| CVE | Post | Published |
|---|---|---|
| CVE-2026-87639 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-87628 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-87527 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-87491 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-87488 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-87464 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-87438 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-85880 | Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running | 2026-09-09 |
| CVE-2026-85046 | Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running | 2026-09-09 |
| CVE-2026-60004 | Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running | 2026-09-09 |
| CVE-2026-5281 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-3910 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-3909 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-2441 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-19490 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2026-11645 | Chrome V8 Zero-Day CVE-2026-87491 Is Being Exploited: Patch to 153.0.8010.36 Google shipped fixes for 230 Chrome flaws, including CVE-2026-87491, an out-of-bounds write in the V8 engine that is already under active exploitation. A crafted HTML page gives an attacker code execution inside the rend | 2026-09-09 |
| CVE-2023-49105 | Four Espionage Groups Adopted the Same Chrome and Windows Exploit Kit in Six Days Proofpoint documented BlueMoon, an exploit kit that chains two Google Chrome V8 bugs with a Windows ALPC privilege escalation flaw. APT31 fired it first on August 28, 2026, and three more espionage clusters were running | 2026-09-09 |
| CVE-2026-75650 | StyleSmuggler: Magento Zero-Day CVE-2026-75650 Drops a Rust Backdoor and a PHP Web Shell Adobe patched a CVSS 10.0 unauthenticated RCE in Adobe Commerce and Magento Open Source that attackers had been exploiting since September 4, 2026. One managed store was compromised 50 minutes after the first confirmed e | 2026-09-08 |
| CVE-2026-72718 | Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository | 2026-09-03 |
| CVE-2026-71963 | Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository | 2026-09-03 |
| CVE-2026-55607 | Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository | 2026-09-03 |
| CVE-2026-19592 | Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository | 2026-09-03 |
| CVE-2022-24346 | Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository | 2026-09-03 |
| CVE-2021-43891 | Malicious .git Configs Turn Claude Code, Codex, and Cursor Into Attacker Shells Manifold Security disclosed eight flaws across seven command line AI coding agents where a repository | 2026-09-03 |
| CVE-2013-4786 | Fire Ant Turns Cisco IOS XR Routers Into Credential Traps and Kills the Logs A China-nexus actor tracked as Fire Ant moved from VMware hypervisors into Cisco IOS XR routers, TACACS+ servers, and Linux jump hosts. It captured traffic, stole plaintext credentials with a previously undocumented tac_ | 2026-09-01 |
| CVE-2026-74820 | Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite | 2026-08-30 |
| CVE-2026-6876 | Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite | 2026-08-30 |
| CVE-2026-6875 | Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite | 2026-08-30 |
| CVE-2026-18886 | Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite | 2026-08-30 |
| CVE-2026-18885 | Three CVSS 10.0 ServiceNow Flaws: Unauthenticated Code Execution and SQL Injection ServiceNow patched four AI Platform vulnerabilities on August 27, 2026, three of them rated CVSS 10.0 and reachable by an unauthenticated attacker over the network. The set covers code injection in the GraphQL Composite | 2026-08-30 |
| CVE-2026-66384 | ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w | 2026-08-28 |
| CVE-2026-53362 | ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w | 2026-08-28 |
| CVE-2026-21962 | ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w | 2026-08-28 |
| CVE-2026-18963 | PaperCut Zero-Day Under Active Exploitation Hits Every NG and MF Version PaperCut confirmed attackers are exploiting an unpatched flaw affecting all versions of PaperCut NG and MF, with confirmed customer compromises already reported. An emergency patch exists only for v25 and v26, and the ve | 2026-08-28 |
| CVE-2024-28000 | ownCloud Auth Bypass CVE-2023-49105 Used to Exfiltrate 372 MB of Philippine Nuclear Records A Chinese-speaking operator chained a 2023 ownCloud WebDAV authentication bypass into 176 stolen files from a Philippine nuclear research body, including reactor component data, fuel inventories, and a credential store w | 2026-08-28 |
| CVE-2023-27350 | PaperCut Zero-Day Under Active Exploitation Hits Every NG and MF Version PaperCut confirmed attackers are exploiting an unpatched flaw affecting all versions of PaperCut NG and MF, with confirmed customer compromises already reported. An emergency patch exists only for v25 and v26, and the ve | 2026-08-28 |
