<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — critical severity</title><description>Actively exploited or weaponised threats requiring immediate action.</description><link>https://runtimerebel.com</link><item><title>MikroTik RouterOS Unauthenticated SSH Exploit: Critical Advisory</title><link>https://runtimerebel.com/blog/mikrotik-routeros-unauthenticated-ssh-exploit-critical-advisory</link><guid isPermaLink="true">https://runtimerebel.com/blog/mikrotik-routeros-unauthenticated-ssh-exploit-critical-advisory</guid><description>Attackers are exploiting a critical vulnerability in MikroTik RouterOS via internet-exposed SSH to gain full administrative control without authentication.</description><pubDate>Sun, 06 Sep 2026 11:50:33 GMT</pubDate><category>Unauthenticated Access</category><category>Remote Code Execution</category><category>Zero-Day</category><category>MikroTik</category><category>RouterOS</category></item><item><title>Zero-Day Exploitation: StyleSmuggler RCE in Magento, Adobe Commerce</title><link>https://runtimerebel.com/blog/zero-day-exploitation-stylesmuggler-rce-in-magento-adobe-commerce</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-day-exploitation-stylesmuggler-rce-in-magento-adobe-commerce</guid><description>Attackers are exploiting an unpatched zero-day (StyleSmuggler) in Magento Open Source and Adobe Commerce for unauthenticated RCE, installing backdoors.</description><pubDate>Sun, 06 Sep 2026 01:55:08 GMT</pubDate><category>Zero-Day</category><category>RCE</category><category>E Commerce</category><category>Magento Open Source</category><category>Adobe Commerce</category></item><item><title>CVE-2026-63077: JetBrains Cadence Breach Exposes Credentials</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-cadence-breach-exposes-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-cadence-breach-exposes-credentials</guid><description>JetBrains Cadence suffered a data breach via unpatched TeamCity (CVE-2026-63077), exposing AWS credentials, source code, and user data. Immediate action required.</description><pubDate>Sat, 05 Sep 2026 17:48:47 GMT</pubDate><category>Data Breach</category><category>CVE-2026-63077</category><category>JetBrains Cadence</category><category>TeamCity</category><category>AWS Credentials</category></item><item><title>SonicWall SMA 1000 Zero-Days: Unauthenticated RCE Explained</title><link>https://runtimerebel.com/blog/sonicwall-sma-1000-zero-days-unauthenticated-rce-explained</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma-1000-zero-days-unauthenticated-rce-explained</guid><description>Zero-day vulnerabilities in SonicWall SMA 1000 series appliances enable unauthenticated remote code execution, posing critical risks to organizations.</description><pubDate>Sat, 05 Sep 2026 11:31:26 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>Zero-Day</category><category>RCE</category><category>Unauthenticated Rce</category></item><item><title>CVE-2026-19490: Citrix NetScaler Auth Bypass Under Attack</title><link>https://runtimerebel.com/blog/cve-2026-19490-citrix-netscaler-auth-bypass-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-19490-citrix-netscaler-auth-bypass-under-attack</guid><description>Critical Citrix NetScaler authentication bypass (CVE-2026-19490) is actively exploited in the wild, allowing remote unprivileged access.</description><pubDate>Sat, 05 Sep 2026 02:00:06 GMT</pubDate><category>CVE-2026-19490</category><category>Citrix NetScaler</category><category>Authentication Bypass</category><category>Zero-Day</category><category>Vulnerability Exploitation</category></item><item><title>Chrome Zero-Day CVE-2026-85046 Actively Exploited: Patch Now</title><link>https://runtimerebel.com/blog/chrome-zero-day-cve-2026-85046-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-zero-day-cve-2026-85046-actively-exploited-patch-now</guid><description>Google released an urgent update for a critical Chrome zero-day, CVE-2026-85046, actively exploited in V8 engine type confusion attacks.</description><pubDate>Fri, 04 Sep 2026 12:22:34 GMT</pubDate><category>Google Chrome</category><category>Zero-Day</category><category>RCE</category><category>CVE-2026-85046</category><category>Type Confusion</category></item><item><title>WordPress RCE Exploited via CVE-2026-14894 &amp; CVE-2026-32475</title><link>https://runtimerebel.com/blog/wordpress-rce-exploited-via-cve-2026-14894-cve-2026-32475</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-rce-exploited-via-cve-2026-14894-cve-2026-32475</guid><description>Attackers exploit critical RCE flaws in WordPress Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to deploy web shells and seize sites.