CVEPostPublished
CVE-2026-54121SourTrade Malvertising Makes the Victim's Browser Assemble the Malware
A malvertising operation called SourTrade delivers no finished binary over the wire. The browser fetches a clean Bun runtime, then byte-copies attacker-supplied PE structures and bytecode into a unique Windows executable
2026-07-27
CVE-2026-32194Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers
XBOW found two unauthenticated command-injection bugs in Bing
2026-07-26
CVE-2026-32191Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers
XBOW found two unauthenticated command-injection bugs in Bing
2026-07-26
CVE-2016-3714Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers
XBOW found two unauthenticated command-injection bugs in Bing
2026-07-26
CVE-2026-6875Fastjson 1.x Zero-Day (CVE-2026-16723): Unauthenticated RCE With No Patch Available
A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath
2026-07-25
CVE-2026-16723Fastjson 1.x Zero-Day (CVE-2026-16723): Unauthenticated RCE With No Patch Available
A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath
2026-07-25
CVE-2026-50522Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2026-42533Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2022-26923Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2026-62145Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access
Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir
2026-07-23
CVE-2026-62144Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access
Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir
2026-07-23
CVE-2026-16232Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access
Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir
2026-07-23
CVE-2025-66376Russian APT Ran a Zimbra Zero-Day for Five Months, Stealing Mail, Passwords and 2FA Codes
A Russian state-backed group exploited CVE-2025-66376, a stored XSS flaw in Zimbra
2026-07-23
CVE-2026-63030CVE-2026-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation
Attackers are exploiting CVE-2026-6875, a CVSS 9.5 sandbox escape in the ServiceNow AI Platform that gives unauthenticated remote code execution and full instance compromise. Patches shipped in June; Defused Cyber caught
2026-07-22
CVE-2026-58644SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2026-56164SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2026-45659SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2026-32201SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2021-39275Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics
Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine
2026-07-20
CVE-2016-7407Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics
Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine
2026-07-20
CVE-2026-34183HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find
Okta
2026-07-18
CVE-2025-66199HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find
Okta
2026-07-18
CVE-2026-57092Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-56155Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-55040Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-55008Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-54118Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-54117Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-50661Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-20896One Header, Full Admin: Attackers Exploit Critical Auth Bypass in Gitea Docker Images
Attackers are actively exploiting CVE-2026-20896, a critical authentication bypass in official Gitea Docker images up to 1.26.2. A single spoofed X-WEBAUTH-USER header grants full impersonation of any account, including
2026-07-12
CVE-2026-55116Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-55115Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-54402Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-54400Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-50748Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-50747Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-50746Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-34910Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-34909Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-34908Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2023-24489Progress Orders Emergency Shutdown of ShareFile Storage Zone Controllers Over Unnamed Threat
Progress Software has told every ShareFile customer running a self-hosted Storage Zone Controller to power the servers down over a
2026-07-10
CVE-2026-56290CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-55255CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-53166GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-5027CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-48908CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-48282CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-46242GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-43499GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-33017CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-31431GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-21445CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-10702GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-0770CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2025-34291CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2025-3248CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-40141BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-40140BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-40139BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-40138BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-1731BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2024-12356BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-5335916-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4631616-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4611316-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4350016-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4328416-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-48558Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android
A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un
2026-07-05
CVE-2026-43074Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android
A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un
2026-07-05
CVE-2026-6688Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6687Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6686Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6685Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6684Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6683Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6682Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2025-9491Armored Likho Hits Government and Power Sector with BusySnake Stealer
A newly documented threat actor, Armored Likho, is hitting government agencies and electric power operators across Russia, Brazil, and Kazakhstan with a Python-based stealer called BusySnake. The campaign blends espionag
2026-07-03
CVE-2025-11371SharePoint RCE CVE-2026-45659 Hits CISA KEV as Attackers Exploit It in the Wild
CISA added Microsoft SharePoint Server flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The deserialization bug lets any authenticated user with Site Mem
2026-07-02
CVE-2021-29441JADEPUFFER: An AI Agent Just Ran a Ransomware Attack End to End
Sysdig says an AI agent executed a full ransomware operation with no human at the keyboard: exploiting a patched Langflow RCE, harvesting credentials, pivoting to a production MySQL/Nacos server, and encrypting 1,342 con
2026-07-02
CVE-2026-8037Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2026-46817Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2026-20245Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2024-1212Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2026-24061Backdoor.Turn Got the Headlines. convoC2 Is the Version Anyone Can Run
The DPRK
2026-06-25
CVE-2026-23111usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain
Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by
2026-06-21
CVE-2026-20253usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain
Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by
2026-06-21
CVE-2026-12569usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain
Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by
2026-06-21
CVE-2025-67038usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain
Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by
2026-06-21
CVE-2026-47729FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2026-35273Microsoft Ties Mastra AI npm Supply Chain Attack to North Korean Hackers
Microsoft has attributed a supply chain compromise of the Mastra AI agent framework
2026-06-20
CVE-2025-24472FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2024-55591FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2022-40684FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2020-12812FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2018-13382FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2018-13379FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2026-26030AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution
Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv
2026-06-19
CVE-2026-25592AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution
Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv
2026-06-19
CVE-2026-2473Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads With Nothing but a Project ID
A flaw in Google Cloud
2026-06-19
CVE-2026-47102LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2026-47101LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2026-42271LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2026-40217LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2024-20399China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years
Chinese APT group Velvet Ant compromised the Linux login layer itself—backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where ord
2026-06-14
CVE-2026-39987Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls
University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts wi
2026-06-09
CVE-2026-50752Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting
2026-06-08
CVE-2026-50751Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting
2026-06-08
CVE-2026-39218AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
2026-06-06
CVE-2026-39210AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
2026-06-06
CVE-2026-10881AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
2026-06-06
CVE-2026-42832Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-41102Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-41101Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-41100Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-21509Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
2026-06-02
CVE-2026-0257Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
2026-06-02
CVE-2025-8088Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
2026-06-02
CVE-2026-35616PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation
Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across n
2026-05-31
CVE-2026-5194Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month
Anthropic
2026-05-23
CVE-2026-42945Critical RCE Vulnerability in ChromaDB Enables Complete Server Takeover
A maximum severity vulnerability (CVSS 10.0) in ChromaDB, a widely-used vector database for AI applications, allows unauthenticated attackers to execute arbitrary code and hijack servers. Organizations running ChromaDB v
2026-05-20
CVE-2026-28517NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
2026-05-19
CVE-2026-28516NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
2026-05-19
CVE-2026-28515NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
2026-05-19
CVE-2021-34527Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published
A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available
2026-05-18
CVE-2026-44338PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure
CVE-2026-44338, a critical authentication bypass in PraisonAI
2026-05-17
CVE-2026-33825YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio
2026-05-15
CVE-2025-48804YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio
2026-05-15
CVE-2026-45321Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems
TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att
2026-05-13
CVE-2026-7482Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-44009Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44008Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44007Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44006Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44005Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43999Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43997Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-42249Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-42248Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-26956Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-26332Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24781Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24120Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24118Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-22709Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2023-37466Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-5281PamDOORa: Linux Backdoor Exploits PAM Framework for SSH Credential Theft
A new Linux backdoor called PamDOORa is being sold on Russian cybercrime forums for $1,600, targeting PAM authentication modules to steal SSH credentials and maintain persistent access. The malware represents an evolutio
2026-05-09
CVE-2026-41940PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2026-1357PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-9501PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-55182PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-48703PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-29927PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2026-33827April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-33824April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-32202April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-0625Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free
A use-after-free in Chrome
2026-05-05
CVE-2023-50224Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials
GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure.
2026-05-05
CVE-2026-9256Sixteen Researchers Found the Same NGINX Bug. CVE-2026-42533 Is What AI-Assisted Discovery Looks Like.
F5 patched a critical NGINX heap overflow in the map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. That is what open-source review looks like now AI lowered
CVE-2026-50012Squidbleed: A 1997 Squid Proxy Bug Leaks Other Users' Cleartext HTTP Requests
A 29-year-old heap over-read in the Squid web proxy, dubbed Squidbleed (CVE-2026-47729), lets any permitted proxy user leak another user
CVE-2026-20182Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici
CVE-2026-20127Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici
CVE-2026-15410Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0
SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added
CVE-2026-15409Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0
SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added
CVE-2025-61882Oracle E-Business Suite CVE-2026-46817 Under Active Attack: Patch Now
A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are af
CVE-2024-36401SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2024-21762SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2023-46747SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2023-32315SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2023-20198SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2022-41082SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2022-27925SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2021-36260SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2021-27076SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2021-26855SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
CVE-2018-0171FSB Center 16 Is Still Looting Cisco Routers With a 2018 Bug: Inside the 11-Nation Advisory
NSA, FBI, CISA and 15 partner agencies across eight allied nations published joint guidance on Russian FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, who have been harvesting configs from internet-expo
CVE-2016-4437SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky