<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Exploitation</title><description>Cybersecurity articles tagged #Exploitation on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens</title><link>https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</guid><description>Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 19:00:04 GMT</pubDate><category>CVE-2026-82329</category><category>JFrog Artifactory</category><category>Authentication Bypass</category><category>Supply Chain Attack</category><category>Exploitation</category></item><item><title>Zimbra CVE-2026-73570 Actively Exploited: Patch Now</title><link>https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</guid><description>Active exploitation targets Zimbra servers via CVE-2026-73570, a high-severity flaw allowing unauthenticated RCE. Patch to v10.1.20 now.</description><pubDate>Thu, 20 Aug 2026 16:24:30 GMT</pubDate><category>Zimbra</category><category>Exploitation</category><category>Remote Code Execution</category><category>CVE-2026-73570</category><category>Zimbra Collaboration Suite</category></item><item><title>Apple Screen Sharing Exploits: Secure Your macOS Systems Now</title><link>https://runtimerebel.com/blog/apple-screen-sharing-exploits-secure-your-macos-systems-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-screen-sharing-exploits-secure-your-macos-systems-now</guid><description>Critical vulnerabilities in Apple Screen Sharing are actively exploited, allowing system compromise. Learn how to secure macOS against these threats.</description><pubDate>Mon, 17 Aug 2026 16:20:27 GMT</pubDate><category>Apple</category><category>macOS</category><category>Exploitation</category><category>Remote Access</category><category>Screen Sharing</category></item><item><title>CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</guid><description>CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.</description><pubDate>Tue, 04 Aug 2026 17:33:39 GMT</pubDate><category>Authentication Bypass</category><category>CISA KEV</category><category>Exploitation</category><category>CVE-2026-18556</category><category>N Able N Central</category></item><item><title>Arista VeloCloud Orchestrator Zero-Day: Command Injection Exploited</title><link>https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</guid><description>Arista patches a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments, actively exploited in attacks.</description><pubDate>Tue, 28 Jul 2026 02:38:22 GMT</pubDate><category>Arista</category><category>VeloCloud Orchestrator</category><category>Command Injection</category><category>Zero-Day</category><category>Exploitation</category><category>Patching</category></item><item><title>2-Click Cursor Exploit: Dev Environment Takeover Risks &amp; Mitigations</title><link>https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</link><guid isPermaLink="true">https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</guid><description>Analyze the &apos;2-click cursor exploit&apos; leveraging &apos;age-old bugs&apos; to compromise developer environments, risking source code and IP theft.</description><pubDate>Wed, 15 Jul 2026 13:49:23 GMT</pubDate><category>Developer Environments</category><category>Supply Chain Security</category><category>Application Security</category><category>Exploitation</category><category>Source Code Theft</category></item><item><title>Apple&apos;s Accelerated Patch Policy: Responding to AI Exploit Generation</title><link>https://runtimerebel.com/blog/apple-s-accelerated-patch-policy-responding-to-ai-exploit-generation</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-s-accelerated-patch-policy-responding-to-ai-exploit-generation</guid><description>Apple is shifting to more frequent security updates in response to AI&apos;s ability to accelerate exploit development, demanding faster patching cycles from organizations.</description><pubDate>Fri, 03 Jul 2026 07:31:06 GMT</pubDate><category>Apple</category><category>Patching</category><category>AI</category><category>Exploitation</category><category>Vulnerability Management</category></item><item><title>Critical SimpleHelp Vulnerability Exploited for Malware Delivery</title><link>https://runtimerebel.com/blog/critical-simplehelp-vulnerability-exploited-for-malware-delivery</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-simplehelp-vulnerability-exploited-for-malware-delivery</guid><description>A critical vulnerability in SimpleHelp is actively exploited to deploy malware, targeting credentials, SSH keys, and crypto wallets. Immediate patching is essential.