Skip to main content
← All Articles

Category

Vulnerabilities

851 articles

Advertisement

VU
CRITICAL
Vulnerabilities

CVE-2024-40766: SonicWall SonicOS Patch and Configuration Guide

Analysis of CVE-2024-40766, a critical improper access control flaw in SonicWall SonicOS exploited by ransomware groups. Learn how to secure management interfaces.

Runtime Rebel Intel
3 min read · Jun 23, 2026
VU
HIGH
Vulnerabilities

Gravity SMTP Flaw Exploited: WordPress Data Harvest & Remediation

Attackers are actively exploiting a flaw in the Gravity SMTP WordPress plugin to exfiltrate sensitive data, including API keys and server info.

Runtime Rebel Intel
5 min read · Jun 22, 2026
VU
HIGH
Vulnerabilities

Squidbleed: Heartbleed-Style Data Exposure in Squid Proxy

A critical flaw dubbed Squidbleed in Squid Proxy, affecting versions 3.5-6.x, enables Heartbleed-style memory leakage exposing user credentials and session data.

Runtime Rebel Intel
5 min read · Jun 22, 2026
VU
HIGH
Vulnerabilities

Microsoft AutoGen Studio RCE via AutoJack Flaw — Patch Now

Microsoft patched the AutoJack vulnerability chain in AutoGen Studio, enabling remote code execution through malicious AI agent manipulation.

Runtime Rebel Intel
4 min read · Jun 22, 2026
Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests
HIGH
Vulnerabilities

Squidbleed: 29-Year-Old Squid Proxy Bug Leaks Cleartext HTTP Requests

A 29-year-old heap over-read vulnerability, dubbed 'Squidbleed,' in Squid web proxy's default configuration can leak cleartext HTTP requests and credentials.

Runtime Rebel Intel
5 min read · Jun 22, 2026
DifyTap Flaws Expose AI Chats in Dify Platform Without Auth
HIGH
Vulnerabilities

DifyTap Flaws Expose AI Chats in Dify Platform Without Auth

Zafran Security details DifyTap, a set of four vulnerabilities in Dify, allowing unauthenticated access to cross-tenant AI chat data. Learn impact and mitigation.

Runtime Rebel Intel
4 min read · Jun 22, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-0012: Critical PAN-OS Management Interface RCE Analysis

Technical analysis of CVE-2024-0012 affecting Palo Alto Networks PAN-OS. Learn how to detect CVE-2024-0012 exploit and implement immediate mitigation steps.

Runtime Rebel Intel
3 min read · Jun 22, 2026
VU
HIGH
Vulnerabilities

Apple A-Series BootROM Bypass: Usbliter8 Exploit Technical Analysis

Technical breakdown of the Usbliter8 exploit affecting millions of iPhones. Learn why this hardware-level BootROM vulnerability cannot be patched.

Runtime Rebel Intel
4 min read · Jun 22, 2026
CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys
MEDIUM
Vulnerabilities

CVE-2026-4020: Gravity SMTP Exploit Exposes WordPress API Keys

Unauthenticated attackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to extract API keys, secrets, and OAuth tokens from 100,000 sites.

Runtime Rebel Intel
3 min read · Jun 20, 2026
VU
HIGH
Vulnerabilities

CVE-2024-49403: Gravity SMTP Information Disclosure Patch Guidance

Exploitation of CVE-2024-49403 in the Gravity SMTP WordPress plugin allows unauthenticated actors to steal SMTP credentials. Learn how to secure your site now.

Runtime Rebel Intel
3 min read · Jun 20, 2026
usbliter8 Exploit Breaks Apple A12/A13 SecureROM Boot Chain
HIGH
Vulnerabilities

usbliter8 Exploit Breaks Apple A12/A13 SecureROM Boot Chain

Paradigm Shift researchers disclose 'usbliter8', an unpatchable hardware exploit enabling arbitrary code execution in Apple A12 and A13 SecureROM, requiring physical…

Runtime Rebel Intel
4 min read · Jun 19, 2026
VU
HIGH
Vulnerabilities

GCP Config Connector Takeover: Unpatched Flaw Critical for Cloud Environments

An unpatched flaw in GCP Config Connector poses a critical takeover risk to Google Cloud environments.

