<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Active Exploitation</title><description>Cybersecurity articles tagged #Active Exploitation on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-48710: Kludex Starlette HTTP Smuggling for Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2026-48710-kludex-starlette-http-smuggling-for-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48710-kludex-starlette-http-smuggling-for-auth-bypass</guid><description>CVE-2026-48710 impacts Kludex Starlette, enabling HTTP request smuggling and authentication bypass via path injection. Actively exploited.</description><pubDate>Wed, 02 Sep 2026 19:10:47 GMT</pubDate><category>Authentication Bypass</category><category>Active Exploitation</category><category>CVE-2026-48710</category><category>Kludex Starlette</category><category>HTTP Request Smuggling</category></item><item><title>CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-82078-papercut-ng-mf-unsafe-reflection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82078-papercut-ng-mf-unsafe-reflection-exploit</guid><description>CISA adds CVE-2026-82078 in PaperCut NG/MF to its KEV catalog following active exploitation. Review technical details and patch now.</description><pubDate>Tue, 01 Sep 2026 02:54:42 GMT</pubDate><category>CVE-2026-82078</category><category>PaperCut</category><category>Unsafe Reflection</category><category>Active Exploitation</category><category>Zero-Day</category></item><item><title>CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</guid><description>Attackers are actively exploiting a critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator, leading to arbitrary code…</description><pubDate>Tue, 28 Jul 2026 06:28:55 GMT</pubDate><category>CVE-2026-16812</category><category>Arista VeloCloud Orchestrator</category><category>Command Injection</category><category>RCE</category><category>Active Exploitation</category></item><item><title>CVE-2026-29059: Windmill Unauthenticated Path Traversal Exploit</title><link>https://runtimerebel.com/blog/cve-2026-29059-windmill-unauthenticated-path-traversal-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-29059-windmill-unauthenticated-path-traversal-exploit</guid><description>Attackers are exploiting CVE-2026-29059 in Windmill&apos;s get_log_file endpoint to read sensitive server files without authentication. Patch immediately.</description><pubDate>Wed, 22 Jul 2026 13:59:27 GMT</pubDate><category>CVE-2026-29059</category><category>Windmill</category><category>Path Traversal</category><category>Active Exploitation</category></item><item><title>WP2Shell Vulnerabilities CVE-2026-60137 &amp; CVE-2026-63030 Exploited</title><link>https://runtimerebel.com/blog/wp2shell-vulnerabilities-cve-2026-60137-cve-2026-63030-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-vulnerabilities-cve-2026-60137-cve-2026-63030-exploited</guid><description>WordPress sites face active exploitation via WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030. Learn the technical details and mitigation steps.</description><pubDate>Mon, 20 Jul 2026 06:49:53 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>RCE</category><category>Active Exploitation</category></item><item><title>Zimbra Classic Web Client XSS: Critical Flaw Under Active Exploit</title><link>https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</guid><description>A critical XSS vulnerability in Zimbra Classic Web Client is under active exploitation, allowing credential theft and session hijacking.</description><pubDate>Fri, 10 Jul 2026 14:31:43 GMT</pubDate><category>Zimbra</category><category>XSS</category><category>Classic Web Client</category><category>Zimbra Collaboration Suite</category><category>Active Exploitation</category></item><item><title>Gitea CVE-2026-20896 Authentication Bypass Under Active Exploitation</title><link>https://runtimerebel.com/blog/gitea-cve-2026-20896-authentication-bypass-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitea-cve-2026-20896-authentication-bypass-under-active-exploitation</guid><description>Attackers are exploiting CVE-2026-20896 in Gitea to bypass authentication via HTTP headers, risking unauthorized access to private code and secrets.