Ongoing attacks involving the high-severity path traversal flaw in the open-source Git service Gogs, tracked as CVE-2025-8110, have prompted the issue's inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, reports Security Affairs.
Coolify, an open-source self-hosting platform, has disclosed 11 critical security flaws that could allow attackers to bypass authentication, run remote code execution, and fully take over affected servers, The Hacker News reports.
The Cybersecurity and Infrastructure Security Agency has canned 10 emergency directives, issued between 2019 and 2024, after concluding they are no longer needed due to improved vulnerability tracking and remediation efforts, according to The Record, a news site by cybersecurity firm Recorded Future.
SecurityWeek reports that updates have been issued by Cisco to fix the medium-severity Identity Services Engine and ISE Passive Identity Connector flaw, tracked as CVE-2026-20029, following the release of a proof-of-concept exploit.
Trio of VMware ESXi zero-days chained long before disclosure BleepingComputer reports that attacks spreading a VMware ESXi exploit toolkit which involved a trio of zero-days that were chained more than a year before their disclosure last March have been conducted by Chinese-speaking threat actors last month.