Skip to main content
← All Articles

Category

Vulnerabilities

962 articles

Advertisement

CRITICAL
Vulnerabilities

CVE-2026-49869: Kestra OSS OS Command Injection Exploited

CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.

Runtime Rebel Intel
4 min read · Sep 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-48710: Kludex Starlette HTTP Smuggling for Auth Bypass

CVE-2026-48710 impacts Kludex Starlette, enabling HTTP request smuggling and authentication bypass via path injection. Actively exploited.

Runtime Rebel Intel
5 min read · Sep 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-59822: BerriAI LiteLLM Authentication Bypass

BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.

Runtime Rebel Intel
4 min read · Sep 2, 2026
HIGH
Vulnerabilities

CVE-2026-84115: Cleo Harmony Auth Bypass Exploit Published

An exploit is published for CVE-2026-84115, an authentication bypass in Cleo Harmony allowing remote privilege escalation. Immediate patching to v5.8.1.11 is urged.

Runtime Rebel Intel
4 min read · Sep 2, 2026
CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens
CRITICAL
Vulnerabilities

CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens

Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.

Runtime Rebel Intel
4 min read · Sep 1, 2026
HIGH
Vulnerabilities

CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack

Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.

Runtime Rebel Intel
4 min read · Sep 1, 2026

Advertisement

CRITICAL
Vulnerabilities

CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data

CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.

Runtime Rebel Intel
4 min read · Sep 1, 2026
HIGH
Vulnerabilities

CVE-2026-66384: JFrog Artifactory Path Traversal Exploit

CISA warns of active exploitation of CVE-2026-66384 in JFrog Artifactory, allowing authenticated users to write data outside intended paths. Patch immediately.

Runtime Rebel Intel
4 min read · Sep 1, 2026
CRITICAL
Vulnerabilities

CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation

CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.

Runtime Rebel Intel
5 min read · Sep 1, 2026
CRITICAL
Vulnerabilities

CVE-2023-49105: ownCloud Improper Auth Leads to Data Compromise

CVE-2023-49105 in ownCloud allows unauthenticated file access, modification, or deletion, actively exploited in the wild.

Runtime Rebel Intel
4 min read · Sep 1, 2026
CRITICAL
Vulnerabilities

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Exploit

CISA adds CVE-2026-82078 in PaperCut NG/MF to its KEV catalog following active exploitation. Review technical details and patch now.

Runtime Rebel Intel
3 min read · Sep 1, 2026
LOW
Vulnerabilities

Nightmare Eclipse Releases HardBreacher Kaspersky Exploit

Security researcher Nightmare Eclipse releases HardBreacher, a privilege escalation proof-of-concept targeting Kaspersky Endpoint Security.

Runtime Rebel Intel
3 min read · Sep 1, 2026
CRITICAL
Vulnerabilities

CVE-2026-60004: Gitea Code Injection Under Active Exploitation

CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.

Runtime Rebel Intel
4 min read · Aug 26, 2026
NVIDIA NemoClaw Weakness Allows AI Model Poisoning via Ollama
HIGH
Vulnerabilities

NVIDIA NemoClaw Weakness Allows AI Model Poisoning via Ollama

Oasis Security uncovered a weakness in NVIDIA NemoClaw allowing unauthenticated AI model poisoning through a malicious webpage exploiting Ollama.

Runtime Rebel Intel
4 min read · Aug 25, 2026
CRITICAL
Vulnerabilities

CVE-2026-21962: Oracle WebLogic RCE Under Active Attack

CISA urges immediate patching for CVE-2026-21962, a critical Oracle WebLogic Server Proxy plugin vulnerability actively exploited in the wild.

Runtime Rebel Intel
3 min read · Aug 25, 2026
HIGH
Vulnerabilities

miniOrange SAML SSO Auth Bypass Exploited in WordPress Attacks

Hackers exploit two critical authentication bypasses in miniOrange SAML 2.0 Single Sign On WordPress plugin to gain admin access. Immediate patching is vital.

Runtime Rebel Intel
4 min read · Aug 25, 2026
HIGH
Vulnerabilities

Calix CVE-2026-75501: Unauthenticated NAT Bypass Exposes Devices

An unpatched flaw, CVE-2026-75501, in Calix GS7 XGS routers allows remote, unauthenticated attackers to bypass NAT, exposing internal devices.

Runtime Rebel Intel
3 min read · Aug 25, 2026
HIGH
Vulnerabilities

Critical Type Confusion in isolated-vm Leads to Host RCE

A critical type confusion vulnerability in the Node.js isolated-vm library allows remote code execution on the host system via V8 Isolates.

Runtime Rebel Intel
4 min read · Aug 23, 2026
Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated
LOW
Vulnerabilities

Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated

Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.

Runtime Rebel Intel
4 min read · Aug 23, 2026
N-able Passportal Master Key Exposure: Cloud Risk Persists Post-Patch
HIGH
Vulnerabilities

N-able Passportal Master Key Exposure: Cloud Risk Persists Post-Patch

N-able Passportal's cloud architecture exposes master keys, posing ongoing risk to MSP and SMB password vaults even after patching.

Runtime Rebel Intel
4 min read · Aug 23, 2026
Cisco Patches Nine Crosswork and Secure Workload Flaws
LOW
Vulnerabilities

Cisco Patches Nine Crosswork and Secure Workload Flaws

Cisco patches nine vulnerabilities in Crosswork and Secure Workload platforms, with five flaws scoring the maximum CVSS 10.0 severity rating.

Runtime Rebel Intel
4 min read · Aug 23, 2026
Weaponizing Defender's BTR.sys to Disable Security Software
MEDIUM
Vulnerabilities

Weaponizing Defender's BTR.sys to Disable Security Software

Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.

Runtime Rebel Intel
4 min read · Aug 22, 2026
LOW
Vulnerabilities

Microsoft Patch Tuesday: Critical Azure and Entra ID Flaws

Microsoft rolls out 22 new security patches addressing critical elevation of privilege and remote code execution vulnerabilities across Azure and Entra ID.

Runtime Rebel Intel
3 min read · Aug 21, 2026
CRITICAL
Vulnerabilities

CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth

CISA warns of active exploitation of CVE-2026-72529 in TrueConf Server, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.

Runtime Rebel Intel
4 min read · Aug 21, 2026