</description><pubDate>Tue, 30 Jun 2026 09:19:14 GMT</pubDate><category>SimpleHelp</category><category>Exploitation</category><category>Malware</category><category>Credentials</category><category>SSH Keys</category><category>Cryptocurrency</category><category>Remote Support</category></item><item><title>CISA Warns: Ubiquiti UniFi &amp; Lantronix Flaws Actively Exploited</title><link>https://runtimerebel.com/blog/cisa-warns-ubiquiti-unifi-lantronix-flaws-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-ubiquiti-unifi-lantronix-flaws-actively-exploited</guid><description>CISA warns of active exploitation against Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. Security professionals must patch immediately.</description><pubDate>Wed, 24 Jun 2026 16:51:17 GMT</pubDate><category>Ubiquiti</category><category>UniFi OS</category><category>Lantronix</category><category>CISA</category><category>Exploitation</category><category>Critical Vulnerability</category></item><item><title>CVE-2026-20230: Cisco Unified CM SSRF Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-20230-cisco-unified-cm-ssrf-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20230-cisco-unified-cm-ssrf-actively-exploited</guid><description>Cisco Unified CM Server is vulnerable to CVE-2026-20230, a high-severity SSRF flaw now under active exploitation. Patch immediately to prevent attacks.</description><pubDate>Wed, 24 Jun 2026 00:53:37 GMT</pubDate><category>CVE-2026-20230</category><category>Cisco Unified Communications Manager</category><category>SSRF</category><category>Exploitation</category><category>Vulnerability</category></item><item><title>Ivanti Sentry Max-Severity Flaw Exploited Within 24 Hours</title><link>https://runtimerebel.com/blog/ivanti-sentry-max-severity-flaw-exploited-within-24-hours</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-sentry-max-severity-flaw-exploited-within-24-hours</guid><description>A critical Ivanti Sentry vulnerability was actively exploited within 24 hours of public disclosure. Defenders must patch immediately to prevent compromise.</description><pubDate>Fri, 12 Jun 2026 09:41:02 GMT</pubDate><category>Ivanti Sentry</category><category>Critical Vulnerability</category><category>Zero-Day</category><category>Exploitation</category><category>Patch Management</category></item><item><title>ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances</title><link>https://runtimerebel.com/blog/servicenow-flaw-exploited-unauthenticated-access-to-customer-instances</link><guid isPermaLink="true">https://runtimerebel.com/blog/servicenow-flaw-exploited-unauthenticated-access-to-customer-instances</guid><description>ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances.</description><pubDate>Wed, 10 Jun 2026 09:34:05 GMT</pubDate><category>ServiceNow</category><category>Unauthorized Access</category><category>Cloud Security</category><category>Exploitation</category><category>Patching</category></item><item><title>FortiClient EMS Critical Flaw Exploited for Credential Stealing</title><link>https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</guid><description>Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.</description><pubDate>Thu, 28 May 2026 17:21:27 GMT</pubDate><category>FortiClient EMS</category><category>Credential Stealer</category><category>Endpoint Security</category><category>Exploitation</category><category>Malware</category></item><item><title>CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation - Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-48172-litespeed-cpanel-plugin-privilege-escalation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48172-litespeed-cpanel-plugin-privilege-escalation-patch-now</guid><description>Exploitation of CVE-2026-48172 in the LiteSpeed cPanel plugin allows local users to gain root access. Organizations should update to version 1.2.2 immediately.</description><pubDate>Sat, 23 May 2026 08:47:28 GMT</pubDate><category>CVE-2026-48172</category><category>LiteSpeed</category><category>cPanel</category><category>Privilege Escalation</category><category>Exploitation</category></item><item><title>Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits</title><link>https://runtimerebel.com/blog/pwn2own-berlin-microsoft-exchange-windows-11-zero-day-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/pwn2own-berlin-microsoft-exchange-windows-11-zero-day-exploits</guid><description>Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.