vulnerability 238
- PaperCut Warns of Zero-Day Flaw Exploited in NG, MF Print Management Software
- Next.js Patches Critical AVIF and Windows Path Traversal Flaws Enabling Unauthenticated RCE
- CISA Warns of Critical Command Injection and Auth Bypass Flaws in Xiiaozet LK100W
- CISA Warns of Critical Flaws in Ebyte NA111-M Allowing Full Device Compromise
- CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler RCE by Saturday
- GPUThor Rowhammer Attack Defeats ECC on NVIDIA RTX A6000, Enables Root Access
- CISA Adds Six Actively Exploited Flaws to KEV Catalog, Including NetScaler, Linux, and SQL Server Bugs
- Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access
- N-able Ships Second N-central Hotfix as Attackers Persist on Managed Systems
- Critical Vulnerabilities Patched With Chrome 151 Update
- CSS: The Bomb Inside Your Inbox
- Datasette SQL Injection Fix (1.0a38)
- Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks
- Critical Flaw Led to Azure Cosmos DB Pwnage
- VMware Patches Three Critical Flaws Allowing Auth Bypass, VM Escapes
- Azure Cosmos DB Flaw 'CosmosEscape' Exposed Platform-Wide Key
- 'DangleGeddon': Researchers Warn AI Could Weaponize Dangling DNS Records at Scale
- Toptech Systems RCU II+/Multiload II+ Missing Authentication Flaw Rated 8.8
- MikroTik RouterOS Flaw Allows WireGuard Private Key Extraction
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
- Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms via MCP Bridge
- Cisco FMC Zero-Day Actively Exploited, Added to CISA KEV Catalog
- Critical Unauthenticated RCE in Ruflo AI Agent Harness (CVE-2026-59726, CVSS 10.0)
- Russian State Hackers 'Laundry Bear' Exploiting Microsoft Outlook Web Access Bug
- OpenAI's Rogue Agent Breach Widens: JFrog Zero-Days and Stolen Credentials Hit Hugging Face and Others
- vBulletin Fixes Critical Pre-Auth RCE Flaw With Public Exploit
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
- Unpatched Fastjson Vulnerability Exploited in Attacks
- Unpatched Fastjson Vulnerability Exploited in Attacks
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
- PTC Windchill Vulnerability Exploited in Ransomware Campaign
- Kimi K3 AI Agents Found Redis Zero-Days, Built RCE Exploit
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit
- Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
- Check Point Patches Actively Exploited SmartConsole Authentication Bypass
- Check Point Patches Exploited SmartConsole Zero-Day (CVE-2026-16232)
- CISA Orders Urgent Patch of Actively Exploited Langflow RCE Flaw
- Fourth SharePoint Vulnerability Exploited to Steal Machine Keys
- Critical SharePoint RCE Exploited to Steal Machine Keys
- Critical wp2shell WordPress Flaws Exploited to Install Webshells
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
- WordPress wp2shell Vulnerabilities Under Mass Exploitation
- ServiceNow AI Platform Flaw Actively Exploited for Unauthenticated RCE
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- SonicWall SMA1000 Zero-Days Exploited for Weeks to Deploy Malware
- SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
- Critical ServiceNow Code Execution Flaw Now Exploited in Attacks
- Critical ServiceNow AI Platform Flaw Actively Exploited
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
- WordPress Core "wp2shell" RCE Flaws Get Public Exploits, Patch Now
- Unauthenticated RCE in WordPress Core (wp2shell) Now Has Public PoC
- Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- Zoom Patches Critical Windows Flaw Enabling Account Takeover