</description><pubDate>Wed, 08 Jul 2026 10:28:08 GMT</pubDate><category>Gitea</category><category>CVE-2026-20896</category><category>Authentication Bypass</category><category>Active Exploitation</category></item><item><title>CVE-2026-48282: Adobe ColdFusion Path Traversal RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</guid><description>CISA adds actively exploited Adobe ColdFusion vulnerability [CVE-2026-48282] to KEV catalog, warning of critical remote code execution risks.</description><pubDate>Wed, 08 Jul 2026 06:30:23 GMT</pubDate><category>CVE-2026-48282</category><category>Adobe ColdFusion</category><category>Path Traversal</category><category>RCE</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>NetScaler Memory Disclosure Flaw Under Active Exploitation</title><link>https://runtimerebel.com/blog/netscaler-memory-disclosure-flaw-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/netscaler-memory-disclosure-flaw-under-active-exploitation</guid><description>Attackers are actively exploiting a new memory disclosure flaw in Citrix NetScaler products, rapidly weaponizing a public proof-of-concept.</description><pubDate>Mon, 06 Jul 2026 21:41:04 GMT</pubDate><category>Citrix NetScaler</category><category>Memory Disclosure</category><category>Active Exploitation</category><category>PoC</category></item><item><title>Cisco Unified Communications Manager: Urgent Patch for Active Exploitation</title><link>https://runtimerebel.com/blog/cisco-unified-communications-manager-urgent-patch-for-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-unified-communications-manager-urgent-patch-for-active-exploitation</guid><description>CISA mandates urgent patching for an actively exploited vulnerability in Cisco Unified Communications Manager, posing immediate risk to federal agencies and beyond.</description><pubDate>Fri, 26 Jun 2026 20:39:28 GMT</pubDate><category>Cisco Unified Communications Manager</category><category>CISA</category><category>Active Exploitation</category><category>UC Manager</category><category>Vulnerability Management</category></item><item><title>Cisco CUCM SSRF Flaw: Rapid Exploitation &amp; Root Privilege Escalation</title><link>https://runtimerebel.com/blog/cisco-cucm-ssrf-flaw-rapid-exploitation-root-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-cucm-ssrf-flaw-rapid-exploitation-root-privilege-escalation</guid><description>Attackers are rapidly weaponizing a Cisco Unified CM server-side request forgery (SSRF) flaw, escalating privileges to root. Immediate patching is critical.</description><pubDate>Fri, 26 Jun 2026 05:32:30 GMT</pubDate><category>Cisco Unified CM</category><category>Cisco Unified CM SME</category><category>SSRF</category><category>Privilege Escalation</category><category>Root Access</category><category>Active Exploitation</category></item><item><title>CVE-2024-20230: Critical RCE in Cisco Unified CM Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2024-20230-critical-rce-in-cisco-unified-cm-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-20230-critical-rce-in-cisco-unified-cm-actively-exploited</guid><description>Cisco confirms active exploitation of CVE-2024-20230, a critical 9.9 CVSS vulnerability in Unified Communications Manager. Urgent patching is required.</description><pubDate>Wed, 24 Jun 2026 09:17:44 GMT</pubDate><category>CVE-2024-20230</category><category>Cisco Unified CM</category><category>RCE</category><category>Active Exploitation</category><category>UC Security</category></item><item><title>CVE-2026-54420: LiteSpeed cPanel Plugin Flaw Under Active Exploit</title><link>https://runtimerebel.com/blog/cve-2026-54420-litespeed-cpanel-plugin-flaw-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-54420-litespeed-cpanel-plugin-flaw-under-active-exploit</guid><description>CISA warns of active exploitation targeting CVE-2026-54420 in LiteSpeed cPanel user-end plugin, urging immediate patching for server security.</description><pubDate>Tue, 16 Jun 2026 13:58:29 GMT</pubDate><category>CVE-2026-54420</category><category>LiteSpeed</category><category>cPanel</category><category>Active Exploitation</category><category>CISA</category><category>Web Hosting</category></item><item><title>Fortinet FortiSandbox: Attackers Exploit CVE-2026-39813, -39808, -25089</title><link>https://runtimerebel.com/blog/fortinet-fortisandbox-attackers-exploit-cve-2026-39813-39808-25089</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-fortisandbox-attackers-exploit-cve-2026-39813-39808-25089</guid><description>Critical Fortinet FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are under active exploitation. Patch immediately.