| CVE | Post | Published |
|---|---|---|
| CVE-2026-54121 | SourTrade Malvertising Makes the Victim's Browser Assemble the Malware A malvertising operation called SourTrade delivers no finished binary over the wire. The browser fetches a clean Bun runtime, then byte-copies attacker-supplied PE structures and bytecode into a unique Windows executable | 2026-07-27 |
| CVE-2026-32194 | Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers XBOW found two unauthenticated command-injection bugs in Bing | 2026-07-26 |
| CVE-2026-32191 | Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers XBOW found two unauthenticated command-injection bugs in Bing | 2026-07-26 |
| CVE-2016-3714 | Bing SVG Flaws Gave RCE as SYSTEM on Microsoft's Image Servers XBOW found two unauthenticated command-injection bugs in Bing | 2026-07-26 |
| CVE-2026-6875 | Fastjson 1.x Zero-Day (CVE-2026-16723): Unauthenticated RCE With No Patch Available A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath | 2026-07-25 |
| CVE-2026-16723 | Fastjson 1.x Zero-Day (CVE-2026-16723): Unauthenticated RCE With No Patch Available A critical Fastjson 1.x flaw lets a single unauthenticated JSON request execute code inside Spring Boot fat-JAR applications, and Alibaba has no fixed 1.x release. The chain works without AutoType and without a classpath | 2026-07-25 |
| CVE-2026-50522 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2026-42533 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2022-26923 | Certighost: A Low-Privileged AD User Can Forge a Domain Controller (CVE-2026-54121) Certighost (CVE-2026-54121) is a CVSS 8.8 flaw in Active Directory Certificate Services that lets any low-privileged domain user obtain a certificate for a domain controller | 2026-07-24 |
| CVE-2026-62145 | Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir | 2026-07-23 |
| CVE-2026-62144 | Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir | 2026-07-23 |
| CVE-2026-16232 | Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers. Exploitation is confir | 2026-07-23 |
| CVE-2025-66376 | Russian APT Ran a Zimbra Zero-Day for Five Months, Stealing Mail, Passwords and 2FA Codes A Russian state-backed group exploited CVE-2025-66376, a stored XSS flaw in Zimbra | 2026-07-23 |
| CVE-2026-63030 | CVE-2026-6875: ServiceNow AI Platform Sandbox Escape Under Active Exploitation Attackers are exploiting CVE-2026-6875, a CVSS 9.5 sandbox escape in the ServiceNow AI Platform that gives unauthenticated remote code execution and full instance compromise. Patches shipped in June; Defused Cyber caught | 2026-07-22 |
| CVE-2026-58644 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2026-56164 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2026-45659 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2026-32201 | SharePoint CVE-2026-50522 Exploited in the Wild: Attackers Stealing Machine Keys in a Single Request A CVSS 9.8 deserialization flaw in on-premises SharePoint Server is under active exploitation following a public PoC release. Attackers are pulling IIS machine keys with a single HTTP request, which means patching alone | 2026-07-21 |
| CVE-2021-39275 | Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine | 2026-07-20 |
| CVE-2016-7407 | Russian Intelligence Is Hijacking IP Cameras to Track NATO Military Logistics Dutch intelligence services AIVD and MIVD say at least one Russian service is systematically hijacking internet-exposed IP cameras across NATO states and Ukraine to watch weapons shipments and troop movements. In Ukraine | 2026-07-20 |
| CVE-2026-34183 | HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find Okta | 2026-07-18 |
| CVE-2025-66199 | HollowByte: 11 Bytes Freeze OpenSSL Server Memory, and There's No CVE to Find Okta | 2026-07-18 |
| CVE-2026-57092 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-56155 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-55040 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-55008 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-54118 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-54117 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-50661 | Microsoft's 622-CVE Patch Tuesday: Two Zero-Days in SharePoint and AD FS Are Already Being Exploited Microsoft shipped 622 CVEs in July 2026, more than triple the previous record, and two of them are under active attack: an unauthenticated SharePoint privilege escalation and an AD FS elevation flaw found by incident res | 2026-07-17 |
| CVE-2026-20896 | One Header, Full Admin: Attackers Exploit Critical Auth Bypass in Gitea Docker Images Attackers are actively exploiting CVE-2026-20896, a critical authentication bypass in official Gitea Docker images up to 1.26.2. A single spoofed X-WEBAUTH-USER header grants full impersonation of any account, including | 2026-07-12 |
