Today's Top Cybersecurity News – February 13, 2026
1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites
A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited.
Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord
https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/
2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover
A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution.
Sources: Cvefeed, Microsoft
https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/
3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal
A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2019-25335
4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access
CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks.
Sources: Cvefeed, Feedburner, Securityaffairs
https://cvefeed.io/vuln/detail/CVE-2024-50619
5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices
Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks.
Sources: Cvefeed
https://cvefeed.io/vuln/detail/CVE-2026-25084
Stay sharp. Stay secure.
#NerdieNews#InfoSec#CyberSecurity#TechNews#DataSecurity#CyberThreats
Post summary
The post reports several critical vulnerabilities across various software, providing technical details and emphasizing immediate patching, with no evidence of active exploitation or PoC.
CVE-2026-24789
Unauthenticated Remote Password Change Vulnerability in Target Device API
https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24789
Post summary
The text announces CVE‑2026‑24789 as an unauthenticated remote password change vulnerability in a target device API and directs readers to a vulnerability details page.
CVE-2026-24789 An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. https://www.cve.org/CVERecord?id=CVE-2026-24789
Post summary
The CVE identifies an unprotected API endpoint that lets an attacker remotely change a device password without any authentication.
🔴 CVE-2026-24789 - Critical
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
https://www.thehackerwire.com/vulnerability/CVE-2026-24789/ https://t.co/GIY3iIKAFN
Post summary
CVE-2026-24789 exposes an unprotected API endpoint that lets attackers change device passwords without authentication, posing a critical security risk.
🚨 CISA Warns: Critical ZLAN5143D ICS Bugs Allow Full Device Takeover (CVSS 9.8)
CISA advisory ICSA-26-041-02 flags two critical ZLAN5143D serial-to-Ethernet flaws—CVE-2026-25084 (missing auth) and CVE-2026-24789 (auth bypass/password reset)—that enable unauthenticated remote admin control on firmware v1.600. This matters because these devices often bridge IT/OT in manufacturing, so compromise can become a lateral-movement pivot into control networks; isolate from the internet, segment OT, and patch/monitor immediately.
🎯 Target: Global/Manufacturing & ICS/OT
#️⃣ Category: #Vulnerability#BlueTeam#CyberIntel
🔗 URL: https://cyberpress.org/zlan-ics-flaws/
Post summary
CISA issued a warning about two critical ZLAN5143D flaws that allow unauthenticated remote administration, urging immediate patching and network isolation.
[CVE-2026-24789: CRITICAL] An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.#cve,CVE-2026-24789,#cybersecurity https://cvefind.com/CVE-2026-24789
Post summary
The post discloses CVE‑2026‑24789, a critical vulnerability enabling unauthenticated device password changes via an unprotected API endpoint; no PoC, exploit, or patch details are provided.