</description><pubDate>Fri, 04 Sep 2026 12:22:02 GMT</pubDate><category>WordPress</category><category>RCE</category><category>Web Shells</category><category>Super Forms</category><category>Elementor Pro</category></item><item><title>CVE-2026-73749: HPE ArubaOS-CX RCE Flaw Patched</title><link>https://runtimerebel.com/blog/cve-2026-73749-hpe-arubaos-cx-rce-flaw-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-73749-hpe-arubaos-cx-rce-flaw-patched</guid><description>HPE patches a critical remote code execution flaw, CVE-2026-73749, in ArubaOS-CX switches. Unauthenticated attackers can exploit a buffer overflow.</description><pubDate>Thu, 03 Sep 2026 19:00:03 GMT</pubDate><category>Remote Code Execution</category><category>Buffer Overflow</category><category>HPE</category><category>ArubaOS CX</category><category>CVE-2026-73749</category></item><item><title>CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-83548-sonicwall-sma1000-ssrf-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-83548-sonicwall-sma1000-ssrf-under-active-exploitation</guid><description>A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.</description><pubDate>Wed, 02 Sep 2026 19:13:21 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>SSRF</category><category>Vulnerability</category><category>CISA KEV</category></item><item><title>CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection</title><link>https://runtimerebel.com/blog/cve-2026-9586-sangoma-switchvox-rce-via-sql-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-9586-sangoma-switchvox-rce-via-sql-injection</guid><description>Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.</description><pubDate>Wed, 02 Sep 2026 19:12:29 GMT</pubDate><category>CVE-2026-9586</category><category>Sangoma Switchvox</category><category>SQL Injection</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-49869: Kestra OSS OS Command Injection Exploited</title><link>https://runtimerebel.com/blog/cve-2026-49869-kestra-oss-os-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-49869-kestra-oss-os-command-injection-exploited</guid><description>CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.</description><pubDate>Wed, 02 Sep 2026 19:11:22 GMT</pubDate><category>CVE-2026-49869</category><category>Kestra OSS</category><category>OS Command Injection</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2026-48710: Kludex Starlette HTTP Smuggling for Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2026-48710-kludex-starlette-http-smuggling-for-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48710-kludex-starlette-http-smuggling-for-auth-bypass</guid><description>CVE-2026-48710 impacts Kludex Starlette, enabling HTTP request smuggling and authentication bypass via path injection. Actively exploited.</description><pubDate>Wed, 02 Sep 2026 19:10:47 GMT</pubDate><category>Authentication Bypass</category><category>Active Exploitation</category><category>CVE-2026-48710</category><category>Kludex Starlette</category><category>HTTP Request Smuggling</category></item><item><title>CVE-2026-59822: BerriAI LiteLLM Authentication Bypass</title><link>https://runtimerebel.com/blog/cve-2026-59822-berriai-litellm-authentication-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59822-berriai-litellm-authentication-bypass</guid><description>BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.</description><pubDate>Wed, 02 Sep 2026 19:09:55 GMT</pubDate><category>CVE-2026-59822</category><category>BerriAI LiteLLM</category><category>Authentication Bypass</category><category>CISA KEV</category><category>Improper Authentication</category></item><item><title>CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens</title><link>https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82329-jfrog-artifactory-auth-bypass-to-admin-tokens</guid><description>Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.</description><pubDate>Tue, 01 Sep 2026 19:00:04 GMT</pubDate><category>CVE-2026-82329</category><category>JFrog Artifactory</category><category>Authentication Bypass</category><category>Supply Chain Attack</category><category>Exploitation</category></item><item><title>CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data</title><link>https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</guid><description>CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.</description><pubDate>Tue, 01 Sep 2026 02:58:41 GMT</pubDate><category>CVE-2021-23758</category><category>Ajax NET Professional</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-53362: Linux Kernel IPv6 Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-53362-linux-kernel-ipv6-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53362-linux-kernel-ipv6-privilege-escalation</guid><description>CISA adds CVE-2026-53362 to KEV, confirming active exploitation of a Linux Kernel privilege escalation vulnerability via IPv6. Patch now.