CVEPostPublished
CVE-2026-33825Nightmare-Eclipse Toolkit Deployed 8 Days After Public Release — FortiGate Intrusion Analysis
A threat actor gained access via compromised FortiGate SSL VPN credentials and deployed three publicly available Nightmare-Eclipse privilege escalation tools just eight days after release. A previously undocumented Go-ba
2026-05-11
CVE-2026-7482Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-44009Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44008Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44007Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44006Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44005Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43999Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43997Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-42249Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-42248Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-26956Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-26332Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24781Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24120Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24118Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-22709Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2023-37466Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-1357PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-9501PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-55182PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-48703PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-29927PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2026-5281Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free
A use-after-free in Chrome
2026-05-05
CVE-2026-41940cPanel Was Being Exploited for Two Months Before a Patch Existed (CVE-2026-41940)
An auth bypass in cPanel/WHM was exploited as a zero-day from February 23 to April 28, compromising 44,000+ servers before a patch existed. 1.5 million servers remain at risk.
2026-05-05
CVE-2026-33827April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-33824April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-32202April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-31431Copy Fail: The 732-Byte Python Script That Roots Every Major Linux Distro
A 9-year-old Linux kernel bug in the AEAD crypto interface lets any local user overwrite any file
2026-05-05
CVE-2026-0625This D-Link Router Zero-Day Has Been Exploited Since November. There Is No Patch.
A command injection vulnerability in four end-of-life D-Link router models has been exploited by a Mirai variant since November 2025. D-Link confirmed no patch is coming. The only fix is hardware replacement.
2026-05-05
CVE-2023-50224Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials
GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure.
2026-05-05
CVE-2026-5194Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month
Anthropic
CVE-2026-45321Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems
TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att
CVE-2026-44338PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure
CVE-2026-44338, a critical authentication bypass in PraisonAI
CVE-2026-42945NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-28517NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-28516NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-28515NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2025-48804YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio
CVE-2021-34527Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published
A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available