| CVE | Post | Published |
|---|---|---|
| CVE-2026-33825 | Nightmare-Eclipse Toolkit Deployed 8 Days After Public Release — FortiGate Intrusion Analysis A threat actor gained access via compromised FortiGate SSL VPN credentials and deployed three publicly available Nightmare-Eclipse privilege escalation tools just eight days after release. A previously undocumented Go-ba | 2026-05-11 |
| CVE-2026-7482 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-44009 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44008 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44007 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44006 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-44005 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-43999 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-43997 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-42249 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-42248 | Critical Ollama Vulnerabilities Expose 300,000+ Servers to Memory Leaks and Persistent Code Execution A critical out-of-bounds read vulnerability (CVE-2026-7482, CVSS 9.1) in Ollama enables unauthenticated attackers to exfiltrate entire process memory from over 300,000 servers. Two additional unpatched Windows vulnerabil | 2026-05-10 |
| CVE-2026-26956 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-26332 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24781 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24120 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-24118 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-22709 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2023-37466 | Twelve Critical Vulnerabilities in vm2 Node.js Library Enable Complete Sandbox Escape Twelve critical vulnerabilities in the widely-used vm2 Node.js sandbox library allow attackers to escape isolation and execute arbitrary code on host systems. Three vulnerabilities scored perfect 10.0 CVSS ratings, affec | 2026-05-10 |
| CVE-2026-1357 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-9501 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-55182 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-48703 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2025-29927 | PCPJack Worm Exploits 5 CVEs to Steal Credentials and Hijack TeamPCP Infrastructure New credential theft framework PCPJack exploits five CVEs to spread worm-like across cloud environments while deliberately removing TeamPCP artifacts. The campaign targets Docker, Kubernetes, and multiple cloud services | 2026-05-07 |
| CVE-2026-5281 | Chrome Zero-Day CVE-2026-5281: Active Exploitation of a WebGPU Use-After-Free A use-after-free in Chrome | 2026-05-05 |
| CVE-2026-41940 | cPanel Was Being Exploited for Two Months Before a Patch Existed (CVE-2026-41940) An auth bypass in cPanel/WHM was exploited as a zero-day from February 23 to April 28, compromising 44,000+ servers before a patch existed. 1.5 million servers remain at risk. | 2026-05-05 |
| CVE-2026-33827 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-33824 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-32202 | April Patch Tuesday: 163 Vulnerabilities, a Wormable TCP/IP RCE, and Two Already-Exploited Flaws Microsoft | 2026-05-05 |
| CVE-2026-31431 | Copy Fail: The 732-Byte Python Script That Roots Every Major Linux Distro A 9-year-old Linux kernel bug in the AEAD crypto interface lets any local user overwrite any file | 2026-05-05 |
| CVE-2026-0625 | This D-Link Router Zero-Day Has Been Exploited Since November. There Is No Patch. A command injection vulnerability in four end-of-life D-Link router models has been exploited by a Mirai variant since November 2025. D-Link confirmed no patch is coming. The only fix is hardware replacement. | 2026-05-05 |
| CVE-2023-50224 | Russia's APT28 Is Hijacking Your Router to Steal Microsoft 365 Credentials GRU-affiliated APT28 exploited unpatched TP-Link routers to perform DNS hijacking against NATO members and Ukraine, capturing M365 credentials via adversary-in-the-middle infrastructure. | 2026-05-05 |
| CVE-2026-5194 | Anthropic's Claude Mythos AI Discovers 10,000 Critical Vulnerabilities in One Month Anthropic | |
| CVE-2026-50752 | Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting | |
| CVE-2026-50751 | Check Point IKEv1 VPN Authentication Bypass Exploited by Qilin Ransomware Affiliate CVE-2026-50751, a critical logic flaw in Check Point VPN certificate validation, allows unauthenticated attackers to bypass passwords in IKEv1 configurations. Exploitation tied to Qilin ransomware began May 7, targeting | |
| CVE-2026-5027 | CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm | |
| CVE-2026-47102 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | |
| CVE-2026-47101 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | |
| CVE-2026-45321 | Mini Shai-Hulud Worm Deploys SLSA-Attested Malware Across Major Package Ecosystems TeamPCP threat actors compromised 42 TanStack packages and infiltrated npm/PyPI repositories from Mistral AI, UiPath, OpenSearch, and Guardrails AI using GitHub Actions OIDC token hijacking. The worm produces validly att | |
| CVE-2026-44338 | PraisonAI Authentication Bypass Exploited Within 4 Hours of Disclosure CVE-2026-44338, a critical authentication bypass in PraisonAI | |
| CVE-2026-43500 | Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts wi | |
| CVE-2026-43284 | Self-Replicating AI Worm Operates Entirely on Local Models, Bypasses Vendor Controls University of Toronto researchers built a proof-of-concept AI worm that uses local open-weight LLMs to autonomously reason through networks, generate runtime exploits, and self-replicate—compromising 62% of test hosts wi | |