</description><pubDate>Tue, 01 Sep 2026 02:57:10 GMT</pubDate><category>CVE-2026-53362</category><category>Linux Kernel</category><category>Privilege Escalation</category><category>IPv6</category><category>CISA KEV</category></item><item><title>CVE-2023-49105: ownCloud Improper Auth Leads to Data Compromise</title><link>https://runtimerebel.com/blog/cve-2023-49105-owncloud-improper-auth-leads-to-data-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-49105-owncloud-improper-auth-leads-to-data-compromise</guid><description>CVE-2023-49105 in ownCloud allows unauthenticated file access, modification, or deletion, actively exploited in the wild.</description><pubDate>Tue, 01 Sep 2026 02:56:15 GMT</pubDate><category>CVE-2023-49105</category><category>ownCloud</category><category>Improper Authentication</category><category>Data Compromise</category><category>CWE-287</category></item><item><title>CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-82078-papercut-ng-mf-unsafe-reflection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-82078-papercut-ng-mf-unsafe-reflection-exploit</guid><description>CISA adds CVE-2026-82078 in PaperCut NG/MF to its KEV catalog following active exploitation. Review technical details and patch now.</description><pubDate>Tue, 01 Sep 2026 02:54:42 GMT</pubDate><category>CVE-2026-82078</category><category>PaperCut</category><category>Unsafe Reflection</category><category>Active Exploitation</category><category>Zero-Day</category></item><item><title>CVE-2026-60004: Gitea Code Injection Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-60004-gitea-code-injection-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60004-gitea-code-injection-under-active-exploitation</guid><description>CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.</description><pubDate>Wed, 26 Aug 2026 00:45:21 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-60004</category><category>Gitea</category><category>Code Injection</category></item><item><title>CVE-2026-21962: Oracle WebLogic RCE Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack</guid><description>CISA urges immediate patching for CVE-2026-21962, a critical Oracle WebLogic Server Proxy plugin vulnerability actively exploited in the wild.</description><pubDate>Tue, 25 Aug 2026 08:32:45 GMT</pubDate><category>CVE-2026-21962</category><category>Oracle</category><category>WebLogic</category><category>Zero-Day</category><category>Ransomware</category></item><item><title>CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth</title><link>https://runtimerebel.com/blog/cve-2026-72529-critical-rce-in-trueconf-server-via-missing-auth</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72529-critical-rce-in-trueconf-server-via-missing-auth</guid><description>CISA warns of active exploitation of CVE-2026-72529 in TrueConf Server, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.</description><pubDate>Fri, 21 Aug 2026 00:48:00 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-72529</category><category>TrueConf Server</category><category>Missing Authentication</category></item><item><title>CVE-2026-72530: TrueConf Server Remote Code Execution</title><link>https://runtimerebel.com/blog/cve-2026-72530-trueconf-server-remote-code-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72530-trueconf-server-remote-code-execution</guid><description>CISA confirms active exploitation of CVE-2026-72530, a TrueConf Server code injection flaw leading to remote code execution. Immediate patching is critical.</description><pubDate>Fri, 21 Aug 2026 00:47:12 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>Vulnerability Management</category><category>CVE-2026-72530</category><category>TrueConf Server</category></item><item><title>Zimbra CVE-2026-73570 Actively Exploited: Patch Now</title><link>https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</guid><description>Active exploitation targets Zimbra servers via CVE-2026-73570, a high-severity flaw allowing unauthenticated RCE. Patch to v10.1.20 now.</description><pubDate>Thu, 20 Aug 2026 16:24:30 GMT</pubDate><category>Zimbra</category><category>Exploitation</category><category>Remote Code Execution</category><category>CVE-2026-73570</category><category>Zimbra Collaboration Suite</category></item><item><title>CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw</title><link>https://runtimerebel.com/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw</guid><description>A critical flaw, CVE-2026-32475, in Elementor Pro allows unauthenticated attackers to upload PHP files and execute code, affecting versions &lt;= 4.2.1.