- Zoom Patches Critical Windows Flaw Enabling Account Takeover (CVE-2026-53412)
- CISA Urges Immediate Patching of Actively Exploited SharePoint Zero-Days
- Two SonicWall SMA 1000 Zero-Days Under Active Exploitation
- Microsoft's Record Patch Tuesday Fixes 622 Flaws, Two Under Active Attack
- SAP Patches Critical Vulnerabilities in NetWeaver, Commerce Cloud, AppRouter
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
- iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days, Added to CISA KEV
- Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
- Hackers Exploit Critical Auth Bypass in Gitea Docker Image
- Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets
- 12 Million Impacted by Data Breach at Japanese Telco KDDI
- CISA Adds 4 Actively Exploited Flaws to KEV, Including Adobe ColdFusion and Langflow
- CISA Adds 4 Actively Exploited Flaws to KEV: ColdFusion, Langflow, Joomla
- FortiBleed Credential Theft Tied to INC and Lynx Ransomware Operations
- CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog
- Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
- Progress Kemp LoadMaster Pre-Auth RCE Under Active Exploitation
- Langflow RCE Flaw (CVE-2026-33017) Exploited to Deploy Monero Miner
- Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
- CISA Confirms Active Ransomware Exploitation of Windows BlueHammer Flaw
- CISA Confirms Ransomware Gangs Exploiting Microsoft Defender 'BlueHammer' Flaw (CVE-2026-33825)
- Critical Pre-Auth RCE in Progress Kemp LoadMaster Lets Attackers Run Root Commands
- Critical Progress Kemp LoadMaster Flaw (CVE-2026-8037) Allows Pre-Auth Root RCE
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited
- Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
- Djinn Stealer Exploits Critical SimpleHelp Auth Bypass to Steal Cloud and AI Credentials
- Nissan, NAIC Breached via Oracle PeopleSoft Zero-Day, ShinyHunters Campaign
- Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
- CISA Adds Actively Exploited PTC Windchill RCE Flaw to KEV Catalog
- First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
- In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
- GitLab Patches Code Execution and Information Disclosure Vulnerabilities
- Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
- Critical Ubiquiti Vulnerabilities Actively Exploited, CISA Warns
- FortiBleed Attackers Use Golang Sniffer to Harvest 110 Million Credentials
- CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog
- Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution
- Fortinet Confirms 86,000 Working Credentials Harvested in FortiBleed Campaign
- Splunk Enterprise RCE Flaw Exploited Days After Disclosure
- FIFA Bug Exposed World Cup Streams to Remote Takeover via Unenforced Entra Controls
- F5 Patches Two Critical NGINX Open Source RCE Flaws
- 'FortiBleed' Leak Exposes Fortinet VPN Credentials for 73,000 Devices
- Critical Flaw in AVer PTC Cameras (CVSS 9.8) Allows Arbitrary Code Execution
- Microsoft Working on Patch for 'RoguePlanet' Zero-Day
- Chrome and Firefox Patch Critical Memory Safety Bugs
- Attackers Exploit Three Fortinet FortiSandbox Flaws Including CVSS 9.1
- Vertex AI Python SDK Flaw Allows Cross-Tenant RCE via Bucket Squatting
- LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
- Critical Splunk Enterprise Flaw (CVE-2026-20253, CVSS 9.8) Allows Unauthenticated Remote Code Execution
- ShinyHunters Exploit Oracle Zero-Day to Steal Data From US Universities
- GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
- Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks (CVE-2026-5027)
- Veeam Backup & Replication Critical RCE CVE-2026-44963 (CVSS 9.4)
- Chrome V8 Zero-Day CVE-2026-11645 Actively Exploited — Patch Now
- Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliates
- CVE-2026-3300: Critical Everest Forms Pro Flaw Actively Exploited for WordPress Takeover
- Autonomous AI Agent Finds 21 Zero-Days in FFmpeg; Chrome 149 Patches Record 429 Bugs
- OWASP Incubator Releases CVE Lite CLI: Free Open-Source Dependency Vulnerability Scanner
- New Chinese Espionage Cluster OP-512 Targets IIS Servers With Custom Web Shell Framework
- Cisco Catalyst SD-WAN Manager Zero-Day CVE-2026-20245 Actively Exploited, No Patch Available
- VS Code Vulnerability Enables One-Click GitHub Token Theft
- Actively Exploited Magento RCE CVE-2026-45247 Added to CISA KEV
- Google Patches Android Zero-Day CVE-2025-48595 Exploited in Targeted Attacks
- Gamaredon Exploits WinRAR CVE-2025-8088 to Deploy GammaWorm and GammaSteel Against Ukraine
- Oracle WebLogic CVE-2024-21182 Under Active Exploitation, Added to CISA KEV
- Russia's FSB Claims Foreign Intelligence Agencies Installed Malware on Senior Officials' Phones
- One Misconfigured Line Exposed Microsoft Account Tokens Across Billions of Android App Installs
- Critical Stack Overflow in HP VoIP Phones Enables Unauthenticated Remote Code Execution
- CISA and Eight Agencies Warn of Active Attacks Targeting Automatic Tank Gauge Systems
- SideCopy Targets Afghanistan Finance Ministry with Xeno RAT via Pashto-Language Spear Phishing
- Dashlane Brute-Force Attack Leads to Encrypted Vault Downloads
- Palo Alto PAN-OS CVE-2026-0257 Authentication Bypass Exploited for Weeks
- PAN-OS GlobalProtect CVE-2026-0257 Authentication Bypass Under Active Exploitation
- FortiClient EMS Auth Bypass CVE-2026-35616 Actively Exploited to Deploy EKZ Credential Stealer
- Gogs Zero-Day RCE Lets Any Authenticated User Execute Arbitrary Code
- Gitea CVE-2026-27771: Unauthenticated Attackers Can Pull Private Container Images
- CISA Emergency: Exploited LiteSpeed cPanel Plugin Zero-Day Grants Root Access
- MuddyWater Uses DLL Side-Loading in Global Espionage Campaign Hitting 9 Countries
- KnowledgeDeliver LMS Zero-Day Exploited to Deploy Godzilla Web Shell and Cobalt Strike
- Anthropic's Project Glasswing Uncovers 10,000 High-Severity Vulnerabilities in Critical Software
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
- LiteSpeed cPanel Plugin CVE-2026-48172 Actively Exploited for Root Privilege Escalation
- BYOVD: Exploiting Vulnerable Windows Kernel Drivers Without Their Target Hardware
- Langflow CVE-2025-34291 (CVSS 9.4) Added to CISA KEV Under Active Exploitation
- Cisco Patches CVSS 10.0 Flaw in Secure Workload REST API
- Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Allowing Unauthenticated Data Access
- Cisco Patches Maximum-Severity Auth Bypass in Secure Workload
- Drupal Patches Unauthenticated RCE Flaw CVE-2026-9082
- Microsoft Defender Vulnerabilities Actively Exploited in the Wild
- Anthropic Silently Patches Claude Code Sandbox Bypass
- CISA Adds 7 Known Exploited Vulnerabilities Including Active Microsoft Defender Flaws
- ExifTool CVE-2026-3102: Malicious Image File Triggers macOS Compromise
- Windows Zero-Day Barrage: YellowKey, GreenPlasma, and MiniPlasma Disclosed Post-Patch Tuesday
- DirtyDecrypt PoC Published for Patched Linux Kernel LPE CVE-2026-31635