| CVE-2026-42945 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | |
| CVE-2026-42832 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | |
| CVE-2026-42271 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | |
| CVE-2026-41102 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | |
| CVE-2026-41101 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | |
| CVE-2026-41100 | Debug Flag Left Enabled in Microsoft 365 Android Apps Exposed Account Tokens to Any App A single line of debug code left in production builds of six Microsoft 365 Android apps disabled authentication checks, allowing any app on the device to steal user account tokens without password prompts or user interac | |
| CVE-2026-40217 | LiteLLM Vulnerability Chain Enables Full AI Gateway Takeover from Default Account Three chained vulnerabilities in LiteLLM let low-privilege users escalate to admin and execute code on AI gateway servers. Critical-severity chain exposes all provider keys, credentials, and prompts flowing through the p | |
| CVE-2026-39987 | LLM Agents Enter the Attack Chain: Marimo CVE-2026-39987 Breach Shows AI-Driven Post-Exploitation Threat actors deployed an LLM agent for post-exploitation after breaching a Marimo notebook via CVE-2026-39987, exfiltrating a complete PostgreSQL database in under two minutes. The attack demonstrates how AI agents enab | |
| CVE-2026-39218 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | |
| CVE-2026-39210 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | |
| CVE-2026-35616 | FortiClient EMS Flaw Exploited to Deploy Credential Stealer Across Managed Endpoints Threat actors are exploiting CVE-2026-35616, a critical authentication bypass in FortiClient EMS, to deploy credential-stealing malware disguised as legitimate Fortinet updates. The attack abuses trusted endpoint managem | |
| CVE-2026-35273 | ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach 100+ Universities The ShinyHunters extortion crew exploited CVE-2026-35273, a 9.8-severity zero-day in Oracle PeopleSoft, to breach over 100 organizations—68% of them universities. Oracle patched after attackers had already exfiltrated st | |
| CVE-2026-33017 | CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm | |
| CVE-2026-28517 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | |
| CVE-2026-28516 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | |
| CVE-2026-28515 | NGINX CVE-2026-42945 Under Active Exploitation: 18-Year-Old Flaw Triggers Worker Crashes and RCE Critical heap buffer overflow in NGINX versions 0.6.27 through 1.30.0 is being actively exploited in the wild. The vulnerability, introduced in 2008, allows unauthenticated attackers to crash worker processes or achieve | |
| CVE-2026-23111 | Single-Character Kernel Typo Grants Root on Millions of Linux Systems CVE-2026-23111, a one-character typo in nf_tables, lets unprivileged users escalate to root and escape containers. Patched February 5, exploits published in April and June—update and reboot now. | |
| CVE-2026-21509 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | |
| CVE-2026-21445 | CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm | |
| CVE-2026-20253 | Splunk Enterprise CVE-2026-20253: Unauthenticated RCE via PostgreSQL Sidecar A critical 9.8 CVSS vulnerability in Splunk Enterprise allows unauthenticated attackers to achieve remote code execution through exposed PostgreSQL sidecar endpoints. WatchTowr Labs published a detailed exploit chain exp | |
| CVE-2026-10881 | AI Agent Finds 21 Zero-Days in FFmpeg for $1,000 as Chrome Ships Record 429 Patches A security startup | |
| CVE-2026-0770 | CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm | |
| CVE-2026-0257 | PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Under Active Exploitation Palo Alto Networks CVE-2026-0257 authentication bypass vulnerability is being actively exploited in the wild, allowing attackers to establish unauthorized VPN connections. Rapid7 confirms successful exploitation across n | |
| CVE-2025-8088 | Gamaredon Exploits WinRAR Vulnerability to Deploy GammaWorm and GammaSteel Against Ukraine Russian FSB-linked threat group Gamaredon weaponizes CVE-2025-8088 WinRAR vulnerability to deliver modular malware framework targeting Ukrainian organizations. Attack chain deploys GammaPhish HTML applications, GammaWorm | |
| CVE-2025-48804 | YellowKey and GreenPlasma Zero-Days Target BitLocker Encryption and Windows Privilege Escalation Anonymous researcher Chaotic Eclipse disclosed two critical Windows zero-days: YellowKey enables BitLocker bypass through Windows Recovery Environment in minutes, while GreenPlasma allows SYSTEM-level privilege escalatio | |
| CVE-2025-34291 | CVE-2026-5027: Unpatched Langflow RCE Under Active Exploitation A critical path traversal flaw in Langflow enables unauthenticated remote code execution and is being actively exploited in the wild. With 7,000 exposed instances and no patch available, organizations running AI developm | |
| CVE-2024-20399 | China-Linked Velvet Ant Backdoored Linux PAM and OpenSSH for Nine Years Chinese APT group Velvet Ant compromised the Linux login layer itself—backdooring PAM modules and OpenSSH binaries on air-gapped networks since 2016. Sygnia researchers found nine variants recording credentials where ord | |
| CVE-2021-34527 | Windows MiniPlasma Zero-Day Grants SYSTEM Access, PoC Published A newly disclosed Windows zero-day vulnerability dubbed MiniPlasma allows unprivileged users to escalate to SYSTEM-level access through a flaw in the Print Spooler service. Proof-of-concept code is now publicly available |