CVE Feed
- CVE-2026-27043 – WordPress Photography theme <= 7.7.5 – Arbitrary File Upload vulnerability March 19, 2026
- CVE-2026-32843 – Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php March 19, 2026
- CVE-2026-22558 – "UniFi Network Authenticated NoSQL Injection Vulnerability" March 19, 2026
- CVE-2026-22557 – "UniFi Network Application Path Traversal Account Access Vulnerability" March 19, 2026
- CVE-2026-4427 – Github.com/jackc/pgproto3: pgproto3: denial of service via negative field length in datarow message March 19, 2026
- CVE-2026-2369 – Libsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources March 19, 2026
- CVE-2025-71258 – BMC 20.20.02 <= 20.24.01.001 FootPrints ITSM Blind SSRF in searchWeb March 19, 2026
- CVE-2025-71259 – BMC 20.20.02 <= 20.24.01.001 FootPrints ITSM Blind SSRF in externalfeed/RSS March 19, 2026
- CVE-2025-71260 – BMC 20.20.02 <= 20.24.01.001 FootPrints ITSM VIEWSTATE Deserialization RCE March 19, 2026
- CVE-2025-71257 – BMC 20.20.02 <= 20.24.01.001 FootPrints ITSM Authentication Bypass March 19, 2026
- CVE-2026-4426 – Libarchive: libarchive: denial of service via malformed iso file processing March 19, 2026
- CVE-2026-4424 – Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing March 19, 2026
- CVE-2026-3511 – Slovensko.Digital Autogram XML External Entity SSRF Vulnerability March 19, 2026
- CVE-2026-3658 – Appointment Booking Calendar <= 1.6.10.0 – Unauthenticated SQL Injection via 'fields' Parameter March 19, 2026
- CVE-2006-10003 – XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack March 19, 2026
- CVE-2006-10002 – XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes March 19, 2026
- CVE-2025-14716 – Unauthorized access to information March 19, 2026
- CVE-2026-27068 – WordPress Website LLMs.txt plugin <= 8.2.6 – Reflected Cross Site Scripting (XSS) vulnerability March 19, 2026
- CVE-2026-27070 – WordPress Everest Forms Pro plugin <= 1.9.10 – Cross Site Scripting (XSS) vulnerability March 19, 2026
Microsoft Security
- When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures March 19, 2026In recent months, Microsoft Threat Intelligence identified email campaigns using lures around W-2, tax forms, or similar themes, or posing as government tax agencies, tax services firms, and relevant financial institutions, with many campaigns targeting individuals for personal and financial data theft, but others specifically targeting accountants and other professionals who handle sensitive documents, have […]Microsoft Threat Intelligence and Microsoft Defender Security Research Team
- Observability for AI Systems: Strengthening visibility for proactive risk detection March 18, 2026As AI systems grow more autonomous, observability becomes essential. Learn how visibility into AI behavior helps detect risk and strengthen secure development. The post Observability for AI Systems: Strengthening visibility for proactive risk detection appeared first on Microsoft Security Blog.Angela Argentati, Matthew Dressman, Habiba Mohamed and Microsoft AI Security
- New Microsoft Purview innovations for Fabric to safely accelerate your AI transformation March 16, 2026As organizations adopt AI, security and governance remain core primitives for safe AI transformation and acceleration. The post New Microsoft Purview innovations for Fabric to safely accelerate your AI transformation appeared first on Microsoft Security Blog.Darren Portillo
- Help on the line: How a Microsoft Teams support call led to compromise March 16, 2026A DART investigation into a Microsoft Teams voice phishing attack shows how deception and trusted tools can enable identity-led intrusions and how to stop them. The post Help on the line: How a Microsoft Teams support call led to compromise appeared first on Microsoft Security Blog.Microsoft Incident Response
- Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft March 12, 2026Storm-2561 uses SEO poisoning to push fake VPN downloads that install signed trojans and steal VPN credentials. Active since 2025, Storm-2561 mimics trusted brands and abuses legitimate services. This post reviews TTPs, IOCs, and mitigation guidance. The post Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft appeared first on Microsoft Security […]Microsoft Threat Intelligence and Microsoft Defender Experts



