Skip to main content
← All Articles

Category

Vulnerabilities

962 articles

Advertisement

LOW
Vulnerabilities

Apple Addresses 85 Vulnerabilities in Recent OS Updates

Apple released significant security updates patching 85 vulnerabilities across macOS, iOS, iPadOS, tvOS, watchOS, and visionOS, with no active exploitation reported.

Runtime Rebel Intel
4 min read · Mar 26, 2026
HIGH
Vulnerabilities

CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores

Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.

Runtime Rebel Intel
3 min read · Mar 26, 2026
INFO
Vulnerabilities

GitHub Copilot Autofix: AI-Driven Vulnerability Remediation in GHAS

GitHub integrates AI-powered scanning into Advanced Security to detect and remediate vulnerabilities across more languages using Copilot Autofix.

Runtime Rebel Intel
3 min read · Mar 26, 2026
CRITICAL
Vulnerabilities

CVE-2026-33017: Langflow Code Injection - Patch Immediately

CISA adds actively exploited Langflow Code Injection Vulnerability (CVE-2026-33017) to KEV catalog. Critical patch urged for all organizations.

Runtime Rebel Intel
4 min read · Mar 25, 2026
HIGH
Vulnerabilities

Citrix NetScaler Info Disclosure: CVE-2024-8069 Patch Guide

Citrix urges immediate patching of two NetScaler ADC and Gateway vulnerabilities, including a flaw similar to the high-impact CitrixBleed exploit.

Runtime Rebel Intel
4 min read · Mar 25, 2026
HIGH
Vulnerabilities

Archer NX200 and NX510v Auth Bypass: CVE-2024-5035 Patch Guidance

TP-Link patches critical auth bypass CVE-2024-5035 and command injection in Archer NX routers, preventing unauthorized firmware uploads and remote code execution.

Runtime Rebel Intel
3 min read · Mar 25, 2026

Advertisement

CRITICAL
Vulnerabilities

PTC Windchill RCE via CVE-2024-38472 — Mitigation and Patch Guide

PTC warns of imminent RCE threats against Windchill and FlexPLM systems. Learn how to secure your PLM environment and apply critical security updates now.

Runtime Rebel Intel
3 min read · Mar 25, 2026
HIGH
Vulnerabilities

Schneider Electric Plant iT/Brewmaxx RCE via Multiple Redis Vulnerabilities

Multiple critical and high-severity vulnerabilities in Schneider Electric Plant iT/Brewmaxx 9.60+ (Redis component) enable RCE and privilege escalation, affecting…

Runtime Rebel Intel
4 min read · Mar 24, 2026
HIGH
Vulnerabilities

CVE-2026-2417: Pharos Controls RCE via Missing Authentication

Critical vulnerability (CVE-2026-2417) in Pharos Controls Mosaic Show Controller firmware 2.15.3 allows unauthenticated root RCE. Upgrade to 2.16+ immediately.

Runtime Rebel Intel
4 min read · Mar 24, 2026
LOW
Vulnerabilities

Microsoft Outlook Fixes Gmail IMAP Sync Bug in Version 2404

Microsoft resolves a persistent bug in Classic Outlook causing IMAP synchronization failures and connection errors for Gmail and Yahoo mail users.

Runtime Rebel Intel
3 min read · Mar 24, 2026
HIGH
Vulnerabilities

CVE-2023-4966: Critical Citrix NetScaler Memory Leak Patching Guide

Critical unauthenticated memory leak in Citrix NetScaler ADC and Gateway allows session hijacking. Learn to mitigate CVE-2023-4966 and secure your network.

Runtime Rebel Intel
3 min read · Mar 24, 2026
Citrix NetScaler CVE-2026-3055: Critical Data Leak Patch Guidance
CRITICAL
Vulnerabilities

Citrix NetScaler CVE-2026-3055: Critical Data Leak Patch Guidance

Citrix releases critical security updates for NetScaler ADC and Gateway to address CVE-2026-3055, an unauthenticated memory overread and data leak flaw.

