Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
First reported
Last updated
Happening score
H score 67
1 unique sources, 1 articles

Summary

Hide ▲

Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw in versions up to and including 3.16.4 that could let unauthenticated attackers reach an administrator session on vulnerable configurations. Site owners should update to 3.16.5 or later to remove the exposure.

Related Happenings

WordPress security patch release for CVE-2026-64638

Security Patch Release
H score34 First: 07.08.2026 15:56 Last: 07.08.2026 15:56 Sources 1

About this happening: WordPress 7.0.3 shipped a security fix for CVE-2026-64638, and the release was backported through the 4.7 branch. WordPress urged operators to update immediately a...

Zoom security patch release for CVE-2026-53412

Security Patch Release
H score43 First: 15.07.2026 23:16 Last: 15.07.2026 23:16 Sources 1

About this happening: Zoom released Windows security patches covering CVE-2026-53412 and three additional flaws across Zoom Workplace, Windows VDI, Zoom Rooms, Contact Center, a...

RabbitMQ maintainers security patch release for CVE-2026-57219

Security Patch Release
H score29 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ maintainers released fixed versions for multiple supported release lines, closing two access-control flaws that could expose OAuth client secrets and cross-te...

Gitea Docker images security update (CVE-2026-20896)

Security Patch Release
H score51 First: 06.07.2026 19:28 Last: 06.07.2026 19:28 Sources 1

About this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...

Google security patch release for CVE-2026-10881

Security Patch Release
H score26 First: 06.06.2026 10:28 Last: 06.06.2026 10:28 Sources 1

About this happening: Google shipped Chrome 149 with patches for 429 security bugs, including CVE-2026-10881 in ANGLE, creating a broad browser update for users on Linux, Windows, and...

Timeline

  1. 17.08.2026 16:30 1 articles · 2h ago

    Wordfence receives vulnerability report for CVE-2026-15826 in User Profile Builder

    Initial Disclosure

    Wordfence received a vulnerability report about an authentication bypass in the User Profile Builder plugin tracked as CVE-2026-15826, exposing more than 40,000 WordPress sites to administrator-account access on vulnerable configurations.

    Show sources
  2. 17.08.2026 16:30 1 articles · 2h ago

    Wordfence validates type confusion in User Profile Builder registration flow

    Technical Analysis Update

    Wordfence validated the flaw the following day and traced it to a type confusion error in User Profile Builder’s registration and automatic-login flow, where a failed account-creation result could be converted into an integer and treated as user ID 1, allowing an attacker to obtain an administrator session when the affected site used that configuration.

    Show sources
  3. 17.08.2026 16:30 2 articles · 2h ago

    Cozmoslabs releases User Profile Builder 3.16.5 to fix CVE-2026-15826

    Mitigation Patch Update

    Cozmoslabs acknowledged the report and released User Profile Builder version 3.16.5 to address CVE-2026-15826, with affected site owners advised to update to version 3.16.5 or later to remove the vulnerable code path.

    Show sources