CVE-2026-8778: Unauthenticated file upload in WooCommerce plugin
CVE-2026-8778 affects MIPL Grouped Checkout Fields for WooCommerce up to and including 1.2.1.
Read ArticleCurrent security alerts, regulatory guidance and practical knowledge for well-founded cyber risk decisions.
CVE-2026-8778 affects MIPL Grouped Checkout Fields for WooCommerce up to and including 1.2.1.
Read Article
CVE-2026-78509 affects multiple Microsoft Office products and has a CVSS score of 9.8.
Read Article
Microsoft is releasing security updates for CVE-2026-69356 and CVE-2026-69641 in Exchange Server.
Read Article
CVE-2026-82067 can cause MongoDB Server authorization to remain disabled upon startup.
Read Article
Three OAuth2 vulnerabilities affect XenForo before 2.3.13. XenForo 2.3.13 includes security fixes for CVE-2026-73309, CVE-2026-73311, and CVE-2026-73312.
Read Article
CVE-2026-67276 affects SSH key verification in MikroTik RouterOS. Security updates are available.
Read Article
CVE-2026-84238 affects YITH Request a Quote for WooCommerce Premium prior to version 4.46.0. Patchstack recommends updating to version 4.46.0 or later.
Read Article
CVE-2026-62911 affects local Microsoft Exchange servers. Microsoft is providing security updates for Exchange Server SE RTM, as well as ESU updates for older versions.
Read Article
CVE-2026-16947 affects the WordPress plugin "Total Processing Card Payments for WooCommerce" and allows SSRF.
Read Article
The Spring Batch release dated August 20, 2026, contains three vulnerabilities in the Spring Framework. Affected applications should upgrade to newer versions.
Read Article
CVE-2026-55634 and CVE-2026-55220 affect Pimcore. Fixes are available for three version series.
Read Article
CVE-2026-81934 affects Redis instances configured with TLS. Fixed releases are available for several Redis branches.
Read Article
CVE-2026-32475 (Elementor Pro ≤4.2.1), CVE-2026-66592 (rtMedia ≤4.7.11) and CVE-2026-78003 (Mailgun ≤2.2.0): PHP upload, SQL injection, and SSRF. Patches are partially available.
Read Article