CVEPostPublished
CVE-2026-87639Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-87628Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-87527Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-87491Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-87488Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-87464Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-87438Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-85880Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days
Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running
2026-09-09
CVE-2026-85046Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days
Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running
2026-09-09
CVE-2026-60004Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days
Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running
2026-09-09
CVE-2026-5281Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-3910Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-3909Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-2441Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-19490Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2026-11645Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36
Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend
2026-09-09
CVE-2023-49105Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days
Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running
2026-09-09
CVE-2026-75650StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell
Adobe patched a CVSS 10.0 unauthenticated RCE in Adobe Commerce and Magento Open Source that attackers had been exploiting since September 4, 2026. One managed store was compromised 50 minutes after the first confirmed e
2026-09-08
CVE-2026-72718Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells
Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository
2026-09-03
CVE-2026-71963Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells
Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository
2026-09-03
CVE-2026-55607Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells
Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository
2026-09-03
CVE-2026-19592Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells
Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository
2026-09-03
CVE-2022-24346Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells
Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository
2026-09-03
CVE-2021-43891Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells
Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository
2026-09-03
CVE-2013-4786Fire Ant Turns Cisco IOS XR Routers Into Credential Traps and Kills the Logs
A China-nexus actor tracked as Fire Ant moved from VMware hypervisors into Cisco IOS XR routers, TACACS+ servers, and Linux jump hosts. It captured traffic, stole plaintext credentials with a previously undocumented tac_
2026-09-01
CVE-2026-74820Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection
ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite
2026-08-30
CVE-2026-6876Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection
ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite
2026-08-30
CVE-2026-6875Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection
ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite
2026-08-30
CVE-2026-18886Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection
ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite
2026-08-30
CVE-2026-18885Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection
ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite
2026-08-30
CVE-2026-66384ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records
A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w
2026-08-28
CVE-2026-53362ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records
A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w
2026-08-28
CVE-2026-21962ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records
A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w
2026-08-28
CVE-2026-18963PaperCut Zero-Day Under Active Exploitation Hits Every NG and MF Version
PaperCut confirmed attackers are exploiting an unpatched flaw affecting all versions of PaperCut NG and MF, with confirmed customer compromises already reported. An emergency patch exists only for v25 and v26, and the ve
2026-08-28
CVE-2024-28000ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records
A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w
2026-08-28
CVE-2023-27350PaperCut Zero-Day Under Active Exploitation Hits Every NG and MF Version
PaperCut confirmed attackers are exploiting an unpatched flaw affecting all versions of PaperCut NG and MF, with confirmed customer compromises already reported. An emergency patch exists only for v25 and v26, and the ve
2026-08-28
CVE-2026-75604Next.js Ships Two Unauthenticated RCE Fixes: Windows Path Traversal and an AVIF Heap Overflow
Vercel patched two critical Next.js bugs on August 25, 2026, both ending in unauthenticated remote code execution. CVE-2026-75604 is a CVSS 9.0 path traversal with no workaround on Windows-hosted servers, and a CVSS 9.5
2026-08-27
CVE-2026-19478Critical Gitea RCE Under Active Exploitation: CVE-2026-60004 Turns a Signup Form Into Shell Access
CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog with a federal patch deadline of August 28, 2026. The CVSS 9.8 flaw lets anyone with repository write access plant a Git hook through Gitea
2026-08-26
CVE-2026-1731FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2025-31161FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2024-9380FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2024-8963FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2024-8190FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2024-24919FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2023-22515FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2021-44228FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2021-26855FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2020-5902FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2019-19781FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2019-10068FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2018-13379FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers
The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm
2026-08-26
CVE-2020-2551Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February
CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline.
2026-08-25
CVE-2020-14883Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February
CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline.
2026-08-25
CVE-2020-14882Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February
CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline.
2026-08-25
CVE-2017-10271Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February
CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline.