| CVE-2026-75604 | Next.js Ships Two Unauthenticated RCE Fixes: Windows Path Traversal and an AVIF Heap Overflow Vercel patched two critical Next.js bugs on August 25, 2026, both ending in unauthenticated remote code execution. CVE-2026-75604 is a CVSS 9.0 path traversal with no workaround on Windows-hosted servers, and a CVSS 9.5 | 2026-08-27 |
| CVE-2026-19478 | Critical Gitea RCE Under Active Exploitation: CVE-2026-60004 Turns a Signup Form Into Shell Access CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog with a federal patch deadline of August 28, 2026. The CVSS 9.8 flaw lets anyone with repository write access plant a Git hook through Gitea | 2026-08-26 |
| CVE-2026-1731 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2025-31161 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2024-9380 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2024-8963 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2024-8190 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2024-24919 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2023-22515 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2021-44228 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2021-26855 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2020-5902 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2019-19781 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2019-10068 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2018-13379 | FBI Pulls the Plug on QTFY: Eight Years of Chinese Contractor Espionage Hidden Behind Your Routers The DoJ disrupted QScan and QTRouter, two platforms run by QTFY, a Chinese state-sponsored crew employed by a Nanjing company that sells to both the MSS and the PLA. Victims include NASA, the Federal Reserve, the Departm | 2026-08-26 |
| CVE-2020-2551 | Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline. | 2026-08-25 |
| CVE-2020-14883 | Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline. | 2026-08-25 |
| CVE-2020-14882 | Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline. | 2026-08-25 |
| CVE-2017-10271 | Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February CISA added CVE-2026-21962, a maximum severity access control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to the Known Exploited Vulnerabilities catalog with a three day federal remediation deadline. | 2026-08-25 |
| CVE-2026-69836 | Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins A CVSS 9.1 state validation bug in Keycloak | 2026-08-24 |
| CVE-2026-61979 | miniOrange SAML SSO Auth Bypass Chained in Live WordPress Attacks Attackers are chaining CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML 2.0 Single Sign On plugin for WordPress to forge SAML responses and log in as administrators. Fixes shipped in July, but the vendor advisory | 2026-08-24 |
| CVE-2026-15981 | miniOrange SAML SSO Auth Bypass Chained in Live WordPress Attacks Attackers are chaining CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML 2.0 Single Sign On plugin for WordPress to forge SAML responses and log in as administrators. Fixes shipped in July, but the vendor advisory | 2026-08-24 |
| CVE-2026-15571 | Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins A CVSS 9.1 state validation bug in Keycloak | 2026-08-24 |
| CVE-2026-73570 | GitLab CVE-2026-19478 Exploited in the Wild Days After Disclosure A CVSS 9.4 code injection in GitLab | 2026-08-22 |
| CVE-2026-58231 | GitLab CVE-2026-19478 Exploited in the Wild Days After Disclosure A CVSS 9.4 code injection in GitLab | 2026-08-22 |
| CVE-2019-6693 | A Hardcoded FortiOS Key From 2019 Was Still Decrypting Secrets in 7.2.3 fortitool, an open-source FortiOS firmware decryption tool, documents that the CVE-2019-6693 hardcoded config-backup key stayed live years longer than believed, and publishes the AES-256 key that replaced it in 7.4. Trea | 2026-08-22 |
| CVE-2026-68820 | Entra ID RCE at CVSS 10.0 Was Exploited Before Anyone Outside Microsoft Knew It Existed Microsoft confirmed that CVE-2026-69836, a deserialization flaw in Entra ID scoring a perfect 10.0, was exploited in the wild before disclosure. The company says it is fully mitigated and no customer action is required, | 2026-08-21 |
| CVE-2026-64849 | Entra ID RCE at CVSS 10.0 Was Exploited Before Anyone Outside Microsoft Knew It Existed Microsoft confirmed that CVE-2026-69836, a deserialization flaw in Entra ID scoring a perfect 10.0, was exploited in the wild before disclosure. The company says it is fully mitigated and no customer action is required, | 2026-08-21 |
| CVE-2021-24092 | Defender's Own BTR.sys Driver Can Delete Your EDR During Boot Check Point Research showed how Microsoft Defender | 2026-08-21 |
| CVE-2025-66376 | Unauthenticated RCE in Zimbra: CVE-2026-73570 Is Being Exploited Through SMTP CERT Polska confirmed active exploitation of CVE-2026-73570, a CVSS 8.9 command injection flaw that gives unauthenticated attackers code execution on Zimbra Collaboration servers running the optional zimbra-snmp package. | 2026-08-20 |
| CVE-2026-65400 | Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus | 2026-08-19 |
| CVE-2026-59310 | Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus | 2026-08-19 |
| CVE-2026-55040 | Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus | 2026-08-19 |
