Security researchers say additional flaws are being chained together and a patch will not be available until August.
Related Articles
All CyberSecurityDive →Medusa ransomware slams critical infrastructure organizations
The Medusa ransomware gang has infected more than 300 organizations in critical infrastructure sectors such as the medical, manufacturing and technology industries. That’s according to…
Emerging cybersecurity needs: What the market is telling us
The landscape of cybersecurity has undergone a dramatic transformation, moving far beyond the days of nuisance malware like the “Love Bug” or “Blaster Virus.” Cybercrime…
Critical vulnerability in SAP NetWeaver under threat of active exploitation
Security researchers warn that hackers are actively exploiting a critical unrestricted-file-upload vulnerability in SAP NetWeaver Visual Composer. The vulnerability, tracked as CVE-2025-31324, could allow an…
Fortinet FortiWeb flaws found in unsupported versions of web application firewall
Security researchers warn that two recently disclosed vulnerabilities in Fortinet FortiWeb can be exploited in attacks targeting earlier, unsupported versions of the web application firewall…
Cloudflare, Proofpoint say hackers gained access to Salesforce instances in attack spree
In separate disclosures, Cloudflare Inc. and Proofpoint Inc. on Tuesday said they were impacted by the August supply chain attacks linked to Salesloft Drift. The…
37K+ VMware ESXi instances vulnerable to critical zero-day
Dive Brief: Broadcom on Tuesday disclosed three zero-day vulnerabilities that affect multiple VMware products, including ESXi, Workstation and Fusion. The vulnerabilities have been exploited in…