2026-08-25
CVE-2026-69836Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins
A CVSS 9.1 state validation bug in Keycloak
2026-08-24
CVE-2026-61979miniOrange SAML SSO Auth Bypass Chained in Live WordPress Attacks
Attackers are chaining CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML 2.0 Single Sign On plugin for WordPress to forge SAML responses and log in as administrators. Fixes shipped in July, but the vendor advisory
2026-08-24
CVE-2026-15981miniOrange SAML SSO Auth Bypass Chained in Live WordPress Attacks
Attackers are chaining CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML 2.0 Single Sign On plugin for WordPress to forge SAML responses and log in as administrators. Fixes shipped in July, but the vendor advisory
2026-08-24
CVE-2026-15571Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins
A CVSS 9.1 state validation bug in Keycloak
2026-08-24
CVE-2026-73570GitLab CVE-2026-19478 Exploited in the Wild Days After Disclosure
A CVSS 9.4 code injection in GitLab
2026-08-22
CVE-2026-58231GitLab CVE-2026-19478 Exploited in the Wild Days After Disclosure
A CVSS 9.4 code injection in GitLab
2026-08-22
CVE-2019-6693A Hardcoded FortiOS Key From 2019 Was Still Decrypting Secrets in 7.2.3
fortitool, an open-source FortiOS firmware decryption tool, documents that the CVE-2019-6693 hardcoded config-backup key stayed live years longer than believed, and publishes the AES-256 key that replaced it in 7.4. Trea
2026-08-22
CVE-2026-68820Entra ID RCE at CVSS 10.0 Was Exploited Before Anyone Outside Microsoft Knew It Existed
Microsoft confirmed that CVE-2026-69836, a deserialization flaw in Entra ID scoring a perfect 10.0, was exploited in the wild before disclosure. The company says it is fully mitigated and no customer action is required,
2026-08-21
CVE-2026-64849Entra ID RCE at CVSS 10.0 Was Exploited Before Anyone Outside Microsoft Knew It Existed
Microsoft confirmed that CVE-2026-69836, a deserialization flaw in Entra ID scoring a perfect 10.0, was exploited in the wild before disclosure. The company says it is fully mitigated and no customer action is required,
2026-08-21
CVE-2021-24092Defender's Own BTR.sys Driver Can Delete Your EDR During Boot
Check Point Research showed how Microsoft Defender
2026-08-21
CVE-2025-66376Unauthenticated RCE in Zimbra: CVE-2026-73570 Is Being Exploited Through SMTP
CERT Polska confirmed active exploitation of CVE-2026-73570, a CVSS 8.9 command injection flaw that gives unauthenticated attackers code execution on Zimbra Collaboration servers running the optional zimbra-snmp package.
2026-08-20
CVE-2026-65400Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack
CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus
2026-08-19
CVE-2026-59310Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack
CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus
2026-08-19
CVE-2026-55040Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack
CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus
2026-08-19
CVE-2026-33824Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack
CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus
2026-08-19
CVE-2026-25939MLflow SSRF Bug Is Being Exploited to Loot Cloud Metadata Credentials Hours After Disclosure
Attackers began scanning for exposed MLflow Tracking Servers within hours of CVE-2026-64849 being assigned on August 17, 2026, and are already pulling cloud credentials out of internal metadata endpoints. A second flaw,
2026-08-18
CVE-2026-25895MLflow SSRF Bug Is Being Exploited to Loot Cloud Metadata Credentials Hours After Disclosure
Attackers began scanning for exposed MLflow Tracking Servers within hours of CVE-2026-64849 being assigned on August 17, 2026, and are already pulling cloud credentials out of internal metadata endpoints. A second flaw,
2026-08-18
CVE-2023-33831MLflow SSRF Bug Is Being Exploited to Loot Cloud Metadata Credentials Hours After Disclosure
Attackers began scanning for exposed MLflow Tracking Servers within hours of CVE-2026-64849 being assigned on August 17, 2026, and are already pulling cloud credentials out of internal metadata endpoints. A second flaw,
2026-08-18
CVE-2026-59309China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries
A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA
2026-08-17
CVE-2026-20316China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries
A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA
2026-08-17
CVE-2026-16812China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries
A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA
2026-08-17
CVE-2026-16723China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries
A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA
2026-08-17
CVE-2023-32350Attackers Shut a Polish CHP Turbine by Pivoting Through a Private Cellular APN
CERT Polska disclosed that intruders reached a Polish combined heat and power plant over the distribution operator
2026-08-11
CVE-2023-32349Attackers Shut a Polish CHP Turbine by Pivoting Through a Private Cellular APN
CERT Polska disclosed that intruders reached a Polish combined heat and power plant over the distribution operator
2026-08-11
CVE-2026-63077CSS in Email Is Now an Exploit Primitive: Six Webmail Clients Broken at Black Hat 2026
PortSwigger research presented at Black Hat USA 2026 shows email content escaping its message boundary to hijack the webmail interface itself. Attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and
2026-08-09
CVE-2026-18577Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin
Attackers exploited an unauthenticated SQL injection flaw in Metabase as a zero-day, scoring a maximum CVSS 10.0 and handing them administrator access to business intelligence instances. Six release branches are affected
2026-08-08
CVE-2023-38646Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin
Attackers exploited an unauthenticated SQL injection flaw in Metabase as a zero-day, scoring a maximum CVSS 10.0 and handing them administrator access to business intelligence instances. Six release branches are affected
2026-08-08
CVE-2026-27912Two Active Directory Bugs Turn Write Access on One Account into Domain Admin
KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-pas
2026-08-06
CVE-2026-25177Two Active Directory Bugs Turn Write Access on One Account into Domain Admin
KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-pas
2026-08-06
CVE-2021-42282Two Active Directory Bugs Turn Write Access on One Account into Domain Admin
KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-pas
2026-08-06
CVE-2017-167404,407 Rockwell PLCs Sit on the Public Internet, 22 in Cities Hit by Water Utility Attacks
Forescout
2026-08-06
CVE-2026-18556N-able N-central Auth Bypass Exploited in the Wild After First Patch Missed an Alternate Path
Attackers bypassed authentication on N-able N-central servers, took administrative control, and pivoted through Take Control into managed customer endpoints. N-able
2026-08-03
CVE-2026-32194Adform's trackpoint-async.js Was Poisoned to Rewrite Crypto Wallet Addresses on Downstream Sites
Attackers appended a clipboard-and-DOM hijacking payload to trackpoint-async.js, a tracking script Adform serves from s2.adform[.]net to customer websites. Anyone who copied or typed a Bitcoin, Ethereum, or Tron address
2026-08-02
CVE-2026-20079Cisco Ships Hotfixes for FMC Zero-Day CVE-2026-20316 as CISA Sets August 1 Deadline
Cisco confirmed active exploitation of a static-credential flaw in Secure Firewall Management Center that lets unauthenticated attackers log in as a low-privilege user. CISA added CVE-2026-20316 to the KEV catalog on Jul
2026-07-31
CVE-2025-68686Arista VeloCloud Orchestrator CVE-2026-16812: CVSS 10.0 Command Injection Under Active Attack
A maximum-severity OS command injection flaw in on-premises Arista VeloCloud Orchestrator is being exploited in the wild, giving remote attackers privileged access to the orchestrator host. CISA added CVE-2026-16812 to t
2026-07-28
CVE-2026-54121SourTrade Malvertising Makes the Victim's Browser Assemble the Malware
A malvertising operation called SourTrade delivers no finished binary over the wire. The browser fetches a clean Bun runtime, then byte-copies attacker-supplied PE structures and bytecode into a unique Windows executable
2026-07-27
CVE-2026-32191Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers
XBOW found two unauthenticated command-injection bugs in Bing
2026-07-26
CVE-2016-3714Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers
XBOW found two unauthenticated command-injection bugs in Bing
2026-07-26
CVE-2026-16232Fastjson 1.x Zero-Day (CVE-2026-16723): Unauthenticated RCE With No Patch Available
A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath
2026-07-25
CVE-2026-50522Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2026-42533Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2026-20896Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2022-26923Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121)
Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller
2026-07-24
CVE-2026-62145Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access
Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir
2026-07-23
CVE-2026-62144Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access
Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir
2026-07-23
CVE-2026-63030CVE-2026-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation
Attackers are exploiting CVE-2026-6875, a CVSS 9.5 sandbox escape in the ServiceNow AI Platform that gives unauthenticated remote code execution and full instance compromise. Patches shipped in June; Defused Cyber caught
2026-07-22
CVE-2026-58644SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2026-56164SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2026-45659SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2026-32201SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request
A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone
2026-07-21
CVE-2021-39275Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics
Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine
2026-07-20
CVE-2016-7407Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics
Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine
2026-07-20
CVE-2026-60137WP2Shell: Pre-Auth RCE in WordPress Core (CVE-2026-63030) Puts Sites One Request From a Shell
CVE-2026-63030,
2026-07-18
CVE-2026-34183HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find
Okta
2026-07-18
CVE-2025-66199HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find
Okta
2026-07-18
CVE-2026-57092Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-56155Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-55008Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-54118Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-54117Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-50661Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited
Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res
2026-07-17
CVE-2026-9256Sixteen Researchers Found the Same NGINX Bug. CVE-2026-42533 Is What AI-Assisted Discovery Looks Like.
