Linuxsecurity Critical SOGo Vulnerabilities Affecting Multiple Ubuntu Versions
Article Content
- •SOGo vulnerabilities affect multiple Ubuntu LTS versions, including 18.04 and 26.04.
- •Critical issues include cross-site scripting and SQL injection vulnerabilities.
- •Immediate updates are necessary to mitigate risks associated with these vulnerabilities.
Recent vulnerabilities in SOGo have been identified, impacting Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, and 26.04 LTS. The issues include improper sanitization of input leading to potential cross-site scripting (CVE-2025-71276, CVE-2026-3054) and SQL injection vulnerabilities (CVE-2026-46445, CVE-2026-46446). Additionally, a flaw allows remote attackers to bypass authentication due to issues with one-time password management (CVE-2026-33550). These vulnerabilities could allow attackers to execute arbitrary code or gain unauthorized access. Users are advised to update their systems to the latest package versions to mitigate these risks. The vulnerabilities were disclosed in a security notice by Ubuntu on July 5, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2021-33054 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates Three WordPress plugins have been reported with vulnerabilities: the GiveWP plugin (version 4.16.9) has a Cross Site Scripting (XSS) vulnerability, while both the Siteskite (version 2.1.8) and Cartflows (version 3.2.0) plugins have Remote Code Execution (RCE) vulnerabilities. The XSS vulnerability allows attackers to…