Advertisement
CVE-2024-3300: Critical Everest Forms Pro Bypass Leads to Site Takeover
Hackers are actively exploiting an authentication bypass in the Everest Forms Pro WordPress plugin (CVE-2024-3300). Update immediately to prevent takeover.
SolarWinds Serv-U DoS Vulnerability CVE-2026-28318 Added to CISA KEV
CISA adds CVE-2026-28318 to its KEV catalog following active exploitation of a high-severity DoS vulnerability in SolarWinds Serv-U file server software.
CVE-2026-28318: SolarWinds Serv-U Uncontrolled Resource Consumption Exploit
CISA warns of active exploitation of CVE-2026-28318, an uncontrolled resource consumption flaw in SolarWinds Serv-U. Immediate patching is critical for all organizations.
CVE-2024-28995: SolarWinds Serv-U Exploit Leads to Server Crashes
CISA warns of active exploitation of SolarWinds Serv-U CVE-2024-28995. Attackers are leveraging this directory traversal flaw to crash vulnerable servers.
Cisco Catalyst SD-WAN Manager RCE via CVE-2024-20468 — Patch Now
Cisco warns of a high-severity zero-day vulnerability in Catalyst SD-WAN Manager, tracked as CVE-2024-20468, currently exploited for root privilege escalation.
CVE-2026-3300: Critical RCE in Everest Forms Pro — Patch Now
Attackers are exploiting CVE-2026-3300 in Everest Forms Pro up to 1.9.12 to achieve RCE. Learn how to protect your WordPress site from full compromise.
Critical Fortinet, Apache, Cisco IOS XE Vulnerabilities: Patch & Monitor
Alert: New critical vulnerabilities impact FortiClient, FortiNAC, and Apache products. Cisco IOS XE continues to face active exploitation. Urgent patching is required.
Hitachi Energy MACH HiDraw RCE via CVE-2026-7310 — Patch Guide
Hitachi Energy addresses a heap-based buffer overflow in MACH HiDraw version 9.22. Learn how to mitigate CVE-2026-7310 and protect critical ICS assets.
CVE-2026-21404: NAVTOR NavBox SOAP Credential Bypass and Mitigation
NAVTOR NavBox version 4.16.1.20 is vulnerable to hard-coded credentials in its SOAP implementation, allowing local attackers to manipulate application files.
Cisco Unified CM RCE via CVE-2026-20230 — Mitigation Guide
Cisco patches CVE-2026-20230, a high-severity SSRF in Unified Communications Manager. Learn how public PoC code impacts your security and find remediation steps.
Mirasvit Full Page Cache Warmer RCE via CVE-2024-34961 - Patch Now
Attackers are exploiting a critical RCE vulnerability in Mirasvit's Full Page Cache Warmer for Magento. Learn how to detect and mitigate CVE-2024-34961.
Google Gemini Hijack: Command Injection via Messaging Notifications
Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.
CVE-2024-20469: Critical Cisco Unified CM Root Escalation Risk
Cisco patches a critical SQL injection flaw (CVE-2024-20469) in Unified Communications Manager that allows remote attackers to gain full root-level access.
VS Code One-Click GitHub Token Theft via URI Handler Exploitation
A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.
Cisco Unified CM SSRF CVE-2024-20455 — Public PoC Mitigation Guide
Cisco warns of critical SSRF vulnerabilities in Unified CM with public PoC exploit code. Learn how to detect and patch CVE-2024-20455 to protect your network.
CVE-2026-45247: Magento Mirasvit Cache Warmer RCE Exploit Analysis
CISA adds CVE-2026-45247, a critical Mirasvit Cache Warmer RCE flaw impacting Magento sites, to the KEV catalog following reports of active exploitation.
Google Gemini Hijacked on Android via Poisoned Notifications
Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.
CVE-2026-45247: Mirasvit Full Page Cache Warmer Exploited — Patch Now
CISA adds CVE-2026-45247, a deserialization vulnerability in Mirasvit Full Page Cache Warmer for Magento, to the KEV catalog after reports of active exploitation.
Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626
CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.
Google Gemini Indirect Prompt Injection via Malicious Notifications
Security researchers demonstrate how malicious notifications can manipulate Google Gemini's voice assistant to perform unauthorized tasks or exfiltrate data.
WordPress Sites Targeted via Kirki and Burst Statistics Vulnerabilities
Attackers are exploiting unauthenticated stored XSS in Kirki and Burst Statistics plugins to achieve privilege escalation and website takeover.
Acer Wave 7 Router RCE via CVE-2024-41591 and CVE-2024-41592
Acer addresses two critical 10.0 CVSS zero-day vulnerabilities in Wave 7 mesh routers that allow unauthenticated remote code execution and full takeover.
GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code
New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.
VS Code Zero-Day Exploit: Stealing GitHub Tokens via URI Handlers
Security researcher mthcht reveals a VS Code zero-day vulnerability allowing GitHub token theft via URI handlers. Learn how to defend against this exploit.