</description><pubDate>Tue, 16 Jun 2026 13:57:36 GMT</pubDate><category>Fortinet</category><category>FortiSandbox</category><category>CVE-2026-39813</category><category>CVE-2026-39808</category><category>CVE-2026-25089</category><category>Path Traversal</category><category>Active Exploitation</category></item><item><title>Critical Fortinet, Apache, Cisco IOS XE Vulnerabilities: Patch &amp; Monitor</title><link>https://runtimerebel.com/blog/critical-fortinet-apache-cisco-ios-xe-vulnerabilities-patch-monitor</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-fortinet-apache-cisco-ios-xe-vulnerabilities-patch-monitor</guid><description>Alert: New critical vulnerabilities impact FortiClient, FortiNAC, and Apache products. Cisco IOS XE continues to face active exploitation. Urgent patching is required.</description><pubDate>Fri, 05 Jun 2026 05:38:47 GMT</pubDate><category>Forticlient</category><category>Fortinac</category><category>Apache</category><category>Cisco Ios Xe</category><category>Vulnerability</category><category>Active Exploitation</category><category>Patching</category></item><item><title>CVE-2024-21182: Oracle WebLogic Server Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2024-21182-oracle-weblogic-server-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21182-oracle-weblogic-server-under-active-exploitation</guid><description>CISA added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its KEV Catalog due to active exploitation. Immediate patching required.</description><pubDate>Mon, 01 Jun 2026 18:11:46 GMT</pubDate><category>CVE-2024-21182</category><category>Oracle WebLogic Server</category><category>CISA KEV</category><category>Active Exploitation</category><category>Unspecified Vulnerability</category></item><item><title>Palo Alto PAN-OS GlobalProtect VPN: Active Auth Bypass Exploitation</title><link>https://runtimerebel.com/blog/palo-alto-pan-os-globalprotect-vpn-active-auth-bypass-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/palo-alto-pan-os-globalprotect-vpn-active-auth-bypass-exploitation</guid><description>Urgent advisory on the active exploitation of an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect VPN. Patch immediately.</description><pubDate>Mon, 01 Jun 2026 18:09:49 GMT</pubDate><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect VPN</category><category>Authentication Bypass</category><category>Active Exploitation</category><category>VPN Vulnerability</category></item><item><title>CVE-2024-10642: WP Maps Pro Exploited to Create WordPress Admin Accounts</title><link>https://runtimerebel.com/blog/cve-2024-10642-wp-maps-pro-exploited-to-create-wordpress-admin-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-10642-wp-maps-pro-exploited-to-create-wordpress-admin-accounts</guid><description>Attackers are exploiting a critical privilege escalation flaw in the WP Maps Pro WordPress plugin to create rogue admin accounts without authentication.</description><pubDate>Sun, 31 May 2026 16:31:35 GMT</pubDate><category>CVE-2024-10642</category><category>WordPress</category><category>WP Maps Pro</category><category>Privilege Escalation</category><category>Active Exploitation</category></item><item><title>CVE-2026-0257: Palo Alto PAN-OS Auth Bypass Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-0257-palo-alto-pan-os-auth-bypass-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0257-palo-alto-pan-os-auth-bypass-under-active-attack</guid><description>CISA adds CVE-2026-0257, an actively exploited authentication bypass in Palo Alto Networks PAN-OS, to its KEV catalog.</description><pubDate>Fri, 29 May 2026 20:55:29 GMT</pubDate><category>CVE-2026-0257</category><category>Palo Alto Networks</category><category>PAN OS</category><category>Authentication Bypass</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>Ghost CMS CVE-2022-41654: Over 700 Websites Compromised</title><link>https://runtimerebel.com/blog/ghost-cms-cve-2022-41654-over-700-websites-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/ghost-cms-cve-2022-41654-over-700-websites-compromised</guid><description>Attackers are exploiting a critical Ghost CMS vulnerability to inject malicious scripts into sites belonging to Harvard, Oxford, and DuckDuckGo.