cve 59
- FortiClient EMS Auth Bypass CVE-2026-35616 Actively Exploited to Deploy EKZ Credential Stealer
- Gitea CVE-2026-27771: Unauthenticated Attackers Can Pull Private Container Images
- KnowledgeDeliver LMS Zero-Day Exploited to Deploy Godzilla Web Shell and Cobalt Strike
- LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation
- Langflow CVE-2025-34291 (CVSS 9.4) Added to CISA KEV Under Active Exploitation
- Cisco Patches CVSS 10.0 Flaw in Secure Workload REST API
- CISA Adds 7 Known Exploited Vulnerabilities Including Active Microsoft Defender Flaws
- ExifTool CVE-2026-3102: Malicious Image File Triggers macOS Compromise
- Windows Zero-Day Barrage: YellowKey, GreenPlasma, and MiniPlasma Disclosed Post-Patch Tuesday
- DirtyDecrypt PoC Published for Patched Linux Kernel LPE CVE-2026-31635
- ScadaBR 1.2.0 Hit by Four CVEs Including Unauthenticated RCE (CVSS 9.1)
- Drupal Warns of Critical Core Patch on May 20 — Exploits Expected Within Hours
- DirtyDecrypt: Public PoC Released for Linux Kernel Root Escalation Flaw
- Microsoft Exchange CVE-2026-42897 Zero-Day Exploited via Crafted Email
- Cisco SD-WAN CVE-2026-20182 Added to CISA KEV; Sixth Exploited SD-WAN Zero-Day in 2026
- Fragnesia Linux Kernel LPE (CVE-2026-46300) Grants Root via Page Cache Corruption
- 18-Year-Old NGINX Rewrite Module Bug Enables Unauthenticated RCE
- Critical Exim Mail Server Flaw Allows Unauthenticated Remote Code Execution
- May 2026 Patch Tuesday: 138 CVEs Including Critical Zero-Click Outlook Flaw CVE-2026-40361
- Fortinet Patches Critical RCE Flaws in FortiSandbox and FortiAuthenticator
- Ollama "Bleeding Llama" CVE-2026-7482: Unauthenticated Remote Memory Leak
- cPanel and WHM Patch Three Vulnerabilities Including RCE and Privilege Escalation
- CISA Adds BerriAI LiteLLM SQL Injection to Known Exploited Vulnerabilities
- Dirty Frag Linux Zero-Day Gives Root on All Major Distributions
- PAN-OS Zero-Day CVE-2026-0300 Enables Unauthenticated RCE via Captive Portal
- Palo Alto PAN-OS RCE Zero-Day CVE-2026-0300 Actively Exploited
- MetInfo CMS CVE-2026-29014 Under Active Exploitation — Unauthenticated RCE (CVSS 9.8)
- Weaver E-cology CVE-2026-22679 Actively Exploited — CVSS 9.8 Unauthenticated RCE via Debug API
- 'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins
- Critical cPanel Flaw CVE-2026-41940 Mass-Exploited in "Sorry" Ransomware Attacks
- Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February
- Linux 'Copy Fail' CVE-2026-31431 Enables Root on All Major Distros Since 2017
- Google Patches CVSS 10 Gemini CLI RCE Enabling Supply-Chain Code Execution
- GitHub RCE Flaw CVE-2026-3854 Exposed Millions of Private Repositories
- 38 Vulnerabilities in OpenEMR Allow Access to and Modification of Patient Data
- CISA Adds Actively Exploited ConnectWise ScreenConnect and Windows Flaws to KEV
- Critical GitHub RCE CVE-2026-3854 Exposed Millions of Repositories
- LiteLLM CVE-2026-42208 SQL Injection Exploited Within 36 Hours of Disclosure
- LiteLLM CVE-2026-42208 SQL Injection Under Active Exploit Within 36 Hours
- 15-Year-Old OpenSSH Flaw Allowed Full Root Shell Access via Certificate Principal Parsing Bug
- CVE-2026-6770: Firefox Flaw Enables Fingerprinting and Deanonymization of Tor Browser Users
- Hackers Actively Exploiting Unauthenticated File Upload Bug in Breeze Cache WordPress Plugin
- LMDeploy CVE-2026-33626 SSRF Exploited in the Wild Within 13 Hours of Disclosure
- Checkmarx Supply Chain Attack Compromises Bitwarden CLI and KICS Analysis Tool
- Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges
- Microsoft Issues Emergency Out-of-Band Patches for Critical ASP.NET Core Privilege Escalation
- Over 1,300 SharePoint Servers Still Exposed to Actively Exploited Spoofing Zero-Day
- CVE-2026-1731: Critical Bomgar RMM RCE Actively Exploited to Spread Ransomware
- Splunk Enterprise Patches RCE Flaw Exploitable by Low-Privileged Users via File Upload
- CVE-2026-33032 (MCPwn): Critical Nginx UI Authentication Bypass Actively Exploited
- Fortinet Patches Critical FortiSandbox Vulnerabilities Enabling Auth Bypass and RCE
- April 2026 Patch Tuesday: SharePoint Zero-Day Among 167 CVEs Fixed
- ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
- Critical wolfSSL Vulnerability Allows ECDSA Signature Forgery and Certificate Bypass
- Adobe Patches Actively Exploited Acrobat Reader RCE — CVE-2026-34621
- Palo Alto Networks and SonicWall Patch High-Severity Privilege Escalation Bugs
- Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
- Apache ActiveMQ Classic Carries 13-Year-Old RCE Risk via Unauthenticated Jolokia API
- CVE-2026-1337 — RCE in Widely-Used Python ORM