- ScadaBR 1.2.0 Hit by Four CVEs Including Unauthenticated RCE (CVSS 9.1)
- Drupal Warns of Critical Core Patch on May 20 — Exploits Expected Within Hours
- Critical SEPPMail Gateway Vulnerabilities Enable RCE and Full Mail Traffic Read
- Critical SEPPMail Secure E-Mail Gateway Flaws Enable RCE and Full Mail Traffic Interception
- Microsoft Exchange Zero-Day Under Active Attack, No Patch Available
- MiniPlasma Windows Zero-Day Grants SYSTEM Privileges on Fully Patched Systems
- DirtyDecrypt: Public PoC Released for Linux Kernel Root Escalation Flaw
- Pwn2Own Berlin 2026: $1.3M Paid for 47 Zero-Days in Windows, Linux, VMware, and AI Products
- NGINX CVE-2026-42945: Heap Buffer Overflow Exploited in the Wild, RCE Risk
- Funnel Builder WordPress Plugin Flaw Actively Exploited for WooCommerce Payment Skimming
- PoC Published for Critical NGINX Vulnerability Patched This Week
- Pwn2Own Berlin 2026 Day 2: 15 Zero-Days in Windows 11, Exchange, and RHEL Earn $385K
- Microsoft Edge Will No Longer Load Saved Passwords in Cleartext at Startup
- Four OpenClaw Vulnerabilities Chain to Enable Data Theft, Privilege Escalation, and Backdoor Planting
- Microsoft Exchange CVE-2026-42897 Zero-Day Exploited via Crafted Email
- Cisco SD-WAN CVE-2026-20182 Added to CISA KEV; Sixth Exploited SD-WAN Zero-Day in 2026
- Researcher Drops YellowKey BitLocker Bypass and GreenPlasma Windows EoP Zero-Days
- Fragnesia Linux Kernel LPE (CVE-2026-46300) Grants Root via Page Cache Corruption
- 18-Year-Old NGINX Rewrite Module Bug Enables Unauthenticated RCE
- Critical Exim Mail Server Flaw Allows Unauthenticated Remote Code Execution
- May 2026 Patch Tuesday: 138 CVEs Including Critical Zero-Click Outlook Flaw CVE-2026-40361
- Google Project Zero Demonstrates 0-Click Exploit Chain for Pixel 10
- Fortinet Patches Critical RCE Flaws in FortiSandbox and FortiAuthenticator
- OpenAI Launches Daybreak: AI-Powered Vulnerability Detection and Automated Patch Validation
- GhostLock PoC: Legitimate Windows File API Abused to Block Local and SMB File Access
- Unit 42 Unpacks AD CS Escalation: Template Misconfigs, Shadow Credentials, and Detection Guidance
- Ollama "Bleeding Llama" CVE-2026-7482: Unauthenticated Remote Memory Leak
- cPanel and WHM Patch Three Vulnerabilities Including RCE and Privilege Escalation
- Cybercriminal Group Compromises Canvas LMS, Dozens of Universities Reschedule Finals
- CISA Adds BerriAI LiteLLM SQL Injection to Known Exploited Vulnerabilities
- Hackers Breach ICS at Five Polish Water Treatment Plants
- Dirty Frag Linux Zero-Day Gives Root on All Major Distributions
- Prompt Injection Flaw in Claude Chrome Extension Allows AI Agent Takeover
- Claude Chrome Extension Flaw Allows Prompt Injection and Agent Takeover
- Dozen Critical Vulnerabilities in vm2 Node.js Library Enable Sandbox Escape and RCE
- PAN-OS Zero-Day CVE-2026-0300 Enables Unauthenticated RCE via Captive Portal
- VoidStealer Trojan Bypasses Chrome App-Bound Encryption to Steal Credentials
- Oracle Shifts to Monthly Critical Security Patch Updates
- Palo Alto PAN-OS RCE Zero-Day CVE-2026-0300 Actively Exploited
- Ollama 'Bleeding Llama' Bug Exposes ~300,000 Deployments to Unauthenticated Info Theft
- MetInfo CMS CVE-2026-29014 Under Active Exploitation — Unauthenticated RCE (CVSS 9.8)
- Weaver E-cology CVE-2026-22679 Actively Exploited — CVSS 9.8 Unauthenticated RCE via Debug API
- 'Copy Fail' Linux Flaw Hits CISA KEV as Active Exploitation Begins
- Critical cPanel Flaw CVE-2026-41940 Mass-Exploited in "Sorry" Ransomware Attacks
