theinfosecnews
CISA KEVCVE-2026-35616CVE-2026-3502CVE-2026-5281CVE-2026-3055CVE-2025-53521CISA KEVCVE-2026-35616CVE-2026-3502CVE-2026-5281CVE-2026-3055CVE-2025-53521
V
vulnerability

Critical Vulnerability Found in Ninja Forms File Uploads Add-On for WordPress

A critical vulnerability has been discovered in the Ninja Forms File Uploads add-on for WordPress. This flaw allows unauthenticated file upload, leading to potential remote code execution. Users are urged to update their systems immediately.

BleepingComputer·1h ago·3 min read
Read full story
Allvulnerability124policy34breach21malware19apt16ransomware13
Vvulnerability

CVE-2026-39329: High-Risk SQL Injection in ChurchCRM

CVE-2026-39329 is an SQL injection vulnerability in ChurchCRM versions prior to 7.1.0. Exploited via the newEvtTypeCntLst parameter, it allows authenticated users with AddEvent privileges to manipulate SQL queries. Upgrade to version 7.1.0 or later to mitigate.

NVD·4h ago·3 min read
Aapt

Russian APT28 Exploits Router Vulnerabilities for Massive Token Harvesting

The Forest Blizzard APT group exploits vulnerabilities in outdated routers to intercept Microsoft Office user tokens. Over 18,000 networks are affected due to DNS hijacking without deploying traditional malware. Swift security updates and DNS configurations are necessary to mitigate risks.

Krebs on Security·6h ago·3 min read