Security news.
Active exploitation of web application vulnerabilities headlines today's brief, with critical flaws under attack in Roundcube Webmail alongside fresh CISA additions impacting WSO2 and Adobe Commerce. High-impact compromises also surfaced across the cryptocurrency sector and enterprise platforms, alongside emerging security risks in AI agent integrations and container architectures. IT and security teams should prioritize patching internet-facing email and e-commerce infrastructure immediately.
Roundcube Webmail Pre-Auth SQLi Actively Exploited
Attackers are actively targeting CVE-2026-48842, a high-severity pre-authentication SQL injection vulnerability in Roundcube's virtuser_query plugin affecting versions prior to 1.6.16 and 1.7.1.
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA issued an urgent patching mandate following wild exploitation of CVE-2026-5430, a critical WSO2 path traversal flaw, and CVE-2026-71362, an authorization bypass affecting Adobe Commerce and Magento.
North Korean Hackers Steal $351.6M in Bitget Breach
Cryptocurrency exchange Bitget reported a backend server intrusion resulting in the unauthorized transfer of over $351 million in digital assets from hot and warm storage wallets.
Salesforce Agentforce 'SalesBleed' Flaws Enable Zero-Click Exfiltration
A trio of vulnerabilities in Salesforce's Agentforce system allow threat actors to hijack autonomous AI agents, smuggle instructions across enterprise apps, and exfiltrate internal data.
Cloudflare Resolves Cross-Tenant Container Disk Leak
A discovered isolation vulnerability in Cloudflare Containers allowed tenants to read remnants of unallocated disk data left behind by other customers on shared hardware.
Unpatched Flaws Allow Zero-Permission Root on OnePlus Devices
Researchers chained two vendor-specific software vulnerabilities affecting OxygenOS on OnePlus and OPPO devices, permitting any standard app to obtain root privileges without requesting special permissions.
Carbonato Botnet Exploits Exposed Docker Hosts via AI Agents
Threat actors are actively hunting exposed Docker daemons to deploy the Carbonato malware, which installs the Hermes AI agent framework to gain automated host persistence and control.