| CVE-2026-55116 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-55115 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-54402 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-54400 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-50748 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-50747 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-50746 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-34910 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-34909 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2026-34908 | Ubiquiti Patches Seven Critical UniFi Flaws, Including a Perfect 10.0 Command Injection Ubiquiti shipped fixes for seven critical vulnerabilities spanning UniFi Connect, Talk, Access, Protect, and UniFi OS, topped by a CVSS 10.0 command injection. With prior UniFi OS bugs already on CISA | 2026-07-10 |
| CVE-2023-24489 | Progress Orders Emergency Shutdown of ShareFile Storage Zone Controllers Over Unnamed Threat Progress Software has told every ShareFile customer running a self-hosted Storage Zone Controller to power the servers down over a | 2026-07-10 |
| CVE-2026-56290 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-55255 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-53166 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-5027 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-48908 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-48282 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-46242 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-43499 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-33017 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-31431 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-21445 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-10702 | GhostLock: 15-Year-Old Linux Kernel Flaw Gives Any Local User Root in 5 Seconds GhostLock (CVE-2026-43499) is a use-after-free in Linux futex priority-inheritance code that has shipped by default in nearly every distro since 2011. Nebula Security | 2026-07-08 |
| CVE-2026-0770 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2025-34291 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2025-3248 | CISA Flags Four Actively Exploited Flaws: ColdFusion, Joomla Page Builders, and Langflow Under Attack CISA added four actively exploited vulnerabilities to its KEV catalog, three of them scored CVSS 10.0, spanning Adobe ColdFusion, two Joomla page builders, and the Langflow AI platform. One ColdFusion flaw was hit within | 2026-07-08 |
| CVE-2026-40141 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-40140 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-40139 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-40138 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-1731 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2024-12356 | BeyondTrust Patches Two 9.2-Rated Auth Bypass Flaws in Remote Support and PRA BeyondTrust shipped fixes for four vulnerabilities in Remote Support and Privileged Remote Access, including two pre-auth bypass flaws rated CVSS 9.2 that let unauthenticated attackers seize appliance accounts with eleva | 2026-07-07 |
| CVE-2026-53359 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-46316 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-46113 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-43500 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-43284 | 16-Year-Old Linux KVM Bug 'Januscape' Lets a Guest VM Take Down the Host on Intel and AMD A use-after-free in Linux KVM | 2026-07-06 |
| CVE-2026-48558 | Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un | 2026-07-05 |
| CVE-2026-43074 | Bad Epoll (CVE-2026-46242): Unprivileged-to-Root Linux Kernel Bug Hits Servers, Desktops, and Android A use-after-free race in the Linux epoll subsystem lets any local user reach root roughly 99% of the time, works from inside the Chrome renderer sandbox, and reaches Android. Kernels built on 6.4 or newer are affected un | 2026-07-05 |
| CVE-2026-6688 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6687 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6686 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6685 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6684 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6683 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2026-6682 | Seven Unpatched FatFs Flaws Put Millions of Embedded Devices One USB Away From a Jailbreak runZero disclosed seven vulnerabilities in FatFs, a FAT/exFAT filesystem library bundled into firmware across security cameras, drones, industrial controllers, and crypto wallets. Three carry a 7.6 CVSS and enable code e | 2026-07-04 |
| CVE-2025-9491 | Armored Likho Hits Government and Power Sector with BusySnake Stealer A newly documented threat actor, Armored Likho, is hitting government agencies and electric power operators across Russia, Brazil, and Kazakhstan with a Python-based stealer called BusySnake. The campaign blends espionag | 2026-07-03 |
| CVE-2025-11371 | SharePoint RCE CVE-2026-45659 Hits CISA KEV as Attackers Exploit It in the Wild CISA added Microsoft SharePoint Server flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The deserialization bug lets any authenticated user with Site Mem | 2026-07-02 |
| CVE-2021-29441 | JADEPUFFER: An AI Agent Just Ran a Ransomware Attack End to End Sysdig says an AI agent executed a full ransomware operation with no human at the keyboard: exploiting a patched Langflow RCE, harvesting credentials, pivoting to a production MySQL/Nacos server, and encrypting 1,342 con | 2026-07-02 |