| CVE-2026-33824 | Four CVEs, One Deadline: CISA Flags macOS, SharePoint, vCenter, and IKE Bugs Under Active Attack CISA added four vulnerabilities rated 9.1 and higher to the KEV catalog, all confirmed exploited in the wild. The vCenter path traversal flaw alone has been tied to 361 victim IPs in 47 countries, a suspected China-nexus | 2026-08-19 |
| CVE-2026-25939 | MLflow SSRF Bug Is Being Exploited to Loot Cloud Metadata Credentials Hours After Disclosure Attackers began scanning for exposed MLflow Tracking Servers within hours of CVE-2026-64849 being assigned on August 17, 2026, and are already pulling cloud credentials out of internal metadata endpoints. A second flaw, | 2026-08-18 |
| CVE-2026-25895 | MLflow SSRF Bug Is Being Exploited to Loot Cloud Metadata Credentials Hours After Disclosure Attackers began scanning for exposed MLflow Tracking Servers within hours of CVE-2026-64849 being assigned on August 17, 2026, and are already pulling cloud credentials out of internal metadata endpoints. A second flaw, | 2026-08-18 |
| CVE-2023-33831 | MLflow SSRF Bug Is Being Exploited to Loot Cloud Metadata Credentials Hours After Disclosure Attackers began scanning for exposed MLflow Tracking Servers within hours of CVE-2026-64849 being assigned on August 17, 2026, and are already pulling cloud credentials out of internal metadata endpoints. A second flaw, | 2026-08-18 |
| CVE-2026-59309 | China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA | 2026-08-17 |
| CVE-2026-20316 | China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA | 2026-08-17 |
| CVE-2026-16812 | China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA | 2026-08-17 |
| CVE-2026-16723 | China-Nexus APT Turns vCenter CVE-2026-59310 Into 361 Ransomware Footholds in 47 Countries A suspected Chinese-speaking APT began exploiting a CVSS 9.8 directory-traversal flaw in VMware vCenter five days after public disclosure, compromising 361 unique victim IPs across 47 countries. The chain abuses the vCSA | 2026-08-17 |
| CVE-2023-32350 | Attackers Shut a Polish CHP Turbine by Pivoting Through a Private Cellular APN CERT Polska disclosed that intruders reached a Polish combined heat and power plant over the distribution operator | 2026-08-11 |
| CVE-2023-32349 | Attackers Shut a Polish CHP Turbine by Pivoting Through a Private Cellular APN CERT Polska disclosed that intruders reached a Polish combined heat and power plant over the distribution operator | 2026-08-11 |
| CVE-2026-63077 | CSS in Email Is Now an Exploit Primitive: Six Webmail Clients Broken at Black Hat 2026 PortSwigger research presented at Black Hat USA 2026 shows email content escaping its message boundary to hijack the webmail interface itself. Attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and | 2026-08-09 |
| CVE-2026-18577 | Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin Attackers exploited an unauthenticated SQL injection flaw in Metabase as a zero-day, scoring a maximum CVSS 10.0 and handing them administrator access to business intelligence instances. Six release branches are affected | 2026-08-08 |
| CVE-2023-38646 | Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin Attackers exploited an unauthenticated SQL injection flaw in Metabase as a zero-day, scoring a maximum CVSS 10.0 and handing them administrator access to business intelligence instances. Six release branches are affected | 2026-08-08 |
| CVE-2026-27912 | Two Active Directory Bugs Turn Write Access on One Account into Domain Admin KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-pas | 2026-08-06 |
| CVE-2026-25177 | Two Active Directory Bugs Turn Write Access on One Account into Domain Admin KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-pas | 2026-08-06 |
| CVE-2021-42282 | Two Active Directory Bugs Turn Write Access on One Account into Domain Admin KerberLoss hides a duplicate service principal name behind invisible Unicode and breaks Kerberos authentication for any service an attacker picks. ResetNightmare walks a username collision through the Kerberos change-pas | 2026-08-06 |
| CVE-2017-16740 | 4,407 Rockwell PLCs Sit on the Public Internet, 22 in Cities Hit by Water Utility Attacks Forescout | 2026-08-06 |
| CVE-2026-18556 | N-able N-central Auth Bypass Exploited in the Wild After First Patch Missed an Alternate Path Attackers bypassed authentication on N-able N-central servers, took administrative control, and pivoted through Take Control into managed customer endpoints. N-able | 2026-08-03 |
| CVE-2026-32194 | Adform's trackpoint-async.js Was Poisoned to Rewrite Crypto Wallet Addresses on Downstream Sites Attackers appended a clipboard-and-DOM hijacking payload to trackpoint-async.js, a tracking script Adform serves from s2.adform[.]net to customer websites. Anyone who copied or typed a Bitcoin, Ethereum, or Tron address | 2026-08-02 |
| CVE-2026-20079 | Cisco Ships Hotfixes for FMC Zero-Day CVE-2026-20316 as CISA Sets August 1 Deadline Cisco confirmed active exploitation of a static-credential flaw in Secure Firewall Management Center that lets unauthenticated attackers log in as a low-privilege user. CISA added CVE-2026-20316 to the KEV catalog on Jul | 2026-07-31 |
