Latest Cybersecurity Threats
Security Threats Are Everywhere
Cybersecurity threats are constantly evolving, putting businesses of all sizes at risk of data breaches, ransomware attacks, and operational disruptions. For organizations in Buffalo, New York, and surrounding areas, staying informed about these threats is not just important—it’s essential. Protecting your data means protecting your business, your clients, and your reputation.
Below you’ll find links to the latest security alerts and vulnerabilities that could impact your business. From newly discovered software exploits to ongoing phishing scams, these insights can help you understand the risks and take proactive measures. In today’s digital age, no organization can afford to overlook cybersecurity. Make sure your defenses are robust and up to date to ensure your data—and your business—stay safe.
View Recent Security Threats
- CVE-2026-87935 - Paid Downloads
- CVE-2026-87796 - Multi Uploader for Gravity Forms
- CVE-2026-25283 - Stack-based Buffer Overflow in OOBM
- CVE-2026-61599 - djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
- CVE-2026-92593 - Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution
- CVE-2026-92592 - Craft CMS before 4.18.6 Remote Code Execution via signed cookie
- CVE-2026-92594 - Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
- CVE-2026-92596 - Nodemailer before 9.1.0 Denial of Service via addressparser
- CVE-2026-92597 - Nodemailer before 9.1.0 Email Domain Validation Bypass via RFC 5322 Comment
- CVE-2026-92598 - Nodemailer before 9.1.0 IDN/Punycode Domain Allow-list Bypass
- CVE-2026-92599 - Joi before 17.13.7 and 18.2.6 ReDoS via isoDate
- CVE-2026-92591 - Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
- CVE-2026-92578 - WWBN AVideo through 29.0 Authentication Bypass via Stored Password Hash
- CVE-2026-92580 - AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF
- CVE-2026-85469 - Quay-builder-qemu: quay-builder-qemu: release workflow uses third-party action pinned to mutable @master with registry credentials in scope
- Multiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code Execution
- Multiple Vulnerabilities in Mikrotik Routers Could Allow for Admin Hijacking
- A Vulnerability in GitLab Could Allow for Disclosure of Sensitive Data
- Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code Execution
- A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
- Critical Patches Issued for Microsoft Products, September 8, 2026
- Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in SonicWall SMA1000 Series Appliances Could Allow for Remote Code Execution
- Multiple Vulnerabilities in PaperCut Products Could Allow for Remote Code Execution
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in SonicWall GMS Could Allow for Remote Code Execution
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
- A Vulnerability in Zoom Clients Could Allow for Remote Code Execution
- Critical Patches Issued for Microsoft Products, August 11, 2026
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
- A Vulnerability in VeloCloud Orchestrator (VCO) On-Prem Could Allow for Remote Code Execution
- A Vulnerability Chain in WordPress Core Could Allow for Remote Code Execution
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
Secure Your Business Today!
Contact LACyber today to schedule a consultation and take the first step towards building a more secure, resilient digital infrastructure for your business.
Protect Your Business Today
You're just minutes away from securing your sensitive business data and protecting your employees!
"*" indicates required fields
TAKE OUR CYBER SECURITY QUIZ
Take our short quiz to see where your organization’s cyber security policies are keeping you safe.
RECENT THREATS
No feed items found.
OUR TRUSTED PARTNERS
CONTACT YOUR LOCAL WNY DATA PROTECTION EXPERTS TODAY!
Fill out your information to the right and we’ll be in touch to help you secure your business and teams critical data.
155 Great Arrow
Buffalo, NY 14207
United States
Phone: +1 716-325-4740
Email: info@LACyber.com
"*" indicates required fields