| CVE-2026-8037 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2026-46817 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2026-20245 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2024-1212 | Kemp LoadMaster Pre-Auth RCE Under Active Attack: Patch CVE-2026-8037 Now Attackers began probing Progress Kemp LoadMaster load balancers on June 29, 2026, targeting a CVSS 9.6 pre-auth command injection flaw. A public PoC and watchTowr | 2026-07-01 |
| CVE-2026-24061 | Backdoor.Turn Got the Headlines. convoC2 Is the Version Anyone Can Run The DPRK | 2026-06-25 |
| CVE-2026-23111 | usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by | 2026-06-21 |
| CVE-2026-20253 | usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by | 2026-06-21 |
| CVE-2026-12569 | usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by | 2026-06-21 |
| CVE-2025-67038 | usbliter8: Unpatchable SecureROM Exploit Breaks Apple A12 and A13 Boot Chain Paradigm Shift researchers published a working exploit, usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple A12 and A13 chips. Burned into silicon at manufacture, the flaw cannot be patched by | 2026-06-21 |
| CVE-2026-47729 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2026-35273 | Microsoft Ties Mastra AI npm Supply Chain Attack to North Korean Hackers Microsoft has attributed a supply chain compromise of the Mastra AI agent framework | 2026-06-20 |
| CVE-2025-24472 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2024-55591 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2022-40684 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2020-12812 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2018-13382 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2018-13379 | FortiBleed Isn't a Campaign — It's an Eight-Year Fortinet Audit Result. 86,644 Firewalls Failed FortiBleed isn | 2026-06-20 |
| CVE-2026-26030 | AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv | 2026-06-19 |
| CVE-2026-25592 | AutoJack: One Web Page Turns a Local AI Agent Into Host Code Execution Microsoft researchers detailed AutoJack, an exploit chain that lets a single attacker-controlled web page reach a privileged local service through an AI browsing agent and run arbitrary commands on the host. The flaw liv | 2026-06-19 |
| CVE-2026-2473 | Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads With Nothing but a Project ID A flaw in Google Cloud | 2026-06-19 |
| CVE-2026-47102 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2026-47101 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2026-42271 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2026-40217 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | 2026-06-15 |
| CVE-2024-20399 | China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years Chinese APT group Velvet Ant compromised the Linux login layer itself—backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where ord | 2026-06-14 |
| CVE-2026-39987 | Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts wi | 2026-06-09 |
| CVE-2026-50752 | Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting | 2026-06-08 |
| CVE-2026-50751 | Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting | 2026-06-08 |
| CVE-2026-39218 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | 2026-06-06 |
| CVE-2026-39210 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | 2026-06-06 |
| CVE-2026-10881 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | 2026-06-06 |
| CVE-2026-42832 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-41102 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-41101 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-41100 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | 2026-06-04 |
| CVE-2026-21509 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | 2026-06-02 |
| CVE-2026-0257 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | 2026-06-02 |
| CVE-2025-8088 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | 2026-06-02 |
| CVE-2026-35616 | PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across n | 2026-05-31 |
| CVE-2026-5194 | Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month Anthropic | 2026-05-23 |
| CVE-2026-42945 | Critical RCE Vulnerability in ChromaDB Enables Complete Server Takeover A maximum severity vulnerability (CVSS 10.0) in ChromaDB, a widely-used vector database for AI applications, allows unauthenticated attackers to execute arbitrary code and hijack servers. Organizations running ChromaDB v | 2026-05-20 |
| CVE-2026-28517 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | 2026-05-19 |
| CVE-2026-28516 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | 2026-05-19 |
| CVE-2026-28515 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | 2026-05-19 |
| CVE-2021-34527 | Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available | 2026-05-18 |
| CVE-2026-44338 | PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure CVE-2026-44338, a critical authentication bypass in PraisonAI | 2026-05-17 |
