnerability may cause unpredictable or faulty

Affected product(s): Description A security vulnerability identified as CVE-2026-17106, named CopyEscape, has been disclosed that affects the mechanism used by Docker to copy files from a container to the systemAdobe

Description A phishing and social engineering campaign targeting users in Mexico has been identified, using a supposed “payment receipt” and documentation that appears to be related to the Tax Administration

Affected Product(s): WordPress Core — Content Management System (CMS) Product Affected Versions Fixed Version WordPress All versions (from 4.7 onwards) 7.0.3 WordPress 6.9.x branch 6.9.6 WordPress 4.7 – 6.8.x branches

Affected product(s): Django — High-level Python web framework Version Status Django main (development branch) Vulnerable Django 6.1 (release candidate) Vulnerable Django 6.0 (up to 6.0.7) Vulnerable Django 5.2 (up to

Affected product(s): Description CVE‑2026‑16347 (CVSS 8.8 – High) has been published in MikroTik RouterOS and Cloud Hosted Router: an authentication flaw with no effective rate limiting that allows an attacker

Affected product(s): Description The CISO team confirmed on August 5, 2026 the active exploitation of CVE‑2026‑34486 in Apache Tomcat, a missing encryption flaw in the clustering component that is being

Affected product(s): • cPanel & WHM – all supported versions prior to the fix builds• WP Squared – all versions prior to 138.1.6 Description A critical vulnerability has been disclosed

Affected Product(s): Cisco Secure Firewall Management Center (FMC) Software Description Recently, the Cisco Product Security Incident Response Team (PSIRT) disclosed vulnerability CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC), the

Affected product(s): 9.1.x (fixed in 9.1.0.0300) 9.0.x (fixed in 9.0.2.0100) 8.0.x (fixed in 8.0) 7.0.x (affected; fixes will only be available for customers with an Extended Support contract). 9.1.x (fixed