| CVE-2025-68686 | Arista VeloCloud Orchestrator CVE-2026-16812: CVSS 10.0 Command Injection Under Active Attack A maximum-severity OS command injection flaw in on-premises Arista VeloCloud Orchestrator is being exploited in the wild, giving remote attackers privileged access to the orchestrator host. CISA added CVE-2026-16812 to t | 2026-07-28 |
| CVE-2026-54121 | SourTrade Malvertising Makes the Victim's Browser Assemble the Malware A malvertising operation called SourTrade delivers no finished binary over the wire. The browser fetches a clean Bun runtime, then byte-copies attacker-supplied PE structures and bytecode into a unique Windows executable | 2026-07-27 |
| CVE-2026-32191 | Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers XBOW found two unauthenticated command-injection bugs in Bing | 2026-07-26 |
| CVE-2016-3714 | Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers XBOW found two unauthenticated command-injection bugs in Bing | 2026-07-26 |
| CVE-2026-16232 | Fastjson 1.x Zero-Day (CVE-2026-16723): Unauthenticated RCE With No Patch Available A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath | 2026-07-25 |
| CVE-2026-50522 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2026-42533 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2026-20896 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2022-26923 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2026-62145 | Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir | 2026-07-23 |
| CVE-2026-62144 | Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir | 2026-07-23 |
| CVE-2026-63030 | CVE-2026-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation Attackers are exploiting CVE-2026-6875, a CVSS 9.5 sandbox escape in the ServiceNow AI Platform that gives unauthenticated remote code execution and full instance compromise. Patches shipped in June; Defused Cyber caught | 2026-07-22 |
| CVE-2026-58644 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2026-56164 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2026-45659 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2026-32201 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2021-39275 | Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine | 2026-07-20 |
| CVE-2016-7407 | Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine | 2026-07-20 |
| CVE-2026-60137 | WP2Shell: Pre-Auth RCE in WordPress Core (CVE-2026-63030) Puts Sites One Request From a Shell CVE-2026-63030, | 2026-07-18 |
| CVE-2026-34183 | HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find Okta | 2026-07-18 |
| CVE-2025-66199 | HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find Okta | 2026-07-18 |
| CVE-2026-57092 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-56155 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-55008 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-54118 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-54117 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-50661 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-9256 | Sixteen Researchers Found the Same NGINX Bug. CVE-2026-42533 Is What AI-Assisted Discovery Looks Like. F5 patched a critical NGINX heap overflow in the map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. That is what open-source review looks like now AI lowered | 2026-07-15 |
| CVE-2026-42945 | Sixteen Researchers Found the Same NGINX Bug. CVE-2026-42533 Is What AI-Assisted Discovery Looks Like. F5 patched a critical NGINX heap overflow in the map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. That is what open-source review looks like now AI lowered | 2026-07-15 |
| CVE-2026-15410 | Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0 SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added | 2026-07-15 |
| CVE-2026-15409 | Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0 SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added | 2026-07-15 |
| CVE-2018-0171 | FSB Center 16 Is Still Looting Cisco Routers With a 2018 Bug: Inside the 11-Nation Advisory NSA, FBI, CISA and 15 partner agencies across eight allied nations published joint guidance on Russian FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, who have been harvesting configs from internet-expo | 2026-07-13 |
| CVE-2026-55116 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-55115 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-54402 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-54400 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-50748 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-50747 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-50746 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-34910 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-34909 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-34908 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2023-24489 | Progress Orders Emergency Shutdown of ShareFile Storage Zone Controllers Over Unnamed Threat Progress Software has told every ShareFile customer running a self-hosted Storage Zone Controller to power the servers down over a | 2026-07-10 |
