📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Information Technology CRITICAL 50m Global vulnerability Software and Technology HIGH 1h Global vulnerability Software and Cloud Services CRITICAL 1h Global phishing Artificial Intelligence and Email Security HIGH 1h Global phishing Email and Communications CRITICAL 2h Global vulnerability Enterprise Software / E-commerce CRITICAL 3h Global supply_chain Software Development and Technology CRITICAL 3h Global vulnerability Information Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 50m Global vulnerability Software and Technology HIGH 1h Global vulnerability Software and Cloud Services CRITICAL 1h Global phishing Artificial Intelligence and Email Security HIGH 1h Global phishing Email and Communications CRITICAL 2h Global vulnerability Enterprise Software / E-commerce CRITICAL 3h Global supply_chain Software Development and Technology CRITICAL 3h Global vulnerability Information Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 50m Global vulnerability Software and Technology HIGH 1h Global vulnerability Software and Cloud Services CRITICAL 1h Global phishing Artificial Intelligence and Email Security HIGH 1h Global phishing Email and Communications CRITICAL 2h Global vulnerability Enterprise Software / E-commerce CRITICAL 3h Global supply_chain Software Development and Technology CRITICAL 3h Global vulnerability Information Technology HIGH 3h Global vulnerability Information Technology HIGH 4h Global vulnerability Information Technology CRITICAL 4h
📅 Daily Security Digest — Wednesday, June 10, 2026

🇸🇦 Saudi Cyber Daily Digest

All security vulnerabilities, threats, and news aggregated today from trusted sources — continuously updated

Wednesday, June 10, 2026
12 CVEs Today
5 Threats Today
0 News Today
🛡 Security Vulnerabilities (CVE)
12 vulnerabilities
CVE-2026-5411
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
03:18 KSA
HIGH CVSS 8.8 CWE-434
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the l…
CVE-2026-5415
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
03:18 KSA
HIGH CVSS 8.8 CWE-288
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a no…
CVE-2026-7654
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version
03:18 KSA
HIGH CVSS 8.8 CWE-502
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `unserialize()` without an `allowed_classes` restriction in the `IdsToCollection::get_ids_from_string()`…
CVE-2026-46246
In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for e
03:18 KSA
HIGH CVSS 7.8 CWE-416
In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `extcon` handle, means that the `…
CVE-2026-46267
In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein
03:18 KSA
HIGH CVSS 7.8 CWE-416
In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit() purges SHDLC skb queues and frees the llc_shdlc structure while its timers and state machine work may still be active. Timer call…
CVE-2026-9290
WP User Manager LFI Vulnerability - Unauthenticated PHP Code Execution
03:18 KSA
HIGH CVSS 7.5 CWE-22
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute a…
CVE-2026-11435
Jinher OA 1.0 SQL Injection in nextselectplan.aspx httpOID Parameter
03:18 KSA
HIGH CVSS 7.3 CWE-74
A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be…
CVE-2026-11437
go-fastdfs-web SSRF Vulnerability in Installation Endpoint
03:18 KSA
HIGH CVSS 7.3 CWE-918
A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The ex…
CVE-2026-7537
MDJM Event Management WordPress Plugin Arbitrary File Upload RCE
03:18 KSA
HIGH CVSS 7.2 CWE-434
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes…
CVE-2026-8438
AIOS WordPress Plugin Stored XSS in Debug Logs (CVE-2026-8438)
03:18 KSA
HIGH CVSS 7.2 CWE-79
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the colum…
CVE-2026-8901
Freshsales Integration Plugin Stored XSS via Form Submission Data
03:18 KSA
HIGH CVSS 7.2 CWE-79
The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output es…
CVE-2026-9851
Booking Package WordPress Plugin Privilege Escalation via Account Takeover
03:18 KSA
HIGH CVSS 7.2 CWE-639
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only valid…
⚠️ Threat Intelligence
5 threats
rss:Dark Reading
04:49 KSA
HIGH vulnerability
Blame AI: Patch Tuesday Hits Record 206 CVEs Microsoft released a record 206 CVE patches in a single Patch Tuesday cycle, driven by AI-accelerated vulnerability discovery processes. This trend indicates that organizations will face increasingly voluminous securi…
rss:Dark Reading
04:49 KSA
CRITICAL phishing
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address A vulnerability dubbed 'Ghost-Sender' in Microsoft Exchange Online and on-premises hybrid configurations allows attackers to spoof email addresses by exploiting third-party mail servers or spam filte…
rss:Krebs on Securit
04:49 KSA
CRITICAL vulnerability
A Record-Breaking Patch Tuesday for June 2026 Microsoft released approximately 200 security patches across Windows operating systems and supported software in June 2026, marking a record number of fixes in a single Patch Tuesday cycle. Nearly 36 vulnerabilities …
rss:BleepingComputer
04:49 KSA
CRITICAL vulnerability
ServiceNow discloses security incident exposing customer data ServiceNow disclosed a security incident where attackers exploited an unauthenticated API endpoint vulnerability to access customer data from multiple instances. The vulnerability allowed unauthorized…
rss:BleepingComputer
04:49 KSA
HIGH phishing
OpenClaw AI agent found falling for phishing attacks, spills user data Security researchers demonstrated that OpenClaw AI email agent is vulnerable to phishing attacks, successfully extracting user data through social engineering tactics commonly used against hu…
📰 Cybersecurity News
0 articles
📰 No news aggregated today yet

This digest is updated automatically every day — Last updated: Wednesday, June 10, 2026
CVE Archive · Threats · News

📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.