Runtime Rebel Intel
5 min read · Jun 19, 2026
AutoJack: AI Browsing Agents Hijacked for Host RCE via Web Pages
HIGH
Vulnerabilities

AutoJack: AI Browsing Agents Hijacked for Host RCE via Web Pages

Microsoft researchers reveal AutoJack, a novel exploit chain where malicious web pages hijack AI browsing agents to achieve remote code execution on host systems.

Runtime Rebel Intel
4 min read · Jun 19, 2026
CVE-2025-20701: Apple Patches Beats Studio Buds Eavesdropping Flaw
HIGH
Vulnerabilities

CVE-2025-20701: Apple Patches Beats Studio Buds Eavesdropping Flaw

Apple addresses CVE-2025-20701, a high-severity flaw in Beats Studio Buds allowing nearby attackers to bypass pairing consent and access the microphone.

Runtime Rebel Intel
4 min read · Jun 19, 2026
CVE-2026-42530 & -42531: NGINX RCE via Use-After-Free
HIGH
Vulnerabilities

CVE-2026-42530 & -42531: NGINX RCE via Use-After-Free

F5 addresses critical RCE flaws [CVE-2026-42530, CVE-2026-42531] in NGINX Open Source. Unauthenticated attackers can exploit use-after-free issues. Patch now.

Runtime Rebel Intel
4 min read · Jun 18, 2026
VU
HIGH
Vulnerabilities

Rockwell RSLinx <4.50.00 RCE via CVE-2020-13573 — Patch Now

Urgent advisory for Rockwell RSLinx Classic users. CVE-2020-13573, a stack-based buffer overflow, enables remote code execution and DoS. Patch <=4.50.00.

Runtime Rebel Intel
4 min read · Jun 18, 2026
VU
HIGH
Vulnerabilities

CVE-2026-11317: Rockwell Logix DoS via CIP — Patch Critical ICS

Critical Manufacturing faces high-severity DoS risk in Rockwell Automation Logix 5370 & 5570 controllers from CVE-2026-11317. Patch now.

Runtime Rebel Intel
4 min read · Jun 18, 2026
MongoBleed: Unauthenticated Credential Theft via Server Memory
HIGH
Vulnerabilities

MongoBleed: Unauthenticated Credential Theft via Server Memory

Analysis of MongoBleed, a critical vulnerability enabling unauthenticated credential and session token extraction from server memory, highlighting attack surface…

Runtime Rebel Intel
4 min read · Jun 17, 2026
Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft
HIGH
Vulnerabilities

Microsoft Copilot 'SearchLeak' Attack: AI Prompt Injection Data Theft

Analysis of the critical Microsoft Copilot 'SearchLeak' attack. Learn how prompt injection allowed 1-click data theft and crucial defense strategies for AI applications.

Runtime Rebel Intel
5 min read · Jun 16, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-54420: LiteSpeed cPanel Plugin Flaw Under Active Exploit

CISA warns of active exploitation targeting CVE-2026-54420 in LiteSpeed cPanel user-end plugin, urging immediate patching for server security.

Runtime Rebel Intel
4 min read · Jun 16, 2026
Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089
CRITICAL
Vulnerabilities

Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089

Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.

Runtime Rebel Intel
5 min read · Jun 16, 2026
VU
CRITICAL
Vulnerabilities

FortiSandbox RCE via CVE-2024-23108 and CVE-2024-23109 — Patch Now

Unauthenticated attackers are exploiting critical command injection flaws in Fortinet FortiSandbox to achieve RCE. Apply security updates immediately.

Runtime Rebel Intel
3 min read · Jun 16, 2026
Cisco Catalyst SD-WAN Manager CVE-2026-20262 Exploited in the Wild
HIGH
Vulnerabilities

Cisco Catalyst SD-WAN Manager CVE-2026-20262 Exploited in the Wild

Cisco patches an actively exploited medium-severity vulnerability in Catalyst SD-WAN Manager (CVE-2026-20262) that allows authenticated file creation.

Runtime Rebel Intel
4 min read · Jun 16, 2026
VU
HIGH
Vulnerabilities

CVE-2023-6110: Rogue Account Creation in SimpleHelp — Patch Now

Attackers can exploit an OIDC implementation flaw in SimpleHelp servers to create unauthorized technician accounts. Immediate update to 5.2.24 is required.

Runtime Rebel Intel
3 min read · Jun 16, 2026