Skip to main content
← All Articles

Category

Vulnerabilities

962 articles

Advertisement

Belgium eID Authentication RCE via Browser Extension Flaws
HIGH
Vulnerabilities

Belgium eID Authentication RCE via Browser Extension Flaws

Severe vulnerabilities in a key browser extension fully compromised Belgium's eID authentication trust framework, exposing citizen accounts to remote code execution.

Runtime Rebel Intel
5 min read · Aug 13, 2026
HIGH
Vulnerabilities

ShieldBreak: Windows Zero-Day EoP via Microsoft Defender

Security researcher Nightmare Eclipse released 'ShieldBreak,' a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.

Runtime Rebel Intel
4 min read · Aug 13, 2026
CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC
CRITICAL
Vulnerabilities

CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC

Attackers exploit CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint, leading to data disclosure and modification.

Runtime Rebel Intel
4 min read · Aug 13, 2026
HIGH
Vulnerabilities

Plug and Pwn: SYSTEM Access via Windows Plug and Play Abuse

New Plug and Pwn attacks leverage Windows Plug and Play to install vulnerable vendor software, granting attackers SYSTEM privileges via USB emulation or RDP.

Runtime Rebel Intel
6 min read · Aug 12, 2026
CRITICAL
Vulnerabilities

CVE-2026-72898: Metabase SQL Injection Active Exploitation

CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.

Runtime Rebel Intel
3 min read · Aug 12, 2026
HIGH
Vulnerabilities

CVE-2026-20349: Cisco ASA/FTD DoS Vulnerability Under Active Exploit

CISA warns of active exploitation of CVE-2026-20349, a heap inspection vulnerability causing DoS in Cisco ASA and FTD devices.

Runtime Rebel Intel
4 min read · Aug 12, 2026

Advertisement

HIGH
Vulnerabilities

CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited

Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows' afd.sys component.

Runtime Rebel Intel
4 min read · Aug 12, 2026
Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day
CRITICAL
Vulnerabilities

Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day

Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.

Runtime Rebel Intel
3 min read · Aug 12, 2026
CRITICAL
Vulnerabilities

CVE-2026-63077: JetBrains TeamCity RCE via Deserialization

CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.

Runtime Rebel Intel
4 min read · Aug 11, 2026
Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms
HIGH
Vulnerabilities

Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms

Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.

Runtime Rebel Intel
3 min read · Aug 11, 2026
HIGH
Vulnerabilities

CVE-2026-53413: Zoom Zero-Click RCE – Patch Now

Zoom patches CVE-2026-53413, a critical zero-click RCE in its annotator function, affecting all clients. Immediate patching is advised.

Runtime Rebel Intel
4 min read · Aug 11, 2026
CRITICAL
Vulnerabilities

SonicWall SMA1000 Exploited: Ransomware Targets CVE-2026-15409/15410

CISA confirms ransomware exploitation of SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, urging immediate patching.

Runtime Rebel Intel
4 min read · Aug 10, 2026
TP-Link Zero-Trust Provisioning Bugs: 15 Flaws Threaten Security
MEDIUM
Vulnerabilities

TP-Link Zero-Trust Provisioning Bugs: 15 Flaws Threaten Security

Researchers uncover 15 TP-Link device bugs that undermine automated zero‑trust provisioning, exposing credential leakage and network compromise.

Runtime Rebel Intel
3 min read · Aug 10, 2026
HIGH
Vulnerabilities

TONTOU CPU Attack Bypasses Spectre v2 Mitigations on Linux

New TONTOU CPU attack bypasses Spectre v2 fixes on Intel and AMD, enabling unprivileged attackers to leak Linux kernel password hashes.

Runtime Rebel Intel
5 min read · Aug 10, 2026
AI Browser Prompt Injection Flaws Defeat Vendor Guardrails
MEDIUM
Vulnerabilities

AI Browser Prompt Injection Flaws Defeat Vendor Guardrails

New security research reveals that AI-powered web browsers remain susceptible to persistent prompt injection flaws despite guardrails.

Runtime Rebel Intel
3 min read · Aug 9, 2026
HIGH
Vulnerabilities

Chrome 151 Update Patches 41 Critical, High-Severity Flaws

Google's Chrome 151 update addresses 41 critical and high-severity vulnerabilities, including memory safety bugs potentially leading to RCE.

Runtime Rebel Intel
4 min read · Aug 9, 2026
AI Browsers Face 'PleaseFix' Zero-Click Agent Hijacking
HIGH
Vulnerabilities

AI Browsers Face 'PleaseFix' Zero-Click Agent Hijacking

Attackers can hijack AI browser agents via 'PleaseFix' zero-click vulnerabilities, injecting malicious instructions through content poisoning. No simple fix exists.

Runtime Rebel Intel
5 min read · Aug 9, 2026
HIGH
Vulnerabilities

Microsoft & Apple Patch Critical RCEs and Auth Bypass Flaws

Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.

Runtime Rebel Intel
4 min read · Aug 9, 2026
MEDIUM
Vulnerabilities

NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS

Synack's research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.

Runtime Rebel Intel
4 min read · Aug 9, 2026
New CSS Attacks Break Webmail Interfaces to Steal Credentials
LOW
Vulnerabilities

New CSS Attacks Break Webmail Interfaces to Steal Credentials

PortSwigger researchers revealed new CSS and HTML techniques breaking webmail defenses in Outlook, Gmail, and Yahoo to capture tokens and passwords.

Runtime Rebel Intel
3 min read · Aug 9, 2026
HIGH
Vulnerabilities

RovoBlast: Critical One-Click P2P Injection in Atlassian Rovo AI

Varonis disclosed a critical one-click parameter-to-prompt injection, dubbed RovoBlast, in Atlassian Rovo AI, enabling enterprise data exfiltration.

Runtime Rebel Intel
4 min read · Aug 8, 2026
HIGH
Vulnerabilities

Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder

Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.

Runtime Rebel Intel
3 min read · Aug 8, 2026
Siemens ROX II Zero-Day Trilogy: Chained OT Switch Flaws
HIGH
Vulnerabilities

Siemens ROX II Zero-Day Trilogy: Chained OT Switch Flaws

Siemens and Unit 42 disclose three zero-day vulnerabilities in ROX II switches enabling full root compromise. Patch to firmware V2.17.1.

Runtime Rebel Intel
3 min read · Aug 8, 2026
CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage
CRITICAL
Vulnerabilities

CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage

Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.

Runtime Rebel Intel
4 min read · Aug 8, 2026