Security Affairs newsletter Round 572 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25769 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker architecture) and any organization with a compromised worker node (e.g., through initial access, insider threat, or supply chain attack) are impacted. An attacker who gains access to a worker node (through any means) can achieve full RCE on the master node with root privileges. Version 4.14.3 fixes the issue. NVD description · AI analysis pending | 9.1 | 9% | PoC |
| — | |
| CVE-2026-35616 | Unauthenticated Code Execution in Fortinet FortiClient EMS 7.4.5–7.4.6 Fortinet FortiClient EMS versions 7.4.5 through 7.4.6 contain an improper access control flaw (CWE-284) that allows an unauthenticated attacker to execute unauthorized code or commands by sending crafted requests over the network. The attack requires no authentication, privileges, or user interaction, making any reachable EMS management server a direct target. A successful attacker gains code execution on the EMS host, and reported campaigns have used the flaw to deploy a credential stealer. Any organization running FortiClient EMS 7.4.5 or 7.4.6 is affected. The flaw is being exploited in the wild: it was added to CISA KEV on 2026-04-06, carries a 90.7% EPSS probability of exploitation within 30 days, and Fortinet has released emergency hotfixes. Do: Upgrade FortiClient EMS off 7.4.5/7.4.6 using the fixed release or emergency hotfix per Fortinet's advisory (the available data does not specify the fixed version number), prioritizing internet-exposed servers; U.S. federal agencies must follow BOD 22-01. Until patched, restrict EMS management access to trusted networks or VPN and monitor for credential-stealer activity on managed endpoints. Given confirmed in-the-wild exploitation, assume possible compromise and hunt for indicators on both EMS hosts and endpoints it manages. | 9.8 | 91% | KEV |
| large≈10,000–100,000 EMS deployments (order-of-magnitude estimate; exact counts not in the data) |
Full article487 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
IOCTA 2026 – The evolving threat landscape: how encryption, proxies and AI are expanding cybercrime
Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
BreachForums Data Leaks: Technical Analysis and Timeline Attribution (2022–2026)
Cryptocurrency ATM giant Bitcoin Depot reports $3.6 million stolen in cyberattack
Company that supplies software for patient records attacked by hackers
Senator launches inquiry into 8 tech giants for failures to adequately report CSAM
Malware
Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2
Masjesu Rising: The Commercial IoT Botnet Built for Stealth, DDoS, and IoT Evasion
EXPMON detected sophisticated zero-day fingerprinting attack targeting Adobe Reader users
Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis
GlassWorm goes native: New Zig dropper infects every IDE on your machine
CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads
Hacking
Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
GPUBreach: Privilege Escalation Attacks on GPUs using Rowhammer
Critical Flowise Vulnerability in Attacker Crosshairs
Anthropic Claims Its New A.I. Model, Mythos, Is a Cybersecurity ‘Reckoning’
CVE-2026-25769: Critical Remote Code Execution in Wazuh via Unsafe Deserialization
Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours
Intelligence and Information Warfare
DPRK-Related Campaigns with LNK and GitHub C2
Russia’s banks face major service outages amid internet crackdown
Britons warned about Russian hackers targeting internet routers for espionage
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities
APT28 exploit routers to enable DNS hijacking operations
ICE acknowledges it is using powerful spyware
Artificial Intelligence and Foreign Information Manipulation: Chinese and Russian approaches
New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations
UK says it exposed Russian submarine activity near undersea cables
Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT
Iranian-Affiliated APT Targeting of Rockwell/Allen-Bradley PLCs
Cybersecurity
‘It’s a real shock’: quantum-computing breakthroughs pose imminent risks to cybersecurity
The political effects of X’s feed algorithm
Critical Infrastructure at Risk: 179 ICS Devices Exposed Online
ICE acknowledges it is using powerful spyware
The-broken-physics-of-remediation
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/190662/security/security-affairs-newsletter-round-572-by-pierluigi-paganini-international-edition.html