F5 patched a critical NGINX heap overflow in the map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. That is what open-source review looks like now AI lowered
2026-07-15
CVE-2026-42945Sixteen Researchers Found the Same NGINX Bug. CVE-2026-42533 Is What AI-Assisted Discovery Looks Like.
F5 patched a critical NGINX heap overflow in the map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. That is what open-source review looks like now AI lowered
2026-07-15
CVE-2026-15410Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0
SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added
2026-07-15
CVE-2026-15409Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0
SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added
2026-07-15
CVE-2018-0171FSB Center 16 Is Still Looting Cisco Routers With a 2018 Bug: Inside the 11-Nation Advisory
NSA, FBI, CISA and 15 partner agencies across eight allied nations published joint guidance on Russian FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, who have been harvesting configs from internet-expo
2026-07-13
CVE-2026-55116Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-55115Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-54402Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-54400Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-50748Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-50747Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-50746Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-34910Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-34909Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2026-34908Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection
Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA
2026-07-10
CVE-2023-24489Progress Orders Emergency Shutdown of ShareFile Storage Zone Controllers Over Unnamed Threat
Progress Software has told every ShareFile customer running a self-hosted Storage Zone Controller to power the servers down over a
2026-07-10
CVE-2026-43499GitHub 'Verified' Commits Can Be Cloned Into New Hashes Without the Signing Key
New research shows anyone can take a signed Git commit and mint a second copy with identical files, author, and a valid signature, but a different hash, and GitHub still stamps it Verified. Hash-based blocklists, dedup,
2026-07-09
CVE-2026-56290CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-55255CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-53166GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-5027CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-48908CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-48282CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-46242GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-33017CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-31431GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-21445CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-10702GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds
GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security
2026-07-08
CVE-2026-0770CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2025-34291CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2025-3248CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack
CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within
2026-07-08
CVE-2026-40141BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-40140BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-40139BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-40138BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2024-12356BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA
BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva
2026-07-07
CVE-2026-5335916-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4631616-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4611316-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4350016-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-4328416-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD
A use-after-free in Linux KVM
2026-07-06
CVE-2026-48558Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android
A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un
2026-07-05
CVE-2026-43074Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android
A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un
2026-07-05
CVE-2026-6688Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6687Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6686Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6685Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6684Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6683Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2026-6682Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak
runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e
2026-07-04
CVE-2025-9491Armored Likho Hits Government and Power Sector with BusySnake Stealer
A newly documented threat actor, Armored Likho, is hitting government agencies and electric power operators across Russia, Brazil, and Kazakhstan with a Python-based stealer called BusySnake. The campaign blends espionag
2026-07-03
CVE-2025-11371SharePoint RCE CVE-2026-45659 Hits CISA KEV as Attackers Exploit It in the Wild
CISA added Microsoft SharePoint Server flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The deserialization bug lets any authenticated user with Site Mem
2026-07-02
CVE-2021-29441JADEPUFFER: An AI Agent Just Ran a Ransomware Attack End to End
Sysdig says an AI agent executed a full ransomware operation with no human at the keyboard: exploiting a patched Langflow RCE, harvesting credentials, pivoting to a production MySQL/Nacos server, and encrypting 1,342 con
2026-07-02
CVE-2026-8037Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2026-46817Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2026-20245Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2024-1212Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now
Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr
2026-07-01
CVE-2026-35273Oracle E-Business Suite CVE-2026-46817 Under Active Attack: Patch Now
A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are af
2026-06-30
CVE-2025-61882Oracle E-Business Suite CVE-2026-46817 Under Active Attack: Patch Now
A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are af
2026-06-30
CVE-2026-20182Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici
2026-06-28
CVE-2026-20127Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici
2026-06-28
CVE-2026-12569Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici
2026-06-28