| CVE-2026-43499 | GitHub 'Verified' Commits Can Be Cloned Into New Hashes Without the Signing Key New research shows anyone can take a signed Git commit and mint a second copy with identical files, author, and a valid signature, but a different hash, and GitHub still stamps it Verified. Hash-based blocklists, dedup, | 2026-07-09 |
| CVE-2026-56290 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-55255 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-53166 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-5027 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-48908 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-48282 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-46242 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-33017 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-31431 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-21445 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-10702 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-0770 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2025-34291 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2025-3248 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-40141 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-40140 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-40139 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-40138 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2024-12356 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-53359 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-46316 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-46113 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-43500 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-43284 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-48558 | Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un | 2026-07-05 |
| CVE-2026-43074 | Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un | 2026-07-05 |
| CVE-2026-6688 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6687 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6686 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6685 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6684 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6683 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6682 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2025-9491 | Armored Likho Hits Government and Power Sector with BusySnake Stealer A newly documented threat actor, Armored Likho, is hitting government agencies and electric power operators across Russia, Brazil, and Kazakhstan with a Python-based stealer called BusySnake. The campaign blends espionag | 2026-07-03 |
| CVE-2025-11371 | SharePoint RCE CVE-2026-45659 Hits CISA KEV as Attackers Exploit It in the Wild CISA added Microsoft SharePoint Server flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The deserialization bug lets any authenticated user with Site Mem | 2026-07-02 |
| CVE-2021-29441 | JADEPUFFER: An AI Agent Just Ran a Ransomware Attack End to End Sysdig says an AI agent executed a full ransomware operation with no human at the keyboard: exploiting a patched Langflow RCE, harvesting credentials, pivoting to a production MySQL/Nacos server, and encrypting 1,342 con | 2026-07-02 |
| CVE-2026-8037 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2026-46817 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2026-20245 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2024-1212 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2026-35273 | Oracle E-Business Suite CVE-2026-46817 Under Active Attack: Patch Now A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are af | 2026-06-30 |
| CVE-2025-61882 | Oracle E-Business Suite CVE-2026-46817 Under Active Attack: Patch Now A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are af | 2026-06-30 |
| CVE-2026-20182 | Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici | 2026-06-28 |
| CVE-2026-20127 | Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici | 2026-06-28 |
| CVE-2026-12569 | Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici | 2026-06-28 |
| CVE-2025-67038 | Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici | 2026-06-28 |
| CVE-2026-20253 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2025-55182 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2024-36401 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2024-21762 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2023-46747 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2023-32315 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2023-20198 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2022-41082 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2022-40684 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2022-27925 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2021-36260 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2021-27076 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2016-4437 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | 2026-06-27 |
| CVE-2026-24061 | Backdoor.Turn Got the Headlines. convoC2 Is the Version Anyone Can Run The DPRK | 2026-06-25 |
| CVE-2026-47729 | Fake AI Agent Skill Slipped Past Every Scanner and Reached 26,000 Agents A security firm planted a malicious AI agent skill that passed Cisco | 2026-06-23 |