Runtime Rebel Intel
3 min read · Mar 24, 2026
HIGH
Vulnerabilities

CVE-2024-3400: Exploiting Palo Alto Networks PAN-OS — Patch Now

Technical analysis of CVE-2024-3400, a critical command injection vulnerability in PAN-OS firewalls. Learn exploit mechanics, detection, and mitigation steps.

Runtime Rebel Intel
3 min read · Mar 24, 2026
MEDIUM
Vulnerabilities

Microsoft Xbox One Hardware Security Defeated via Bliss Exploit

Security researchers have bypassed Microsoft Xbox One hardware security using the Bliss voltage glitching exploit, enabling unsigned code execution.

Runtime Rebel Intel
3 min read · Mar 23, 2026
HIGH
Vulnerabilities

QNAP Patches Four Pwn2Own Vulnerabilities in QTS and QuTS hero

QNAP releases security updates for four vulnerabilities, including CVE-2024-50387 and CVE-2024-50388, exploited during the Pwn2Own Ireland 2024 competition.

Runtime Rebel Intel
3 min read · Mar 23, 2026
CRITICAL
Vulnerabilities

CVE-2021-35587: Critical RCE in Oracle Identity Manager Patched

Oracle issues emergency patches for CVE-2021-35587, a critical RCE flaw in Identity Manager with a 9.8 CVSS score. Immediate mitigation is required.

Runtime Rebel Intel
3 min read · Mar 23, 2026
Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance
CRITICAL
Vulnerabilities

Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance

Threat actors are exploiting a critical CVSS 10.0 vulnerability, CVE-2025-32975, in Quest KACE Systems Management Appliances exposed to the internet.

Runtime Rebel Intel
3 min read · Mar 23, 2026
HIGH
Vulnerabilities

PHP 8.1 End-of-Life: Security Risks and Upgrade Path Analysis

PHP 8.1 has reached its end-of-life status. Learn about the security implications of running unsupported software and the technical steps for remediation.

Runtime Rebel Intel
4 min read · Mar 23, 2026
CRITICAL
Vulnerabilities

Quest KACE SMA CVE-2025-32975: Potential Exploitation in Education

Quest KACE Systems Management Appliance (SMA) faces potential active exploitation via CVE-2025-32975, primarily targeting the education sector. Patch now.

Runtime Rebel Intel
4 min read · Mar 21, 2026
Oracle Fusion Middleware RCE Flaw: Immediate Patch Required
HIGH
Vulnerabilities

Oracle Fusion Middleware RCE Flaw: Immediate Patch Required

A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware's Identity and Web Services Managers demands immediate patching.

Runtime Rebel Intel
4 min read · Mar 20, 2026
HIGH
Vulnerabilities

Oracle Identity Manager RCE via CVE-2026-21992 — Patch Now

Oracle issued an emergency patch for CVE-2026-21992, a critical unauthenticated RCE flaw in Identity Manager and Web Services Manager. Immediate patching is required.

Runtime Rebel Intel
4 min read · Mar 20, 2026
CRITICAL
Vulnerabilities

CVE-2026-20131: Cisco FMC/SCC Deserialization Vulnerability Under Active Attack

CISA adds CVE-2026-20131, a critical deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC), to KEV Catalog due…

Runtime Rebel Intel
4 min read · Mar 20, 2026
CRITICAL
Vulnerabilities

CISA Adds 5 KEVs: Apple Buffer Overflow, Code Injections Exploited

CISA's KEV Catalog updated with 5 actively exploited vulnerabilities impacting Apple products, Craft CMS, and Laravel Livewire. Immediate patching is critical.

Runtime Rebel Intel
5 min read · Mar 20, 2026
CRITICAL
Vulnerabilities

CVE-2024-20481: Critical Cisco FMC RCE Exploited in the Wild

CISA mandates federal agencies patch CVE-2024-20481, a 9.8 CVSS RCE vulnerability in Cisco Secure Firewall Management Center, following active exploitation.

Runtime Rebel Intel
3 min read · Mar 20, 2026