</description><pubDate>Thu, 20 Aug 2026 08:26:43 GMT</pubDate><category>WordPress</category><category>Remote Code Execution</category><category>CVE-2026-32475</category><category>Elementor Pro</category><category>File Upload Vulnerability</category></item><item><title>MLflow CVE-2026-64849 Exploited: Cloud Credential Theft Via SSRF</title><link>https://runtimerebel.com/blog/mlflow-cve-2026-64849-exploited-cloud-credential-theft-via-ssrf</link><guid isPermaLink="true">https://runtimerebel.com/blog/mlflow-cve-2026-64849-exploited-cloud-credential-theft-via-ssrf</guid><description>Attackers exploit a critical MLflow SSRF vulnerability (CVE-2026-64849) to steal cloud credentials.</description><pubDate>Wed, 19 Aug 2026 08:25:32 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>MLflow</category><category>FUXA</category><category>CVE-2026-64849</category></item><item><title>CVE-2026-33824: Microsoft IKE Double Free RCE Exploit</title><link>https://runtimerebel.com/blog/cve-2026-33824-microsoft-ike-double-free-rce-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33824-microsoft-ike-double-free-rce-exploit</guid><description>CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.</description><pubDate>Wed, 19 Aug 2026 00:43:34 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-33824</category><category>Microsoft IKE</category><category>Double Free</category></item><item><title>CVE-2026-12569: Clop Exploits Windchill with Custom Web Shell</title><link>https://runtimerebel.com/blog/cve-2026-12569-clop-exploits-windchill-with-custom-web-shell</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-12569-clop-exploits-windchill-with-custom-web-shell</guid><description>Clop ransomware group exploited CVE-2026-12569 in PTC Windchill and FlexPLM servers, deploying a custom web shell for deep data theft. Patch immediately.</description><pubDate>Wed, 19 Aug 2026 00:40:12 GMT</pubDate><category>Clop</category><category>PTC Windchill</category><category>CVE-2026-12569</category><category>Webshell</category><category>Data Theft</category></item><item><title>CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild</title><link>https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</guid><description>CISA confirms active exploitation of CVE-2025-62593, a critical code injection vulnerability in Ray-Project Ray allowing remote code execution. Developers are targeted.</description><pubDate>Mon, 17 Aug 2026 16:20:50 GMT</pubDate><category>Remote Code Execution</category><category>RCE</category><category>CISA KEV</category><category>CVE-2025-62593</category><category>Ray Project</category></item><item><title>Apple Screen Sharing Exploits: Secure Your macOS Systems Now</title><link>https://runtimerebel.com/blog/apple-screen-sharing-exploits-secure-your-macos-systems-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/apple-screen-sharing-exploits-secure-your-macos-systems-now</guid><description>Critical vulnerabilities in Apple Screen Sharing are actively exploited, allowing system compromise. Learn how to secure macOS against these threats.</description><pubDate>Mon, 17 Aug 2026 16:20:27 GMT</pubDate><category>Apple</category><category>macOS</category><category>Exploitation</category><category>Remote Access</category><category>Screen Sharing</category></item><item><title>Clop Ransomware Exploits CVE-2026-12569 in PTC Products</title><link>https://runtimerebel.com/blog/clop-ransomware-exploits-cve-2026-12569-in-ptc-products</link><guid isPermaLink="true">https://runtimerebel.com/blog/clop-ransomware-exploits-cve-2026-12569-in-ptc-products</guid><description>Shell investigates potential data theft by Clop gang after exploitation of critical CVE-2026-12569 in PTC Windchill and FlexPLM instances.</description><pubDate>Sun, 16 Aug 2026 08:18:07 GMT</pubDate><category>Ransomware</category><category>Data Theft</category><category>PTC Windchill</category><category>Clop</category><category>CVE-2026-12569</category></item><item><title>TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</guid><description>A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security&apos;s Trivy scanner, not LiteLLM.</description><pubDate>Sat, 15 Aug 2026 00:42:24 GMT</pubDate><category>TeamPCP</category><category>Trivy</category><category>LiteLLM</category><category>Supply Chain Attack</category><category>Shai Hulud</category></item><item><title>CVE-2026-71362: Adobe Commerce Account Takeover — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-71362-adobe-commerce-account-takeover-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-71362-adobe-commerce-account-takeover-patch-now</guid><description>Hackers are immediately exploiting CVE-2026-71362, a critical authorization flaw in Adobe Commerce, to take over customer accounts. Patch urgently.