CVE-2026-71384: Incorrect Authorization in Adobe ColdFusion Leading to DoS
A CVSS 9.6 incorrect authorization vulnerability in Adobe ColdFusion that could cause application denial-of-service. Fixed in versions 2025.0.12 and 2023.0.23.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
A CVSS 9.6 incorrect authorization vulnerability in Adobe ColdFusion that could cause application denial-of-service. Fixed in versions 2025.0.12 and 2023.0.23.
A CVSS 9.1 incorrect authorization vulnerability in Adobe Commerce that could lead to privilege escalation.
A CVSS 10.0 incorrect authorization vulnerability in Adobe Campaign Classic that could allow arbitrary code execution. Fixed in ACC v7 7.4.4 build…
A CVSS 10.0 incorrect authorization vulnerability in Adobe Campaign Classic that could allow arbitrary code execution. Fixed in ACC v7 7.4.4 build…
A CVSS 9.0 SQL injection vulnerability in Adobe Campaign Classic that could lead to arbitrary code execution. Fixed in ACC v7 7.4.4…
Adobe has released security updates addressing multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. The most severe include three CVSS 10.0…
A massive operation involving 737 free VPN and proxy extensions on the Chrome Web Store has been uncovered, primarily targeting Russian-speaking users…
The Picus Blue Report 2026, based on over 338 million attack simulations in production environments, reveals a split in enterprise defense effectiveness.…
A newly disclosed flaw in the way OpenAI, Anthropic, and Google handle hidden AI reasoning between API calls allowed researchers to recover…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
OpenAI has launched GPT-5.6-Cyber, a specialized cybersecurity model designed for vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol…
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
PurpleHaze is a threat cluster disclosed by SentinelOne in April 2025. It targeted a South Asian government supporting entity with a Windows…
UNC6780 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, is a security researcher who disclosed multiple Windows vulnerabilities, including CVE-2026-50656 (RoguePlanet),…
Kimwolf was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Play ransomware is a notorious ransomware family. According to the Blue Report 2026, prevention effectiveness against Play dropped from 50% to 13%,…
GoReShell is a Windows backdoor used by the PurpleHaze threat cluster. It leverages functionalities from the reverse_ssh tool to establish reverse SSH…
reverse_ssh is an open-source tool used to establish SSH connections to threat actor-controlled infrastructure. It enables outbound connections, bypassing inbound security controls.…
Cybersecurity researchers have uncovered a new version of the Kimwolf/AISURU Android and IoT botnet, tracked as Kimwolf v7, which introduces significant enhancements…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
USENIX WOOT is a security conference where the research on SIM card attacks was presented. The paper highlights the attack surface of…
The GCIH certification demonstrates proficiency in incident handling and response, often pursued after SANS SEC504 training.
EAL6+ is a high assurance level under the Common Criteria certification, indicating strong resistance to tampering. The Samsung S3D232A chip in Tangem…
The SEC660 course at SANS Network Security 2026 teaches how to leverage AI for automating tasks while maintaining deep manual understanding of…
SANS SEC504 is a training course covering hacker tools, techniques, and incident handling, leading to GCIH certification.
Chrome Web Store was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news,…
1.1.1.1 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Outline was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
This Chrome extension was removed for prompt poaching but returned with a monetization scheme. It opens affiliate links in foreground tabs on…
AdGuard VPN was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Browsec was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CyberGhost was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Windscribe was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Vultr is a cloud infrastructure provider that was used to host the fake crypto startup's infrastructure in the undercover operation. The researchers…
Gorilla Servers is a hosting provider that was used in the undercover operation to host infrastructure. The researchers noted that the operatives'…
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…
Poison Claude is an underground service selling discounted access to Anthropic's Claude models. It operates as a proxy, giving the operator full…