FILTERING BY: CLEAR FILTER

Cisco Secure Firewall ASA and FTD 0-Day Vulnerability Exploitation

CVE-2026-20349 is a critical zero-day vulnerability (CVSS 8.6) affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. The flaw originates from insufficient error checking during the processing of malformed HTTP requests, allowing unauthenticated remote attackers to trigger a complete system crash. This results in a Denial of Service (DoS) state, causing the immediate collapse of VPN connectivity and total disruption of firewall-mediated network traffic. Immediate remediation via vendor security patches is required to prevent perimeter security failure and restore operational availability.

HTTP/2 Compression Bomb Exploit Targets Apache, Nginx, and Microsoft IIS

Researchers at Calif have identified the "HTTP/2 Bomb," a synergistic denial-of-service (DoS) exploit targeting the HPACK (RFC 7541) compression mechanism and HTTP/2 flow control. The attack chain utilizes malicious header blocks to trigger massive per-entry memory allocation during decompression, followed by a Slowloris-style "hold" achieved via zero-byte flow-control windows. This prevents servers from releasing allocated resources, enabling a single client on a 100 Mbps connection to exhaust up to 32 GB of RAM within seconds. The vulnerability affects major web servers including Apache, Nginx, Microsoft IIS, Envoy, and Cloudflare Pingora, primarily due to insecure default configurations across the industry.

Critical Unauthenticated Arbitrary File Deletion in Avada Builder CVE-2026-8713

CVE-2026-8713 is a critical arbitrary file deletion vulnerability affecting the Avada Builder (Fusion Builder) WordPress plugin. The flaw enables unauthenticated remote attackers to delete arbitrary files on the host server by exploiting improper input validation and missing authorization checks within the plugin's file-handling functions. This vulnerability poses a severe risk of widespread Denial of Service (DoS) or the removal of critical security configuration files, potentially facilitating further system compromise. Given an estimated install base exceeding one million websites, immediate patching is required to mitigate the risk of large-scale exploitation.


LINK COPIED TO CLIPBOARD