</description><pubDate>Mon, 25 May 2026 16:50:54 GMT</pubDate><category>Ghost CMS</category><category>CVE-2022-41654</category><category>Active Exploitation</category><category>Web Security</category></item><item><title>CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-9082-drupal-core-sql-injection-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-9082-drupal-core-sql-injection-under-active-exploitation</guid><description>CISA adds CVE-2026-9082, a critical Drupal Core SQL Injection vulnerability, to KEV Catalog due to active exploitation. Immediate patching required for all organizations.</description><pubDate>Sat, 23 May 2026 00:55:48 GMT</pubDate><category>CVE-2026-9082</category><category>Drupal</category><category>SQL Injection</category><category>CISA KEV Catalog</category><category>Active Exploitation</category></item><item><title>CVE-2026-9082: Drupal Under Active Exploitation – Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-9082-drupal-under-active-exploitation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-9082-drupal-under-active-exploitation-patch-now</guid><description>Critical Drupal vulnerability CVE-2026-9082 is actively exploited shortly after disclosure. Urgent patching is required to prevent compromise of thousands of websites.</description><pubDate>Fri, 22 May 2026 20:38:07 GMT</pubDate><category>CVE-2026-9082</category><category>Drupal</category><category>Web Vulnerability</category><category>Active Exploitation</category><category>CMS Security</category></item><item><title>Microsoft Defender CVE-2026-41091 Privilege Escalation Exploited</title><link>https://runtimerebel.com/blog/microsoft-defender-cve-2026-41091-privilege-escalation-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-cve-2026-41091-privilege-escalation-exploited</guid><description>Microsoft warns of active exploitation of CVE-2026-41091 in Defender, a privilege escalation flaw allowing attackers to gain SYSTEM privileges on Windows.</description><pubDate>Thu, 21 May 2026 13:16:31 GMT</pubDate><category>CVE-2026-41091</category><category>Microsoft Defender</category><category>Privilege Escalation</category><category>Active Exploitation</category></item><item><title>CVE-2026-42897: Microsoft Exchange XSS Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-xss-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42897-microsoft-exchange-xss-under-active-exploitation</guid><description>CISA adds CVE-2026-42897, a Microsoft Exchange Server Cross-Site Scripting vulnerability, to KEV Catalog due to active exploitation. Immediate patching advised.</description><pubDate>Fri, 15 May 2026 20:32:11 GMT</pubDate><category>CVE-2026-42897</category><category>Microsoft Exchange Server</category><category>Cross Site Scripting</category><category>XSS</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>PraisonAI Auth Bypass CVE-2026-44338 Exploited — Patching Guide</title><link>https://runtimerebel.com/blog/praisonai-auth-bypass-cve-2026-44338-exploited-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/praisonai-auth-bypass-cve-2026-44338-exploited-patching-guide</guid><description>Threat actors are actively exploiting CVE-2026-44338, a critical authentication bypass in the PraisonAI framework, just hours after public disclosure.</description><pubDate>Thu, 14 May 2026 12:45:06 GMT</pubDate><category>CVE-2026-44338</category><category>PraisonAI</category><category>Auth Bypass</category><category>AI Security</category><category>Active Exploitation</category></item><item><title>cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor</title><link>https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploited-for-authentication-bypass-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploited-for-authentication-bypass-backdoor</guid><description>A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.