Skip to content

Just a Security Dude

Close Button
  • Books I’ve written
  • How to Check your Android Phone for Spyware!
  • How to Check your iPhone for Spyware!
  • Joe Seanor
Get Start

Author: Lilly

Author: Lilly

GitLab CVE-2026-85706: CVSS 10.0 Path Traversal Under Active Exploitation — Patch Now

14 September, 2026 Lilly 0 Comments Security 15:06

If your organization runs a self-hosted GitLab instance, stop what you are doing and check your version. A maximum-severity path traversal vulnerability, CVE-2026-85706 (CVSS 10.0), is being actively exploited in the wild, and the window…

Read More

Cisco FMC CVE-2026-20079 (CVSS 10.0): Qilin Ransomware and State Actors Hitting Firewall Management Consoles

11 September, 2026 Lilly 0 Comments Security 15:04

If you manage Cisco Secure Firewalls through a Firewall Management Center (FMC) appliance, stop what you're doing and check your patch status. A maximum-severity authentication bypass — CVE-2026-20079, CVSS 10.0 — is being actively exploited…

Read More

Critical Elementor Pro RCE (CVE-2026-32475, CVSS 9.0): Actively Exploited in WordPress Sites

9 September, 2026 Lilly 0 Comments Security 15:09

If you run a WordPress site with Elementor Pro, stop what you are doing and check your plugin version. A critical unauthenticated remote code execution vulnerability — tracked as CVE-2026-32475 with a CVSS score of…

Read More

Chrome Zero-Day CVE-2026-85046: Actively Exploited V8 Bug Forces Emergency Patch

7 September, 2026 Lilly 0 Comments Security 15:07

Google shipped an emergency Chrome update on September 4, 2026, to close a zero-day vulnerability that attackers are already using against real targets. If you use Chrome — and roughly 69% of the web does…

Read More

Google Chrome’s 6th Zero-Day of 2026: CVE-2026-85046 Under Active Attack

4 September, 2026 Lilly 0 Comments Security 15:06

Google has issued an emergency security update for Chrome 152, patching yet another actively exploited zero-day vulnerability. This marks the sixth Chrome zero-day of 2026, and it's being used in real-world attacks right now. If…

Read More

Critical GiveWP WordPress Plugin Flaw (CVE-2026-82222, CVSS 10.0) — Unauthenticated RCE in 100,000+ Sites

31 August, 2026 Lilly 0 Comments Security 15:02

If you run a WordPress site with the GiveWP donation plugin, patch it immediately. A maximum-severity vulnerability (CVE-2026-82222, CVSS 10.0) has been discovered that allows an unauthenticated attacker to execute arbitrary commands on your server.…

Read More

PaperCut NG/MF Zero-Day Under Active Attack: Emergency Patches Released

28 August, 2026 Lilly 0 Comments Security 15:07

If you run PaperCut print management software, stop what you are doing and read this. PaperCut has confirmed that an unpatched vulnerability in all versions of PaperCut NG and PaperCut MF is being actively exploited…

Read More

Critical Gitea RCE (CVE-2026-60004) Actively Exploited to Deploy Cryptominers

26 August, 2026 Lilly 0 Comments Uncategorized 19:20

CISA Adds Critical Gitea RCE (CVE-2026-60004) to KEV Catalog as Active Attacks Drop Cryptominers CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog. This is a CVSS 9.8 remote code execution flaw in Gitea,…

Read More

Recent Posts

  • GitLab CVE-2026-85706: CVSS 10.0 Path Traversal Under Active Exploitation — Patch Now
  • Cisco FMC CVE-2026-20079 (CVSS 10.0): Qilin Ransomware and State Actors Hitting Firewall Management Consoles
  • Critical Elementor Pro RCE (CVE-2026-32475, CVSS 9.0): Actively Exploited in WordPress Sites
  • Chrome Zero-Day CVE-2026-85046: Actively Exploited V8 Bug Forces Emergency Patch
  • Critical 10.0 RCE in Kestra OSS: What You Need to Know (CVE-2026-49869)

Recent Comments

    Archives

    • September 2026
    • August 2026
    • July 2026
    • June 2026
    • May 2026
    • May 2025

    Categories

    • Security
    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Search

    Archives

    • September 2026
    • August 2026
    • July 2026
    • June 2026
    • May 2026
    • May 2025

    Meta

    • Log in

    Categories

    • Security
    • Uncategorized

    AI Automation WordPress Theme By Themespride