- April Windows 11 Update KB5083769 Breaks Third-Party Backup Software on 24H2 and 25H2
- Critical Gemini CLI Flaw Enabled Host Code Execution and Supply Chain Attacks
- Critical cPanel and WHM Auth Bypass CVE-2026-41940 Exploited as Zero-Day Since February
- Linux 'Copy Fail' CVE-2026-31431 Enables Root on All Major Distros Since 2017
- Google Patches CVSS 10 Gemini CLI RCE Enabling Supply-Chain Code Execution
- Wiz Used AI Reverse Engineering to Uncover High-Severity GitHub Vulnerability
- GitHub RCE Flaw CVE-2026-3854 Exposed Millions of Private Repositories
- 38 Vulnerabilities in OpenEMR Allow Access to and Modification of Patient Data
- CISA Adds Actively Exploited ConnectWise ScreenConnect and Windows Flaws to KEV
- Critical GitHub RCE CVE-2026-3854 Exposed Millions of Repositories
- LiteLLM CVE-2026-42208 SQL Injection Exploited Within 36 Hours of Disclosure
- LiteLLM CVE-2026-42208 SQL Injection Under Active Exploit Within 36 Hours
- Microsoft Patches Entra ID AI Agent Role That Enabled Service Principal Takeover
- Incomplete Windows Patch Exposes Systems to Zero-Click APT28 Attack Vector
- 15-Year-Old OpenSSH Flaw Allowed Full Root Shell Access via Certificate Principal Parsing Bug
- Claude Mythos Accelerates Vulnerability Discovery—but Remediation Teams Aren't Keeping Pace
- CVE-2026-6770: Firefox Flaw Enables Fingerprinting and Deanonymization of Tor Browser Users
- Hackers Actively Exploiting Unauthenticated File Upload Bug in Breeze Cache WordPress Plugin
- LMDeploy CVE-2026-33626 SSRF Exploited in the Wild Within 13 Hours of Disclosure
- Cisco Discovers Memory Vulnerability in Anthropic AI Agent Framework
- Microsoft Defender Zero-Day Exploited to Dump NTLM Hashes and Gain SYSTEM Privileges
- Apple Patches iOS Bug That Let FBI Recover Deleted Signal Messages via Retained Notifications
- Microsoft Issues Emergency Out-of-Band Patches for Critical ASP.NET Core Privilege Escalation
- Over 1,300 SharePoint Servers Still Exposed to Actively Exploited Spoofing Zero-Day
- Claude Mythos Preview Found 271 Firefox Vulnerabilities in Anthropic-Mozilla Collaboration
- CVE-2026-1731: Critical Bomgar RMM RCE Actively Exploited to Spread Ransomware
- Google Antigravity AI IDE: Prompt Injection Chained to Sandbox Escape and Code Execution
- Splunk Enterprise Patches RCE Flaw Exploitable by Low-Privileged Users via File Upload
- Comment and Control: Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via Code Comments
- CVE-2026-33032 (MCPwn): Critical Nginx UI Authentication Bypass Actively Exploited
- Fortinet Patches Critical FortiSandbox Vulnerabilities Enabling Auth Bypass and RCE
- April 2026 Patch Tuesday: SharePoint Zero-Day Among 167 CVEs Fixed
- ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
- Critical wolfSSL Vulnerability Allows ECDSA Signature Forgery and Certificate Bypass
- Anthropic Restricts Mythos Preview After Model Autonomously Exploits Zero-Days in Major OS and Browsers
- Adobe Patches Actively Exploited Acrobat Reader RCE — CVE-2026-34621
- Apple Intelligence Guardrails Bypassed via Neural Exect and Unicode Manipulation
- Hardcoded Google API Keys in Android Apps Expose Gemini AI Endpoints
- Palo Alto Networks and SonicWall Patch High-Severity Privilege Escalation Bugs
- Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
- Russia's APT28 Conducts Malwareless Espionage via SOHO Router DNS Hijack
- Apache ActiveMQ Classic Carries 13-Year-Old RCE Risk via Unauthenticated Jolokia API
- CVE-2026-1337 — RCE in Widely-Used Python ORM