</description><pubDate>Fri, 14 Aug 2026 01:07:52 GMT</pubDate><category>Privilege Escalation</category><category>Account Takeover</category><category>CVE-2026-71362</category><category>Adobe Commerce</category><category>Magento Open Source</category></item><item><title>CVE-2026-59310: vCenter RCE Exploited for Reverse SSH Access</title><link>https://runtimerebel.com/blog/cve-2026-59310-vcenter-rce-exploited-for-reverse-ssh-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59310-vcenter-rce-exploited-for-reverse-ssh-access</guid><description>A critical RCE flaw, CVE-2026-59310, in VMware vCenter Syslog Server is under active exploitation, enabling reverse SSH for persistence.</description><pubDate>Thu, 13 Aug 2026 16:45:32 GMT</pubDate><category>RCE</category><category>CVE-2026-59310</category><category>VMware</category><category>vCenter</category><category>Reverse SSH</category></item><item><title>CVE-2026-55040: Critical SharePoint Auth Bypass Exploited After PoC</title><link>https://runtimerebel.com/blog/cve-2026-55040-critical-sharepoint-auth-bypass-exploited-after-poc</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-55040-critical-sharepoint-auth-bypass-exploited-after-poc</guid><description>Attackers exploit CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint, leading to data disclosure and modification.</description><pubDate>Thu, 13 Aug 2026 09:02:53 GMT</pubDate><category>Microsoft SharePoint</category><category>Authentication Bypass</category><category>Zero Day Exploitation</category><category>Proof of Concept</category><category>CVE-2026-55040</category></item><item><title>Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP</title><link>https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</guid><description>Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.</description><pubDate>Wed, 12 Aug 2026 09:02:31 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>TeamPCP</category><category>Credential Theft</category></item><item><title>CVE-2026-72898: Metabase SQL Injection Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-72898-metabase-sql-injection-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72898-metabase-sql-injection-active-exploitation</guid><description>CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.</description><pubDate>Wed, 12 Aug 2026 01:08:08 GMT</pubDate><category>CVE-2026-72898</category><category>Metabase</category><category>SQL Injection</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day</title><link>https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</guid><description>Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.</description><pubDate>Wed, 12 Aug 2026 01:05:21 GMT</pubDate><category>Windows</category><category>SharePoint</category><category>Zero-Day</category><category>Lazarus Group</category><category>CVE-2026-68820</category></item><item><title>CVE-2026-63077: JetBrains TeamCity RCE via Deserialization</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</guid><description>CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.</description><pubDate>Tue, 11 Aug 2026 16:54:33 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains TeamCity</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>SonicWall SMA1000 Exploited: Ransomware Targets CVE-2026-15409/15410</title><link>https://runtimerebel.com/blog/sonicwall-sma1000-exploited-ransomware-targets-cve-2026-15409-15410</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma1000-exploited-ransomware-targets-cve-2026-15409-15410</guid><description>CISA confirms ransomware exploitation of SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, urging immediate patching.</description><pubDate>Mon, 10 Aug 2026 16:44:58 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>CVE-2025-40602</category></item><item><title>CVE-2025-66376: APT28 Exploits Zimbra Zero-Click for Espionage</title><link>https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-66376-apt28-exploits-zimbra-zero-click-for-espionage</guid><description>Russian state-sponsored actors exploit a zero-click Zimbra vulnerability (CVE-2025-66376) to exfiltrate sensitive webmail data from targeted organizations.</description><pubDate>Sat, 08 Aug 2026 08:33:35 GMT</pubDate><category>CVE-2025-66376</category><category>Zimbra</category><category>Cyber Espionage</category><category>Zero Click</category><category>Phishing</category></item><item><title>Metabase Zero-Day Exploited: Unauthenticated Admin Access</title><link>https://runtimerebel.com/blog/metabase-zero-day-exploited-unauthenticated-admin-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-zero-day-exploited-unauthenticated-admin-access</guid><description>Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.