</description><pubDate>Fri, 15 May 2026 20:31:42 GMT</pubDate><category>Pwn2own</category><category>Zero-Day</category><category>Microsoft Exchange</category><category>Windows 11</category><category>Red Hat Enterprise Linux</category><category>Exploitation</category></item><item><title>CVE-2023-2523: Weaver E-cology RCE Exploitation and Mitigation</title><link>https://runtimerebel.com/blog/cve-2023-2523-weaver-e-cology-rce-exploitation-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-2523-weaver-e-cology-rce-exploitation-and-mitigation</guid><description>Threat actors are exploiting critical file upload flaws in Weaver E-cology software to achieve RCE. Learn how to detect and patch CVE-2023-2523 today.</description><pubDate>Tue, 05 May 2026 00:47:06 GMT</pubDate><category>Weaver E Cology</category><category>CVE-2023-2523</category><category>CVE-2023-2648</category><category>RCE</category><category>Exploitation</category></item><item><title>April 2026 Patch Tuesday: SharePoint Zero-Day, BlueHammer, &amp; Adobe RCE</title><link>https://runtimerebel.com/blog/april-2026-patch-tuesday-sharepoint-zero-day-bluehammer-adobe-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/april-2026-patch-tuesday-sharepoint-zero-day-bluehammer-adobe-rce</guid><description>Microsoft&apos;s April 2026 Patch Tuesday addresses 167 vulnerabilities, including a SharePoint Server zero-day, Windows Defender &apos;BlueHammer&apos; flaw, and an actively exploited…</description><pubDate>Wed, 15 Apr 2026 00:45:50 GMT</pubDate><category>Microsoft</category><category>Windows</category><category>SharePoint Server</category><category>Windows Defender</category><category>Adobe Reader</category><category>Google Chrome</category><category>Patch Tuesday</category><category>Zero-Day</category><category>RCE</category><category>BlueHammer</category><category>Vulnerability</category><category>Exploitation</category></item><item><title>CISA KEV Remediation Exposes Human-Scale Security Limits</title><link>https://runtimerebel.com/blog/cisa-kev-remediation-exposes-human-scale-security-limits</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-remediation-exposes-human-scale-security-limits</guid><description>Analysis of 1 billion CISA KEV records by Qualys exposes critical vulnerabilities are often exploited before organizations can patch them, highlighting limits of…</description><pubDate>Fri, 10 Apr 2026 16:25:05 GMT</pubDate><category>CISA KEV</category><category>Vulnerability Management</category><category>Patch Management</category><category>Exploitation</category><category>Qualys</category><category>Automation</category></item><item><title>Ivanti CSA 4.6 Exploited via CVE-2024-9380: Migration Required</title><link>https://runtimerebel.com/blog/ivanti-csa-4-6-exploited-via-cve-2024-9380-migration-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-csa-4-6-exploited-via-cve-2024-9380-migration-required</guid><description>Attackers are actively exploiting Ivanti CSA 4.6 via CVE-2024-9379 and CVE-2024-9380. Learn how to detect these command injection exploits and migrate to version 5.0.</description><pubDate>Wed, 08 Apr 2026 08:35:31 GMT</pubDate><category>Ivanti</category><category>CVE-2024-9379</category><category>CVE-2024-9380</category><category>Command Injection</category><category>Exploitation</category></item><item><title>Vite Exposed Installs: Exploitation Attempts &amp; Mitigation for CVE-2025-30208</title><link>https://runtimerebel.com/blog/vite-exposed-installs-exploitation-attempts-mitigation-for-cve-2025-30208</link><guid isPermaLink="true">https://runtimerebel.com/blog/vite-exposed-installs-exploitation-attempts-mitigation-for-cve-2025-30208</guid><description>Runtime Rebel warns of active exploitation attempts targeting exposed Vite development environments. Learn about CVE-2025-30208 and critical mitigation steps.