CVEPostPublished
CVE-2026-33825Nightmare-Eclipse Toolkit Deployed 8 Days After Public Release — FortiGate Intrusion Analysis
A threat actor gained access via compromised FortiGate SSL VPN credentials and deployed three publicly available Nightmare-Eclipse privilege escalation tools just eight days after release. A previously undocumented Go-ba
2026-05-11
CVE-2026-7482Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-44009Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44008Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44007Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44006Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-44005Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43999Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-43997Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-42249Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-42248Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution
A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil
2026-05-10
CVE-2026-26956Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-26332Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24781Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24120Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-24118Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-22709Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2023-37466Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape
Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec
2026-05-10
CVE-2026-1357PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-9501PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-55182PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-48703PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2025-29927PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure
New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services
2026-05-07
CVE-2026-5281Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free
A use-after-free in Chrome
2026-05-05
CVE-2026-41940cPanel Was Being Exploited for Two Months Before a Patch Existed (CVE-2026-41940)
An auth bypass in cPanel/WHM was exploited as a zero-day from February 23 to April 28, compromising 44,000+ servers before a patch existed. 1.5 million servers remain at risk.
2026-05-05
CVE-2026-33827April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-33824April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-32202April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws
Microsoft
2026-05-05
CVE-2026-31431Copy Fail: The 732-Byte Python Script That Roots Every Major Linux Distro
A 9-year-old Linux kernel bug in the AEAD crypto interface lets any local user overwrite any file
2026-05-05
CVE-2026-0625This D-Link Router Zero-Day Has Been Exploited Since November. There Is No Patch.
A command injection vulnerability in four end-of-life D-Link router models has been exploited by a Mirai variant since November 2025. D-Link confirmed no patch is coming. The only fix is hardware replacement.
2026-05-05
CVE-2023-50224Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials
GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure.
2026-05-05
CVE-2026-5194Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month
Anthropic
CVE-2026-50752Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting
CVE-2026-50751Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate
CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting
CVE-2026-5027CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation
A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm
CVE-2026-47102LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
CVE-2026-47101LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
CVE-2026-45321Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems
TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att
CVE-2026-44338PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure
CVE-2026-44338, a critical authentication bypass in PraisonAI
CVE-2026-43500Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls
University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts wi
CVE-2026-43284Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls
University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts wi
CVE-2026-42945NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-42832Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
CVE-2026-42271LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
CVE-2026-41102Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
CVE-2026-41101Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
CVE-2026-41100Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App
A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac
CVE-2026-40217LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account
Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p
CVE-2026-39987LLM Agents Enter the Attack Chain: Marimo CVE-2026-39987 Breach Shows AI-Driven Post-Exploitation
Threat actors deployed an LLM agent for post-exploitation after breaching a Marimo notebook via CVE-2026-39987, exfiltrating a complete PostgreSQL database in under two minutes. The attack demonstrates how AI agents enab
CVE-2026-39218AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
CVE-2026-39210AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
CVE-2026-35616FortiClient EMS Flaw Exploited to Deploy Credential Stealer Across Managed Endpoints
Threat actors are exploiting CVE-2026-35616, a critical authentication bypass in FortiClient EMS, to deploy credential-stealing malware disguised as legitimate Fortinet updates. The attack abuses trusted endpoint managem
CVE-2026-35273ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach 100+ Universities
The ShinyHunters extortion crew exploited CVE-2026-35273, a 9.8-severity zero-day in Oracle PeopleSoft, to breach over 100 organizations—68% of them universities. Oracle patched after attackers had already exfiltrated st
CVE-2026-33017CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation
A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm
CVE-2026-28517NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-28516NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-28515NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE
Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve
CVE-2026-23111Single-Character Kernel Typo Grants Root on Millions of Linux Systems
CVE-2026-23111, a one-character typo in nf_tables, lets unprivileged users escalate to root and escape containers. Patched February 5, exploits published in April and June—update and reboot now.
CVE-2026-21509Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
CVE-2026-21445CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation
A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm
CVE-2026-20253Splunk Enterprise CVE-2026-20253: Unauthenticated RCE via PostgreSQL Sidecar
A critical 9.8 CVSS vulnerability in Splunk Enterprise allows unauthenticated attackers to achieve remote code execution through exposed PostgreSQL sidecar endpoints. WatchTowr Labs published a detailed exploit chain exp
CVE-2026-10881AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches
A security startup
CVE-2026-0770CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation
A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm
CVE-2026-0257PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation
Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across n
CVE-2025-8088Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine
Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm
CVE-2025-48804YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation
Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio
CVE-2025-34291CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation
A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm
CVE-2024-20399China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years
Chinese APT group Velvet Ant compromised the Linux login layer itself—backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where ord
CVE-2021-34527Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published
A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available