Skip to main content
← All Articles

Category

Vulnerabilities

851 articles

Advertisement

VU
CRITICAL
Vulnerabilities

CVE-2026-33634: Aqua Trivy Embedded Malicious Code — Patch Now

CISA adds CVE-2026-33634, an Aqua Security Trivy Embedded Malicious Code Vulnerability, to KEV catalog due to active exploitation.

Runtime Rebel Intel
4 min read · Mar 26, 2026
Langflow AI Platform: Critical Code Injection Under Active Attack
CRITICAL
Vulnerabilities

Langflow AI Platform: Critical Code Injection Under Active Attack

Threat actors are actively exploiting a critical code injection vulnerability in the Langflow AI platform, demanding immediate patching to prevent compromise.

Runtime Rebel Intel
4 min read · Mar 26, 2026
VU
CRITICAL
Vulnerabilities

Langflow CVE-2026-33017: AI Workflow Hijacking Under Active Exploitation

CISA warns of active exploitation of CVE-2026-33017 in Langflow, enabling attackers to hijack AI workflows and potentially compromise AI agents.

Runtime Rebel Intel
5 min read · Mar 26, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-4681: Critical RCE in PTC Windchill & FlexPLM

Critical RCE vulnerability CVE-2026-4681 affects PTC Windchill and FlexPLM via deserialization. Patch now to prevent code injection in critical manufacturing.

Runtime Rebel Intel
5 min read · Mar 26, 2026
VU
HIGH
Vulnerabilities

CVE-2026-3587: WAGO Switches CLI Escape Leads to Full Device Compromise

Critical flaw CVE-2026-3587 in WAGO Industrial Managed Switches allows unauthenticated remote attackers to fully compromise devices via CLI escape.

Runtime Rebel Intel
5 min read · Mar 26, 2026
VU
HIGH
Vulnerabilities

CVE-2023-50387: Critical BIND DNSSEC Vulnerabilities — Patch Now

ISC releases critical BIND security updates for CVE-2023-50387 and CVE-2023-50868, addressing high-severity resource exhaustion and KeyTrap DNSSEC vulnerabilities.

Runtime Rebel Intel
4 min read · Mar 26, 2026
Claude Chrome Extension Zero-Click Prompt Injection Vulnerability
HIGH
Vulnerabilities

Claude Chrome Extension Zero-Click Prompt Injection Vulnerability

A critical flaw in Anthropic's Claude Chrome extension allowed websites to silently inject malicious prompts using zero-click XSS techniques.

Runtime Rebel Intel
4 min read · Mar 26, 2026
VU
HIGH
Vulnerabilities

CVE-2024-38077: RCE in Windows Remote Desktop Licensing — Patch Now

Technical analysis of CVE-2024-38077, a critical heap overflow vulnerability in Windows Remote Desktop Licensing Service allowing unauthenticated RCE.

Runtime Rebel Intel
3 min read · Mar 26, 2026
VU
LOW
Vulnerabilities

Apple Addresses 85 Vulnerabilities in Recent OS Updates

Apple released significant security updates patching 85 vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS, with no active exploitation reported.

Runtime Rebel Intel
4 min read · Mar 26, 2026
VU
HIGH
Vulnerabilities

CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores

Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.

Runtime Rebel Intel
3 min read · Mar 26, 2026
VU
INFO
Vulnerabilities

GitHub Copilot Autofix: AI-Driven Vulnerability Remediation in GHAS

GitHub integrates AI-powered scanning into Advanced Security to detect and remediate vulnerabilities across more languages using Copilot Autofix.

Runtime Rebel Intel
3 min read · Mar 26, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-33017: Langflow Code Injection - Patch Immediately

CISA adds actively exploited Langflow Code Injection Vulnerability (CVE-2026-33017) to KEV catalog. Critical patch urged for all organizations.