</description><pubDate>Sat, 08 Aug 2026 08:28:26 GMT</pubDate><category>Zero-Day</category><category>SQL Injection</category><category>Unauthenticated Access</category><category>Data Breach</category><category>Metabase</category></item><item><title>CVE-2026-8037: Progress LoadMaster Command Injection RCE</title><link>https://runtimerebel.com/blog/cve-2026-8037-progress-loadmaster-command-injection-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-8037-progress-loadmaster-command-injection-rce</guid><description>Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.</description><pubDate>Sat, 08 Aug 2026 01:04:01 GMT</pubDate><category>Command Injection</category><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-8037</category><category>Progress LoadMaster</category></item><item><title>Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed</title><link>https://runtimerebel.com/blog/metabase-sqli-zero-day-exploited-data-theft-attacks-confirmed</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-sqli-zero-day-exploited-data-theft-attacks-confirmed</guid><description>A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.</description><pubDate>Sat, 08 Aug 2026 00:54:50 GMT</pubDate><category>SQL Injection</category><category>Zero-Day</category><category>Data Breach</category><category>Metabase</category><category>Framework</category></item><item><title>CISA Warns: Actively Exploited Langflow, N-central, and Tomcat Vulnerabilities</title><link>https://runtimerebel.com/blog/cisa-warns-actively-exploited-langflow-n-central-and-tomcat-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-actively-exploited-langflow-n-central-and-tomcat-vulnerabilities</guid><description>CISA warns federal agencies and organizations about active exploitation of critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat.</description><pubDate>Wed, 05 Aug 2026 10:27:25 GMT</pubDate><category>CISA KEV</category><category>CVE-2026-9198</category><category>CVE-2026-18556</category><category>CVE-2026-18577</category><category>CVE-2026-34486</category></item><item><title>CVE-2026-18556: N-able N-central Authentication Bypass Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-18556-n-able-n-central-authentication-bypass-actively-exploited</guid><description>CISA added CVE-2026-18556 to its KEV catalog, confirming active exploitation of an N-able N-central authentication bypass vulnerability.</description><pubDate>Tue, 04 Aug 2026 17:33:39 GMT</pubDate><category>Authentication Bypass</category><category>CISA KEV</category><category>Exploitation</category><category>CVE-2026-18556</category><category>N Able N Central</category></item><item><title>CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</guid><description>CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…</description><pubDate>Sun, 02 Aug 2026 16:49:14 GMT</pubDate><category>CVE-2026-50522</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</guid><description>CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.</description><pubDate>Sun, 02 Aug 2026 02:55:48 GMT</pubDate><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>CISA KEV</category><category>CVE-2026-60137</category></item><item><title>CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw</title><link>https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</guid><description>CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…</description><pubDate>Sun, 02 Aug 2026 02:54:04 GMT</pubDate><category>CISA KEV</category><category>CVE-2026-16232</category><category>Check Point SmartConsole</category><category>Improper Authentication</category><category>Admin Bypass</category></item><item><title>Coldcard Firmware Flaw Enables $70M Bitcoin Theft</title><link>https://runtimerebel.com/blog/coldcard-firmware-flaw-enables-70m-bitcoin-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/coldcard-firmware-flaw-enables-70m-bitcoin-theft</guid><description>A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.</description><pubDate>Sat, 01 Aug 2026 20:54:22 GMT</pubDate><category>Coldcard</category><category>Hardware Wallet</category><category>Bitcoin</category><category>Firmware Flaw</category><category>Seed Generation</category><category>PRNG</category><category>Cryptocurrency Security</category></item><item><title>CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability</title><link>https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</guid><description>CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.</description><pubDate>Fri, 31 Jul 2026 10:42:09 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco Secure Firewall Management Center</category><category>Hard Coded Password</category><category>Authentication Bypass</category><category>CISA KEV</category></item></channel></rss>