</description><pubDate>Thu, 02 Apr 2026 16:30:01 GMT</pubDate><category>Vite</category><category>CVE-2025-30208</category><category>Frontend Development</category><category>Exploitation</category><category>Misconfiguration</category><category>Development Environment Security</category></item><item><title>Google Chrome Zero-Day Patch: Fourth In-the-Wild Exploit</title><link>https://runtimerebel.com/blog/google-chrome-zero-day-patch-fourth-in-the-wild-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-zero-day-patch-fourth-in-the-wild-exploit</guid><description>Google has released an urgent security update for Chrome, patching the fourth zero-day vulnerability actively exploited in 2024. Update now to protect against…</description><pubDate>Wed, 01 Apr 2026 12:27:55 GMT</pubDate><category>Chrome</category><category>Zero-Day</category><category>Browser Security</category><category>Google</category><category>Vulnerability</category><category>Exploitation</category></item><item><title>Fortinet FortiClient EMS Critical SQLi Flaw Under Active Exploitation</title><link>https://runtimerebel.com/blog/fortinet-forticlient-ems-critical-sqli-flaw-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-forticlient-ems-critical-sqli-flaw-under-active-exploitation</guid><description>Critical SQL injection in FortiClient EMS allows unauthenticated remote code execution. Active exploitation detected, immediate patching required.</description><pubDate>Tue, 31 Mar 2026 12:31:11 GMT</pubDate><category>Fortinet</category><category>FortiClient EMS</category><category>SQL Injection</category><category>RCE</category><category>Exploitation</category></item><item><title>Fortinet BIG-IP RCE via CVE-2025-53521 — Patch Now</title><link>https://runtimerebel.com/blog/fortinet-big-ip-rce-via-cve-2025-53521-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-big-ip-rce-via-cve-2025-53521-patch-now</guid><description>Fortinet BIG-IP vulnerability CVE-2025-53521, initially a DoS, has been reclassified as a critical Remote Code Execution flaw.</description><pubDate>Mon, 30 Mar 2026 20:18:55 GMT</pubDate><category>Fortinet BIG IP</category><category>CVE-2025-53521</category><category>RCE</category><category>Exploitation</category></item><item><title>N8n Flaw Exploitation, Slopoly Malware, AppArmor LPE: Key Threats</title><link>https://runtimerebel.com/blog/n8n-flaw-exploitation-slopoly-malware-apparmor-lpe-key-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-flaw-exploitation-slopoly-malware-apparmor-lpe-key-threats</guid><description>Analysis of recent cybersecurity threats: actively exploited N8n flaw, Slopoly malware, Linux AppArmor root privilege vulnerability, and Telus Digital breach.</description><pubDate>Fri, 13 Mar 2026 16:20:49 GMT</pubDate><category>N8n</category><category>Slopoly</category><category>Malware</category><category>AppArmor</category><category>Linux</category><category>Privilege Escalation</category><category>Data Breach</category><category>Telus Digital</category><category>Exploitation</category></item><item><title>CVE-2026-20127: Cisco Catalyst SD-WAN Exploited — Patch Guide</title><link>https://runtimerebel.com/blog/cve-2026-20127-cisco-catalyst-sd-wan-exploited-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20127-cisco-catalyst-sd-wan-exploited-patch-guide</guid><description>WatchTowr reports widespread exploitation attempts targeting a recent CVE-2026-20127 vulnerability in Cisco Catalyst SD-WAN devices, urging immediate action.</description><pubDate>Sun, 08 Mar 2026 16:22:56 GMT</pubDate><category>Cisco</category><category>Catalyst SD WAN</category><category>CVE-2026-20127</category><category>Exploitation</category></item><item><title>CVE-2026-20122: Cisco Catalyst SD-WAN Manager Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-20122-cisco-catalyst-sd-wan-manager-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20122-cisco-catalyst-sd-wan-manager-exploited-in-the-wild</guid><description>Cisco confirms active exploitation of CVE-2026-20122 in Catalyst SD-WAN Manager, allowing authenticated attackers to perform arbitrary file overwrites.</description><pubDate>Thu, 05 Mar 2026 20:15:56 GMT</pubDate><category>Cisco</category><category>Catalyst SD WAN</category><category>CVE-2026-20122</category><category>Network Security</category><category>Exploitation</category></item><item><title>Cisco Catalyst SD-WAN Manager Exploitation: Patch CVE-2024-20437 Now</title><link>https://runtimerebel.com/blog/cisco-catalyst-sd-wan-manager-exploitation-patch-cve-2024-20437-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-catalyst-sd-wan-manager-exploitation-patch-cve-2024-20437-now</guid><description>Cisco confirms active exploitation of two high-severity flaws in Catalyst SD-WAN Manager, involving hardcoded credentials and authentication bypass.