Runtime Rebel Intel
4 min read · Mar 25, 2026
VU
HIGH
Vulnerabilities

Citrix NetScaler Info Disclosure: CVE-2024-8069 Patch Guide

Citrix urges immediate patching of two NetScaler ADC and Gateway vulnerabilities, including a flaw similar to the high-impact CitrixBleed exploit.

Runtime Rebel Intel
4 min read · Mar 25, 2026
VU
HIGH
Vulnerabilities

Archer NX200 and NX510v Auth Bypass: CVE-2024-5035 Patch Guidance

TP-Link patches critical auth bypass CVE-2024-5035 and command injection in Archer NX routers, preventing unauthorized firmware uploads and remote code execution.

Runtime Rebel Intel
3 min read · Mar 25, 2026
VU
CRITICAL
Vulnerabilities

PTC Windchill RCE via CVE-2024-38472 — Mitigation and Patch Guide

PTC warns of imminent RCE threats against Windchill and FlexPLM systems. Learn how to secure your PLM environment and apply critical security updates now.

Runtime Rebel Intel
3 min read · Mar 25, 2026
VU
HIGH
Vulnerabilities

Schneider Electric Plant iT/Brewmaxx RCE via Multiple Redis Vulnerabilities

Multiple critical and high-severity vulnerabilities in Schneider Electric Plant iT/Brewmaxx 9.60+ (Redis component) enable RCE and privilege escalation, affecting…

Runtime Rebel Intel
4 min read · Mar 24, 2026
VU
HIGH
Vulnerabilities

CVE-2026-2417: Pharos Controls RCE via Missing Authentication

Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.

Runtime Rebel Intel
4 min read · Mar 24, 2026
VU
LOW
Vulnerabilities

Microsoft Outlook Fixes Gmail IMAP Sync Bug in Version 2404

Microsoft resolves a persistent bug in Classic Outlook causing IMAP synchronization failures and connection errors for Gmail and Yahoo mail users.

Runtime Rebel Intel
3 min read · Mar 24, 2026
VU
HIGH
Vulnerabilities

CVE-2023-4966: Critical Citrix NetScaler Memory Leak Patching Guide

Critical unauthenticated memory leak in Citrix NetScaler ADC and Gateway allows session hijacking. Learn to mitigate CVE-2023-4966 and secure your network.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Citrix NetScaler CVE-2026-3055: Critical Data Leak Patch Guidance
CRITICAL
Vulnerabilities

Citrix NetScaler CVE-2026-3055: Critical Data Leak Patch Guidance

Citrix releases critical security updates for NetScaler ADC and Gateway to address CVE-2026-3055, an unauthenticated memory overread and data leak flaw.

Runtime Rebel Intel
3 min read · Mar 24, 2026
VU
HIGH
Vulnerabilities

CVE-2024-3400: Exploiting Palo Alto Networks PAN-OS — Patch Now

Technical analysis of CVE-2024-3400, a critical command injection vulnerability in PAN-OS firewalls. Learn exploit mechanics, detection, and mitigation steps.

Runtime Rebel Intel
3 min read · Mar 24, 2026
VU
MEDIUM
Vulnerabilities

Microsoft Xbox One Hardware Security Defeated via Bliss Exploit

Security researchers have bypassed Microsoft Xbox One hardware security using the Bliss voltage glitching exploit, enabling unsigned code execution.

Runtime Rebel Intel
3 min read · Mar 23, 2026
VU
HIGH
Vulnerabilities

QNAP Patches Four Pwn2Own Vulnerabilities in QTS and QuTS hero

QNAP releases security updates for four vulnerabilities, including CVE-2024-50387 and CVE-2024-50388, exploited during the Pwn2Own Ireland 2024 competition.

Runtime Rebel Intel
3 min read · Mar 23, 2026
VU
CRITICAL
Vulnerabilities

CVE-2021-35587: Critical RCE in Oracle Identity Manager Patched

Oracle issues emergency patches for CVE-2021-35587, a critical RCE flaw in Identity Manager with a 9.8 CVSS score. Immediate mitigation is required.

Runtime Rebel Intel
3 min read · Mar 23, 2026