Urgent.News

What's breaking now, across thousands of outlets.

Tech

GiveWP CVE-2026-82222: RCE Chain from Unauthenticated Registration to PHP Object Injection

1. Basic Information Article Title : GiveWP WordPress donation plugin flaw lets hackers execute server commands Publisher : BleepingComputer Publication Date : 2026-08-28 Original Source : BleepingComputer Related Source : Patchstack technical analysis Related Malware, Attack Groups, CVEs, Products : CVE-2026-82222, GiveWP, WordPress, TCPDF Severity : Critical 2. Executive Summary In GiveWP…

We haven't written up this one. Dev.to has the full story — the link below goes straight to it.

Read the original at dev.to →

More in Tech

Zabbix agent CVE-2026-59781: Privilege Escalation via DLL Loading During Installation

1. Basic Information Article Title : Vulnerability in Zabbix agent installer regarding incorrect file access permissions Publisher : JVN Publication Date : 2026-08-28 Original Source : JVN Related…

  • Zabbix agent versions <7.0.24 and <7.4.8 have CVE-2026-59781 vulnerability
  • Malicious DLL loaded via incorrect file access permissions during installation
  • Administrator running vulnerable installer grants privilege escalation

More from Saturday 29 August →