</description><pubDate>Mon, 11 May 2026 20:39:59 GMT</pubDate><category>CVE-2026-41940</category><category>cPanel</category><category>WebHost Manager</category><category>Mr Rot13</category><category>Filemanager Backdoor</category><category>Authentication Bypass</category><category>Active Exploitation</category></item><item><title>Ivanti EPMM RCE via CVE-2026-6973 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ivanti-epmm-rce-via-cve-2026-6973-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-epmm-rce-via-cve-2026-6973-mitigation-guide</guid><description>Ivanti warns of active exploitation of CVE-2026-6973, a high-severity RCE flaw in Endpoint Manager Mobile (EPMM) allowing admin-level access on core servers.</description><pubDate>Thu, 07 May 2026 20:32:01 GMT</pubDate><category>CVE-2026-6973</category><category>Ivanti EPMM</category><category>RCE</category><category>Active Exploitation</category><category>MDM Security</category></item><item><title>CVE-2026-0300: Palo Alto Networks PAN-OS Out-of-bounds Write Exploit</title><link>https://runtimerebel.com/blog/cve-2026-0300-palo-alto-networks-pan-os-out-of-bounds-write-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-0300-palo-alto-networks-pan-os-out-of-bounds-write-exploit</guid><description>CISA adds CVE-2026-0300, a Palo Alto Networks PAN-OS out-of-bounds write vulnerability, to its KEV Catalog due to active exploitation.</description><pubDate>Wed, 06 May 2026 20:37:19 GMT</pubDate><category>CVE-2026-0300</category><category>Palo Alto Networks</category><category>PAN OS</category><category>Out of Bounds Write</category><category>KEV Catalog</category><category>Active Exploitation</category></item><item><title>CVE-2026-31431: Linux Kernel Resource Transfer Vulnerability Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-31431-linux-kernel-resource-transfer-vulnerability-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-31431-linux-kernel-resource-transfer-vulnerability-actively-exploited</guid><description>CISA adds CVE-2026-31431, a Linux Kernel incorrect resource transfer vulnerability, to its KEV catalog due to active exploitation. Prioritize remediation.</description><pubDate>Fri, 01 May 2026 20:24:29 GMT</pubDate><category>CVE-2026-31431</category><category>Linux Kernel</category><category>Resource Transfer</category><category>CISA KEV</category><category>Active Exploitation</category><category>BOD 22 01</category></item><item><title>CVE-2026-32202: Active Exploitation of Windows Shell Spoofing Bug</title><link>https://runtimerebel.com/blog/cve-2026-32202-active-exploitation-of-windows-shell-spoofing-bug</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-32202-active-exploitation-of-windows-shell-spoofing-bug</guid><description>Microsoft confirms CVE-2026-32202, a Windows Shell spoofing flaw, is under active exploitation. Read our analysis and mitigation guide for enterprise security.</description><pubDate>Tue, 28 Apr 2026 08:56:52 GMT</pubDate><category>CVE-2026-32202</category><category>Windows Shell</category><category>Microsoft</category><category>Spoofing</category><category>Active Exploitation</category></item><item><title>LMDeploy SSRF: CVE-2026-33626 Exploit and Mitigation Guide</title><link>https://runtimerebel.com/blog/lmdeploy-ssrf-cve-2026-33626-exploit-and-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/lmdeploy-ssrf-cve-2026-33626-exploit-and-mitigation-guide</guid><description>Attackers are actively exploiting CVE-2026-33626, a high-severity SSRF in LMDeploy, to access sensitive LLM data. Learn how to detect and patch this flaw.</description><pubDate>Fri, 24 Apr 2026 08:48:12 GMT</pubDate><category>CVE-2026-33626</category><category>LMDeploy</category><category>SSRF</category><category>LLM Security</category><category>Active Exploitation</category></item><item><title>CVE-2024-57353: Nginx UI Auth Bypass Actively Exploited — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-57353-nginx-ui-auth-bypass-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-57353-nginx-ui-auth-bypass-actively-exploited-patch-now</guid><description>Attackers are exploiting CVE-2024-57353, a critical authentication bypass in Nginx UI, to achieve full server takeover. Update to v2.0.0.beta.39 immediately.