</description><pubDate>Thu, 05 Mar 2026 12:20:31 GMT</pubDate><category>Cisco</category><category>SD WAN</category><category>CVE-2024-20437</category><category>CVE-2024-20440</category><category>Exploitation</category></item><item><title>VMware Aria Operations Command Injection Exploitation: Cloud Risk</title><link>https://runtimerebel.com/blog/vmware-aria-operations-command-injection-exploitation-cloud-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-aria-operations-command-injection-exploitation-cloud-risk</guid><description>A critical command injection vulnerability in VMware Aria Operations is actively exploited, granting attackers broad access to cloud environments.</description><pubDate>Thu, 05 Mar 2026 00:35:55 GMT</pubDate><category>VMware Aria Operations</category><category>Command Injection</category><category>Cloud Security</category><category>Exploitation</category></item><item><title>CVE-2025-22719: VMware Aria Operations RCE Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2025-22719-vmware-aria-operations-rce-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-22719-vmware-aria-operations-rce-exploited-in-the-wild</guid><description>CVE-2025-22719 is a critical remote code execution vulnerability in VMware Aria Operations for Networks currently being exploited by unauthenticated attackers.</description><pubDate>Wed, 04 Mar 2026 08:15:00 GMT</pubDate><category>CVE-2025-22719</category><category>VMware</category><category>Aria Operations</category><category>RCE</category><category>Broadcom</category><category>Exploitation</category></item><item><title>Cisco SD-WAN Zero-Day Under Exploitation for 3 Years</title><link>https://runtimerebel.com/blog/cisco-sd-wan-zero-day-under-exploitation-for-3-years</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-sd-wan-zero-day-under-exploitation-for-3-years</guid><description>A critical zero-day vulnerability, CVE-2026-20127, in Cisco SD-WAN has been actively exploited by a sophisticated threat actor for three years.</description><pubDate>Fri, 27 Feb 2026 00:36:10 GMT</pubDate><category>CVE-2026-20127</category><category>Cisco SD WAN</category><category>Zero-Day</category><category>Advanced Persistent Threat</category><category>Exploitation</category></item><item><title>macOS coreaudiod Type Confusion Exploitation: CVE-2024-54529</title><link>https://runtimerebel.com/blog/macos-coreaudiod-type-confusion-exploitation-cve-2024-54529</link><guid isPermaLink="true">https://runtimerebel.com/blog/macos-coreaudiod-type-confusion-exploitation-cve-2024-54529</guid><description>Analysis of CVE-2024-54529, a critical type confusion vulnerability in macOS coreaudiod, detailing its exploitation and necessary mitigations.</description><pubDate>Wed, 25 Feb 2026 04:47:23 GMT</pubDate><category>macOS</category><category>Coreaudiod</category><category>CVE-2024-54529</category><category>Type Confusion</category><category>Exploitation</category><category>CoreAudio</category><category>CVE-2025-31235</category></item><item><title>Automated Reconnaissance Targeting React2Shell Implementations</title><link>https://runtimerebel.com/blog/automated-reconnaissance-targeting-react2shell-implementations</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-reconnaissance-targeting-react2shell-implementations</guid><description>Analysis of a specialized toolkit currently utilized by threat actors to identify and exploit React2Shell vulnerabilities within enterprise network perimeters.</description><pubDate>Mon, 23 Feb 2026 05:34:37 GMT</pubDate><category>Reconnaissance</category><category>React2Shell</category><category>RCE</category><category>Exploitation</category></item><item><title>Automated Exploitation Analysis: AI-Assisted Breach of FortiGate Infrastructure</title><link>https://runtimerebel.com/blog/automated-exploitation-analysis-ai-assisted-breach-of-fortigate-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-exploitation-analysis-ai-assisted-breach-of-fortigate-infrastructure</guid><description>Amazon threat intelligence identifies a high-velocity campaign leveraging LLM automation to compromise over 600 FortiGate firewalls across 55 countries in a five-week…</description><pubDate>Mon, 23 Feb 2026 05:33:11 GMT</pubDate><category>Fortinet</category><category>AI Threats</category><category>Exploitation</category><category>Automation</category><category>Russian Nexus</category></item></channel></rss>