Attackers are actively compromising self-hosted Gitea instances right now by exploiting a critical authentication bypass in the official Gitea Docker image. The flaw lets unauthenticated attackers imp
**CISA has issued a mandatory patching order for a maximum-severity vulnerability in Adobe ColdFusion**, giving federal agencies until this Friday to apply the fix — or take affected systems offline.
A critical authentication vulnerability in Oracle E-Business Suite is being actively exploited in the wild, security researchers at Defused Cyber [have confirmed](https://thehackernews.com/2026/06/ora
The U.S. Cybersecurity and Infrastructure Security Agency has added a maximum-severity remote code execution flaw in the Widget Factory **Joomla Content Editor (JCE)** plugin to its [Known Exploited V
CISA issued [Binding Operational Directive (BOD) 26-04](https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/) on June 12, ordering all feder