</description><pubDate>Thu, 16 Apr 2026 00:46:34 GMT</pubDate><category>CVE-2024-57353</category><category>Nginx UI</category><category>Authentication Bypass</category><category>RCE</category><category>Active Exploitation</category></item><item><title>Adobe Acrobat &amp; Reader Zero-Day Exploitation: Immediate Patch Required</title><link>https://runtimerebel.com/blog/adobe-acrobat-reader-zero-day-exploitation-immediate-patch-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/adobe-acrobat-reader-zero-day-exploitation-immediate-patch-required</guid><description>Adobe has patched an actively exploited Zero-Day in Acrobat and Reader. Attackers used crafted PDF files for at least four months. Update immediately.</description><pubDate>Tue, 14 Apr 2026 00:46:27 GMT</pubDate><category>Adobe Acrobat</category><category>Adobe Reader</category><category>Zero-Day</category><category>PDF</category><category>Active Exploitation</category></item><item><title>Adobe Acrobat Reader RCE via CVE-2026-34621 - Patch Now</title><link>https://runtimerebel.com/blog/adobe-acrobat-reader-rce-via-cve-2026-34621-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/adobe-acrobat-reader-rce-via-cve-2026-34621-patch-now</guid><description>Adobe issues emergency patches for CVE-2026-34621 in Acrobat Reader. This critical vulnerability is under active exploitation, allowing remote code execution.</description><pubDate>Sun, 12 Apr 2026 08:22:44 GMT</pubDate><category>CVE-2026-34621</category><category>Adobe Acrobat Reader</category><category>RCE</category><category>Active Exploitation</category><category>Emergency Patch</category></item><item><title>CVE-2026-1340: Ivanti EPMM Code Injection — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-1340-ivanti-epmm-code-injection-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-1340-ivanti-epmm-code-injection-patch-now</guid><description>CISA adds CVE-2026-1340, a critical code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM), to its KEV Catalog due to active exploitation.</description><pubDate>Thu, 09 Apr 2026 00:36:46 GMT</pubDate><category>CVE-2026-1340</category><category>Ivanti EPMM</category><category>Code Injection</category><category>Active Exploitation</category><category>CISA KEV</category></item><item><title>Ninja Forms RCE via Arbitrary File Upload: Mitigation Guide</title><link>https://runtimerebel.com/blog/ninja-forms-rce-via-arbitrary-file-upload-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ninja-forms-rce-via-arbitrary-file-upload-mitigation-guide</guid><description>Hackers are actively exploiting a critical Ninja Forms vulnerability to upload arbitrary files and achieve RCE. Learn how to secure your WordPress site now.</description><pubDate>Wed, 08 Apr 2026 12:28:42 GMT</pubDate><category>WordPress</category><category>Ninja Forms</category><category>Remote Code Execution</category><category>Active Exploitation</category><category>File Upload</category></item><item><title>FortiClient EMS RCE via CVE-2026-35616 — Mitigation Guide</title><link>https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2026-35616-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-rce-via-cve-2026-35616-mitigation-guide</guid><description>Fortinet releases emergency patches for CVE-2026-35616, a critical SQL injection flaw in FortiClient EMS exploited to achieve unauthenticated RCE.</description><pubDate>Sun, 05 Apr 2026 20:12:25 GMT</pubDate><category>CVE-2026-35616</category><category>Fortinet</category><category>FortiClient EMS</category><category>RCE</category><category>Active Exploitation</category></item><item><title>CVE-2026-3055: Citrix NetScaler Out-of-Bounds Read Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-3055-citrix-netscaler-out-of-bounds-read-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3055-citrix-netscaler-out-of-bounds-read-under-active-exploitation</guid><description>CISA adds CVE-2026-3055, an actively exploited Citrix NetScaler Out-of-Bounds Read vulnerability, to its KEV Catalog, urging immediate remediation.</description><pubDate>Mon, 30 Mar 2026 20:19:34 GMT</pubDate><category>CVE-2026-3055</category><category>Citrix NetScaler</category><category>Out of Bounds Read</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>F5 BIG-IP RCE via CVE-2023-46747 — Mitigation and Exploitation Guide</title><link>https://runtimerebel.com/blog/f5-big-ip-rce-via-cve-2023-46747-mitigation-and-exploitation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/f5-big-ip-rce-via-cve-2023-46747-mitigation-and-exploitation-guide</guid><description>Exploit analysis of the critical F5 BIG-IP authentication bypass (CVE-2023-46747). Learn how to detect webshell deployment and apply essential security patches.