CVE-2025-67038Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric
An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici
2026-06-28
CVE-2026-20253SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2025-55182SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2024-36401SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2024-21762SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2023-46747SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2023-32315SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2023-20198SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2022-41082SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2022-40684SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2022-27925SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2021-36260SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2021-27076SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2016-4437SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs
Kaspersky
2026-06-27
CVE-2026-24061Backdoor.Turn Got the Headlines. convoC2 Is the Version Anyone Can Run
The DPRK
2026-06-25
CVE-2026-47729Fake AI Agent Skill Slipped Past Every Scanner and Reached 26,000 Agents
A security firm planted a malicious AI agent skill that passed Cisco
2026-06-23
CVE-2026-50012Squidbleed: A 1997 Squid Proxy Bug Leaks Other Users' Cleartext HTTP Requests
A 29-year-old heap over-read in the Squid web proxy, dubbed Squidbleed (CVE-2026-47729), lets any permitted proxy user leak another user
2026-06-22
CVE-2026-23111usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain
Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by
2026-06-21
CVE-2025-24472FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2024-55591FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2020-12812FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2018-13382FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed
FortiBleed isn
2026-06-20
CVE-2026-26030AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution
Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv
2026-06-19
CVE-2026-25592AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution
Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv
2026-06-19
CVE-2026-2473Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads With Nothing but a Project ID
A flaw in Google Cloud
2026-06-19
CVE-2026-47102LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2026-47101LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2026-42271LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2026-40217LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
2026-06-15
CVE-2024-20399China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years
Chinese APT group Velvet Ant compromised the Linux login layer itself, backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where or
2026-06-14
CVE-2026-39987Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls
University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate, compromising 62% of test hosts w
2026-06-09
CVE-2026-50752Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting
2026-06-08
CVE-2026-50751Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting
2026-06-08
CVE-2026-39218AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
2026-06-06
CVE-2026-39210AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
2026-06-06
CVE-2026-10881AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
2026-06-06
CVE-2026-42832Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-41102Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-41101Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-41100Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
2026-06-04
CVE-2026-21509Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
2026-06-02
CVE-2026-0257Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
2026-06-02
CVE-2025-8088Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
2026-06-02
CVE-2026-35616PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation
Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across n
2026-05-31
CVE-2026-5194Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month
Anthropic
2026-05-23
CVE-2026-28517NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
2026-05-19
CVE-2026-28516NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
2026-05-19
CVE-2026-28515NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
2026-05-19
CVE-2021-34527Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published
A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available
2026-05-18
CVE-2026-44338PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure
CVE-2026-44338, a critical authentication bypass in PraisonAI
2026-05-17
CVE-2026-33825YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio
2026-05-15
CVE-2025-48804YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio
2026-05-15
CVE-2026-45321Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems
TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att
2026-05-13
CVE-2026-7482Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-44009Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44008Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44007Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44006Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44005Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43999Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43997Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-42249Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-42248Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-26956Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-26332Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24781Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24120Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24118Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-22709Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2023-37466Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-41940PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2026-1357PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-9501PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-48703PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-29927PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2026-33827April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-32202April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-0625Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free
A use-after-free in Chrome
2026-05-05
CVE-2023-50224Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials
GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure.
2026-05-05