| CVE-2026-33825 | YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio | 2026-05-15 |
| CVE-2025-48804 | YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio | 2026-05-15 |
| CVE-2026-45321 | Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att | 2026-05-13 |
| CVE-2026-7482 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-44009 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44008 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44007 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44006 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44005 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-43999 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-43997 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-42249 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-42248 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-26956 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-26332 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24781 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24120 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24118 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-22709 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2023-37466 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-5281 | PamDOORa: Linux Backdoor Exploits PAM Framework for SSH Credential Theft A new Linux backdoor called PamDOORa is being sold on Russian cybercrime forums for $1,600, targeting PAM authentication modules to steal SSH credentials and maintain persistent access. The malware represents an evolutio | 2026-05-09 |
| CVE-2026-41940 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2026-1357 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-9501 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-55182 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-48703 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-29927 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2026-33827 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-33824 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-32202 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-0625 | Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free A use-after-free in Chrome | 2026-05-05 |
| CVE-2023-50224 | Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure. | 2026-05-05 |
| CVE-2026-9256 | Sixteen Researchers Found the Same NGINX Bug. CVE-2026-42533 Is What AI-Assisted Discovery Looks Like. F5 patched a critical NGINX heap overflow in the map/regex path (CVE-2026-42533, CVSS 9.2) and credited about sixteen researchers who each found it independently. That is what open-source review looks like now AI lowered | |
| CVE-2026-50012 | Squidbleed: A 1997 Squid Proxy Bug Leaks Other Users' Cleartext HTTP Requests A 29-year-old heap over-read in the Squid web proxy, dubbed Squidbleed (CVE-2026-47729), lets any permitted proxy user leak another user | |
| CVE-2026-20182 | Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici | |
| CVE-2026-20127 | Cisco SD-WAN Zero-Day CVE-2026-20245 Gave Attackers Root Inside a Telecom Fabric An unknown actor exploited Cisco Catalyst SD-WAN as a zero-day for at least two months before disclosure, escalating a compromised admin account to full root on a communications service provider. Mandiant traced a malici | |
| CVE-2026-15410 | Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0 SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added | |
| CVE-2026-15409 | Two SonicWall SMA 1000 Zero-Days Under Active Attack, One Rated CVSS 10.0 SonicWall confirmed active exploitation of two zero-days in SMA 1000 series appliances, including a CVSS 10.0 unauthenticated SSRF and a post-auth code injection flaw that yields admin-level command execution. CISA added | |
| CVE-2025-61882 | Oracle E-Business Suite CVE-2026-46817 Under Active Attack: Patch Now A CVSS 9.8 flaw in Oracle Payments lets unauthenticated attackers take over Oracle E-Business Suite over HTTP. Honeypots caught live exploitation over the weekend, despite no public PoC. EBS 12.2.3 through 12.2.15 are af | |
| CVE-2024-36401 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2024-21762 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2023-46747 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2023-32315 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2023-20198 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2022-41082 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2022-27925 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2021-36260 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2021-27076 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2021-26855 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky | |
| CVE-2018-0171 | FSB Center 16 Is Still Looting Cisco Routers With a 2018 Bug: Inside the 11-Nation Advisory NSA, FBI, CISA and 15 partner agencies across eight allied nations published joint guidance on Russian FSB Center 16 hackers, tracked as Berserk Bear and Static Tundra, who have been harvesting configs from internet-expo | |
| CVE-2016-4437 | SharkLoader Smuggles Cobalt Strike Through 13 Known-Exploited CVEs Kaspersky |