</description><pubDate>Mon, 30 Mar 2026 12:31:42 GMT</pubDate><category>CVE-2023-46747</category><category>F5 BIG IP</category><category>RCE</category><category>Auth Bypass</category><category>Active Exploitation</category></item><item><title>Langflow AI Platform: Critical Code Injection Under Active Attack</title><link>https://runtimerebel.com/blog/langflow-ai-platform-critical-code-injection-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/langflow-ai-platform-critical-code-injection-under-active-attack</guid><description>Threat actors are actively exploiting a critical code injection vulnerability in the Langflow AI platform, demanding immediate patching to prevent compromise.</description><pubDate>Thu, 26 Mar 2026 20:15:10 GMT</pubDate><category>Langflow</category><category>AI</category><category>Code Injection</category><category>Active Exploitation</category><category>Critical Vulnerability</category></item><item><title>Langflow CVE-2026-33017: AI Workflow Hijacking Under Active Exploitation</title><link>https://runtimerebel.com/blog/langflow-cve-2026-33017-ai-workflow-hijacking-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/langflow-cve-2026-33017-ai-workflow-hijacking-under-active-exploitation</guid><description>CISA warns of active exploitation of CVE-2026-33017 in Langflow, enabling attackers to hijack AI workflows and potentially compromise AI agents.</description><pubDate>Thu, 26 Mar 2026 20:14:50 GMT</pubDate><category>Langflow</category><category>CVE-2026-33017</category><category>AI Security</category><category>Workflow Hijacking</category><category>Active Exploitation</category><category>CISA</category></item><item><title>CVE-2026-33017: Langflow Code Injection - Patch Immediately</title><link>https://runtimerebel.com/blog/cve-2026-33017-langflow-code-injection-patch-immediately</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33017-langflow-code-injection-patch-immediately</guid><description>CISA adds actively exploited Langflow Code Injection Vulnerability (CVE-2026-33017) to KEV catalog. Critical patch urged for all organizations.</description><pubDate>Wed, 25 Mar 2026 20:18:12 GMT</pubDate><category>CVE-2026-33017</category><category>Langflow</category><category>Code Injection</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance</title><link>https://runtimerebel.com/blog/quest-kace-sma-cve-2025-32975-exploited-critical-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/quest-kace-sma-cve-2025-32975-exploited-critical-patch-guidance</guid><description>Threat actors are exploiting a critical CVSS 10.0 vulnerability, CVE-2025-32975, in Quest KACE Systems Management Appliances exposed to the internet.</description><pubDate>Mon, 23 Mar 2026 08:25:12 GMT</pubDate><category>CVE-2025-32975</category><category>Quest Software</category><category>KACE SMA</category><category>Remote Code Execution</category><category>Active Exploitation</category></item><item><title>CVE-2026-33017: Critical Langflow RCE Exploited within 20 Hours</title><link>https://runtimerebel.com/blog/cve-2026-33017-critical-langflow-rce-exploited-within-20-hours</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33017-critical-langflow-rce-exploited-within-20-hours</guid><description>CVE-2026-33017 is a critical RCE vulnerability in Langflow currently under active exploitation. Learn how to secure your AI orchestration and detect attacks.</description><pubDate>Fri, 20 Mar 2026 16:18:45 GMT</pubDate><category>CVE-2026-33017</category><category>Langflow</category><category>RCE</category><category>AI Security</category><category>Active Exploitation</category></item><item><title>CVE-2026-20963: Microsoft SharePoint Deserialization Exploit — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-20963-microsoft-sharepoint-deserialization-exploit-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20963-microsoft-sharepoint-deserialization-exploit-patch-now</guid><description>CISA adds CVE-2026-20963, a Microsoft SharePoint deserialization vulnerability, to its KEV catalog due to active exploitation.</description><pubDate>Wed, 18 Mar 2026 20:17:46 GMT</pubDate><category>CVE-2026-20963</category><category>Microsoft SharePoint</category><category>Deserialization Vulnerability</category><category>KEV Catalog</category><category>Active Exploitation</category></item><item><title>CISA KEV Update: Five Actively Exploited CVEs in Apple, Hikvision, Rockwell</title><link>https://runtimerebel.com/blog/cisa-kev-update-five-actively-exploited-cves-in-apple-hikvision-rockwell</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-update-five-actively-exploited-cves-in-apple-hikvision-rockwell</guid><description>CISA adds five actively exploited vulnerabilities, including Apple iOS/iPadOS use-after-free and Hikvision improper authentication, to its KEV Catalog.</description><pubDate>Thu, 05 Mar 2026 20:18:17 GMT</pubDate><category>CVE-2017-7921</category><category>CVE-2021-22681</category><category>CVE-2021-30952</category><category>CVE-2023-41974</category><category>CVE-2023-43000</category><category>CISA KEV Catalog</category><category>Hikvision</category><category>Rockwell Automation</category><category>Apple iOS</category><category>Apple iPadOS</category><category>Vulnerability Management</category><category>Active Exploitation</category><category>Improper Authentication</category><category>Use After Free</category></item><item><title>Cisco Catalyst SD-WAN Manager CVE-2023-20252 — Mitigation Guide</title><link>https://runtimerebel.com/blog/cisco-catalyst-sd-wan-manager-cve-2023-20252-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-catalyst-sd-wan-manager-cve-2023-20252-mitigation-guide</guid><description>Cisco warns of active exploitation targeting Catalyst SD-WAN Manager vulnerabilities CVE-2023-20252 and CVE-2023-20253. Immediate patching is required.</description><pubDate>Thu, 05 Mar 2026 12:19:33 GMT</pubDate><category>Cisco</category><category>SD WAN</category><category>CVE-2023-20252</category><category>CVE-2023-20253</category><category>Active Exploitation</category></item><item><title>Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access</title><link>https://runtimerebel.com/blog/cisco-sd-wan-zero-day-cve-2026-20127-exploited-for-admin-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-sd-wan-zero-day-cve-2026-20127-exploited-for-admin-access</guid><description>CVE-2026-20127 is a critical CVSS 10.0 flaw in Cisco SD-WAN controllers exploited since 2023, allowing unauthenticated remote administrative access.</description><pubDate>Thu, 26 Feb 2026 08:18:56 GMT</pubDate><category>CVE-2026-20127</category><category>Cisco</category><category>SD WAN</category><category>vManage</category><category>vSmart</category><category>Zero-Day</category><category>Active Exploitation</category></item><item><title>CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog</title><link>https://runtimerebel.com/blog/cisa-adds-two-cisco-sd-wan-exploits-to-kev-catalog</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-adds-two-cisco-sd-wan-exploits-to-kev-catalog</guid><description>CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.</description><pubDate>Wed, 25 Feb 2026 20:17:03 GMT</pubDate><category>CVE-2022-20775</category><category>CVE-2026-20127</category><category>Cisco Catalyst SD WAN</category><category>CISA KEV</category><category>Active Exploitation</category><category>Path Traversal</category><category>Authentication Bypass</category></item><item><title>CISA Alert: CVE-2026-25108 Soliton FileZen OS Command Injection Exploited</title><link>https://runtimerebel.com/blog/cisa-alert-cve-2026-25108-soliton-filezen-os-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-alert-cve-2026-25108-soliton-filezen-os-command-injection-exploited</guid><description>CISA adds CVE-2026-25108, a Soliton Systems FileZen OS Command Injection vulnerability, to KEV Catalog due to active exploitation. Immediate remediation advised.</description><pubDate>Wed, 25 Feb 2026 04:44:11 GMT</pubDate><category>CVE-2026-25108</category><category>Soliton Systems</category><category>FileZen OS</category><category>Command Injection</category><category>KEV Catalog</category><category>Active Exploitation</category></item></channel></rss>