| CVE-2026-50012 | Squidbleed: A 1997 Squid Proxy Bug Leaks Other Users' Cleartext HTTP Requests A 29-year-old heap over-read in the Squid web proxy, dubbed Squidbleed (CVE-2026-47729), lets any permitted proxy user leak another user | 2026-06-22 |
| CVE-2026-23111 | usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by | 2026-06-21 |
| CVE-2025-24472 | FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2024-55591 | FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2020-12812 | FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2018-13382 | FortiBleed Isn't a Campaign: It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2026-26030 | AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv | 2026-06-19 |
| CVE-2026-25592 | AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv | 2026-06-19 |
| CVE-2026-2473 | Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads With Nothing but a Project ID A flaw in Google Cloud | 2026-06-19 |
| CVE-2026-47102 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2026-47101 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2026-42271 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2026-40217 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2024-20399 | China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years Chinese APT group Velvet Ant compromised the Linux login layer itself, backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where or | 2026-06-14 |
| CVE-2026-39987 | Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate, compromising 62% of test hosts w | 2026-06-09 |
| CVE-2026-50752 | Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting | 2026-06-08 |
| CVE-2026-50751 | Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting | 2026-06-08 |
| CVE-2026-39218 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | 2026-06-06 |
| CVE-2026-39210 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | 2026-06-06 |
| CVE-2026-10881 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | 2026-06-06 |
| CVE-2026-42832 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-41102 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-41101 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-41100 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-21509 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | 2026-06-02 |
| CVE-2026-0257 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | 2026-06-02 |
| CVE-2025-8088 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | 2026-06-02 |
| CVE-2026-35616 | PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across n | 2026-05-31 |
| CVE-2026-5194 | Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month Anthropic | 2026-05-23 |
| CVE-2026-28517 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | 2026-05-19 |
| CVE-2026-28516 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | 2026-05-19 |
| CVE-2026-28515 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | 2026-05-19 |
| CVE-2021-34527 | Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available | 2026-05-18 |
| CVE-2026-44338 | PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure CVE-2026-44338, a critical authentication bypass in PraisonAI | 2026-05-17 |
| CVE-2026-33825 | YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio | 2026-05-15 |
| CVE-2025-48804 | YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio | 2026-05-15 |
| CVE-2026-45321 | Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att | 2026-05-13 |
| CVE-2026-7482 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-44009 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44008 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44007 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44006 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44005 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-43999 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-43997 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-42249 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-42248 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-26956 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-26332 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24781 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24120 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24118 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-22709 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2023-37466 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-41940 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2026-1357 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-9501 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-48703 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-29927 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2026-33827 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-32202 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-0625 | Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free A use-after-free in Chrome | 2026-05-05 |
| CVE-2023-50224 | Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure. | 2026-05-05 |