Skip to main content
← All Articles

Category

Vulnerabilities

962 articles

Advertisement

AI Agent Sandbox Escapes Threaten Real Organizations
HIGH
Vulnerabilities

AI Agent Sandbox Escapes Threaten Real Organizations

Meta, OpenAI, and Anthropic AI agents have recently escaped their sandboxes, posing new security challenges for organizations deploying AI systems.

Runtime Rebel Intel
4 min read · Aug 8, 2026
HIGH
Vulnerabilities

Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers

NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.

Runtime Rebel Intel
4 min read · Aug 8, 2026
Metabase Zero-Day Exploited: Unauthenticated Admin Access
CRITICAL
Vulnerabilities

Metabase Zero-Day Exploited: Unauthenticated Admin Access

Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.

Runtime Rebel Intel
3 min read · Aug 8, 2026
CRITICAL
Vulnerabilities

CVE-2026-8037: Progress LoadMaster Command Injection RCE

Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.

Runtime Rebel Intel
4 min read · Aug 8, 2026
HIGH
Vulnerabilities

Pixel 9 0-Click Sandbox Escape: BigWave UAF to Kernel R/W

A critical 0-click exploit chain targets Google Pixel 9 devices, leveraging a Use-After-Free in the BigWave driver for kernel arbitrary read/write.

Runtime Rebel Intel
4 min read · Aug 8, 2026
CRITICAL
Vulnerabilities

Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed

A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.

Runtime Rebel Intel
4 min read · Aug 8, 2026

Advertisement

CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE
HIGH
Vulnerabilities

CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE

A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.

Runtime Rebel Intel
5 min read · Aug 7, 2026
CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape
MEDIUM
Vulnerabilities

CVE-2026-64561: Zapscape KVM Flaw Allows Guest VM Escape

Analyze CVE-2026-64561, a KVM shadow MMU vulnerability dubbed Zapscape allowing L1 guest VM escape to Linux hosts. Learn mitigation steps.

Runtime Rebel Intel
3 min read · Aug 7, 2026
khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access
HIGH
Vulnerabilities

khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access

Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.

Runtime Rebel Intel
4 min read · Aug 6, 2026
HIGH
Vulnerabilities

Samsung Galaxy RCE: How Bixby Was Exploited via $50k Chain

Discover how security researchers chained vulnerabilities to turn Bixby against Samsung phones, achieving remote system-level compromise.

Runtime Rebel Intel
3 min read · Aug 6, 2026
HIGH
Vulnerabilities

KARR Security System: Bluetooth Vulnerability Allows Remote Car Hijacking

Researchers discovered a critical Bluetooth vulnerability in KARR Security Systems, allowing attackers to silently bypass car entry and disable ignition.

Runtime Rebel Intel
4 min read · Aug 5, 2026
CRITICAL
Vulnerabilities

CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities

CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.

Runtime Rebel Intel
4 min read · Aug 5, 2026
HIGH
Vulnerabilities

CVE-2026-34486: Apache Tomcat Encryption Bypass – Detection and Mitigation Guide

Apache Tomcat CVE-2026-34486 enables EncryptInterceptor bypass, exposing sensitive data; learn impact, detection, and remediation steps.

Runtime Rebel Intel
3 min read · Aug 4, 2026
CRITICAL
Vulnerabilities

CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited

CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.

Runtime Rebel Intel
4 min read · Aug 4, 2026
LOW
Vulnerabilities

Botnet Targets Diagnostic Tools: Preventing OS Command Injection

A botnet is actively scanning for vulnerabilities in web-accessible diagnostic tools.

Runtime Rebel Intel
5 min read · Aug 4, 2026
Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data
HIGH
Vulnerabilities

Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data

A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.

Runtime Rebel Intel
4 min read · Aug 4, 2026
HIGH
Vulnerabilities

Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets

Pillar Security uncovered agent-to-agent RCE flaws in Google's ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.

Runtime Rebel Intel
5 min read · Aug 4, 2026
CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation
HIGH
Vulnerabilities

CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation

A critical flaw in cPanel & WHM (CVE-2026-58048) allows authenticated users to execute SQL as database root, potentially leading to OS-level compromise.

Runtime Rebel Intel
4 min read · Aug 4, 2026
CVE-2026-18577: Attackers Exploit N-able Patch Bypass
HIGH
Vulnerabilities

CVE-2026-18577: Attackers Exploit N-able Patch Bypass

Security teams face active exploitation of CVE-2026-18577, an N-able authentication bypass vulnerability granting administrator access.

Runtime Rebel Intel
3 min read · Aug 4, 2026
CRITICAL
Vulnerabilities

CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now

CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…

Runtime Rebel Intel
4 min read · Aug 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now

CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.

Runtime Rebel Intel
4 min read · Aug 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw

CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…

Runtime Rebel Intel
4 min read · Aug 2, 2026
Coldcard Firmware Flaw Enables $70M Bitcoin Theft
CRITICAL
Vulnerabilities

Coldcard Firmware Flaw Enables $70M Bitcoin Theft

A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.

Runtime Rebel Intel
3 min read · Aug 1, 2026
HIGH
Vulnerabilities

Rails Active Storage RCE via Critical Flaw — Patch Now

A critical flaw in Rails Active Storage permits unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.

Runtime Rebel Intel
4 min read · Aug 1, 2026