Second-order SQL injection flaw (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin can be exploited for ...
Threat actors are actively attempting to exploit CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in ...
A high-severity vulnerability in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to take ...
A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin could allow unauthenticated ...
Xinhang Ma and four coauthors submitted ROPE on August 27, 2026, reporting a defense framework for indirect prompt injection ...
Security researcher X1NON disclosed a reported XML tag injection jailbreak in Claude Sonnet 4.6 on June 14, 2026, alleging ...
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution.
The vulnerability, a severe SQL injection flaw with a CVSS score of 9.3, affects Sangoma Switchvox SMB Edition 8.3 (104997).
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites.
A threat actor is targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586).