Advertisement
CVE-2026-20262: Cisco SD-WAN vManage Root Privilege Escalation Fix
Cisco patches CVE-2026-20262, a critical Zero-Day flaw in Catalyst SD-WAN Manager allowing authenticated attackers to escalate to root privileges.
Microsoft 365 Copilot SearchLeak: One-Click Data Exfiltration
Varonis Threat Labs uncovered 'SearchLeak', a one-click flaw in Microsoft 365 Copilot Enterprise Search allowing exfiltration of emails, files, and MFA codes.
LiteLLM Proxy Server Takeover via Critical Vulnerability Chain
Researchers at Obsidian Security have identified a three-vulnerability chain in LiteLLM that allows low-privilege users to gain full server control.
CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Bypass Active
Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass flaw in PAN-OS GlobalProtect. Apply critical security patches now.
FortiSIEM RCE via CVE-2024-23108: Technical Mitigation Guide
Analysis of critical RCE vulnerabilities CVE-2024-23108 and CVE-2024-23109 in Fortinet FortiSIEM, including detection methods and remediation steps.
CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise <10.2.4
Critical flaw CVE-2026-20253 in Splunk Enterprise allows unauthenticated RCE by creating/truncating files. Patch versions <10.2.4 and <10.0.7 immediately.
Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide
CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.
phpBB Authentication Bypass: Admin Login Vulnerability Patched
A decade-old authentication bypass in phpBB forum software, affecting versions up to 3.3.11, allowed attackers to log in as any user, including administrators.
CVE-2026-28742 & Others: Naxclow IoT Platform Critical Flaws
CISA warns of multiple critical vulnerabilities in Naxclow IoT Platform, including hard-coded cryptographic keys, authorization bypasses, and credential exposure.
Ivanti Sentry Max-Severity Flaw Exploited Within 24 Hours
A critical Ivanti Sentry vulnerability was actively exploited within 24 hours of public disclosure. Defenders must patch immediately to prevent compromise.
Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide
Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.
Ivanti Sentry CVE-2023-35081: CISA Issues Urgent 3-Day Patch Mandate
CISA adds CVE-2023-35081 to its KEV catalog, ordering federal agencies to patch Ivanti Sentry path traversal flaws to prevent remote code execution.
Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide
ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.
Yarbo Mobile App & Cloud: Critical Robot Fleet Vulnerabilities
Critical vulnerabilities CVE-2026-10557 & CVE-2026-7368 in Yarbo mobile app and cloud allow attackers to control robot fleets via hard-coded credentials.
CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters
Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.
CISA Mandates Critical Ivanti & ActiveMQ Patching in 3 Days
CISA's BOD 26-04 requires federal agencies to patch critical, exploited Ivanti Connect Secure and Apache ActiveMQ vulnerabilities within 72 hours.
CISA KEV Update: Active Exploitation of Arista, Cisco, and Chrome
CISA adds CVE-2026-7473, CVE-2026-11645, and CVE-2026-20245 to its Known Exploited Vulnerabilities catalog following evidence of active exploitation.
June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now
Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.
Windows Server 2025 BitLocker Recovery Bug: Mitigation Guide
Microsoft resolves a Windows Server 2025 bug causing systems to boot into BitLocker recovery modes following recent security updates. Patching guidance inside.
CVE-2024-5027: Langflow Path Traversal Exploited in Attacks
Security researchers observe active exploitation of CVE-2024-5027, a high-severity path traversal flaw in the Langflow AI platform allowing arbitrary file writes.
FortiSandbox Command Injection (CVE-2026-25089) & Critical Vendor Patches
Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.
ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances
ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances.
Adobe Addresses 123 Vulnerabilities: Focus on Experience Manager RCE
Adobe's extensive patch cycle resolves 123 vulnerabilities across multiple products, with a critical focus on Experience Manager arbitrary code execution flaws.