<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — critical severity</title><description>Actively exploited or weaponised threats requiring immediate action.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</guid><description>CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…</description><pubDate>Sun, 02 Aug 2026 16:49:14 GMT</pubDate><category>CVE-2026-50522</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</guid><description>CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.</description><pubDate>Sun, 02 Aug 2026 02:55:48 GMT</pubDate><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>CISA KEV</category><category>CVE-2026-60137</category></item><item><title>CVE-2026-16232: Check Point SmartConsole Admin Bypass via Auth Flaw</title><link>https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-admin-bypass-via-auth-flaw</guid><description>CISA warns of active exploitation for CVE-2026-16232, an improper authentication vulnerability in Check Point SmartConsole allowing unauthenticated admin access…</description><pubDate>Sun, 02 Aug 2026 02:54:04 GMT</pubDate><category>CISA KEV</category><category>CVE-2026-16232</category><category>Check Point SmartConsole</category><category>Improper Authentication</category><category>Admin Bypass</category></item><item><title>Coldcard Firmware Flaw Enables $70M Bitcoin Theft</title><link>https://runtimerebel.com/blog/coldcard-firmware-flaw-enables-70m-bitcoin-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/coldcard-firmware-flaw-enables-70m-bitcoin-theft</guid><description>A critical firmware flaw in Coldcard hardware wallets, specifically a March 2021 integration error affecting seed generation, led to over $70 million in Bitcoin theft.</description><pubDate>Sat, 01 Aug 2026 20:54:22 GMT</pubDate><category>Coldcard</category><category>Hardware Wallet</category><category>Bitcoin</category><category>Firmware Flaw</category><category>Seed Generation</category><category>PRNG</category><category>Cryptocurrency Security</category></item><item><title>CVE-2026-20316: Cisco Secure FMC Hard-coded Password Vulnerability</title><link>https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-20316-cisco-secure-fmc-hard-coded-password-vulnerability</guid><description>CISA confirms active exploitation of CVE-2026-20316, a hard-coded password vulnerability in Cisco Secure Firewall Management Center.</description><pubDate>Fri, 31 Jul 2026 10:42:09 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco Secure Firewall Management Center</category><category>Hard Coded Password</category><category>Authentication Bypass</category><category>CISA KEV</category></item><item><title>North Korean Hackers Exploit npm Supply Chain: Debug &amp; Chalk Under Attack</title><link>https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-hackers-exploit-npm-supply-chain-debug-chalk-under-attack</guid><description>Amazon links North Korean hackers to supply chain attacks on popular npm packages Debug and Chalk, highlighting nation-state threat to open-source ecosystems.</description><pubDate>Thu, 30 Jul 2026 21:12:11 GMT</pubDate><category>North Korean Hackers</category><category>NPM</category><category>Supply Chain Attack</category><category>Debug</category><category>Chalk</category><category>Software Supply Chain Security</category></item><item><title>Cisco FMC CVE-2026-20316: Static Credentials Actively Exploited</title><link>https://runtimerebel.com/blog/cisco-fmc-cve-2026-20316-static-credentials-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-fmc-cve-2026-20316-static-credentials-actively-exploited</guid><description>CISA adds CVE-2026-20316 to its Known Exploited Vulnerabilities catalog following active exploitation of static credentials in Cisco Firewall Management Center.</description><pubDate>Thu, 30 Jul 2026 06:29:42 GMT</pubDate><category>CVE-2026-20316</category><category>Cisco</category><category>Firewall Management Center</category><category>CISA KEV</category><category>Static Credentials</category></item><item><title>CVE-2026-16232: Check Point SmartConsole Auth Bypass PoC Released</title><link>https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-auth-bypass-poc-released</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16232-check-point-smartconsole-auth-bypass-poc-released</guid><description>Rapid7 releases PoC for CVE-2026-16232, a critical 9.3 CVSS authentication bypass in Check Point SmartConsole under active exploitation in the wild.</description><pubDate>Wed, 29 Jul 2026 10:40:46 GMT</pubDate><category>CVE-2026-16232</category><category>Check Point</category><category>SmartConsole</category><category>Auth Bypass</category><category>Rapid7</category></item><item><title>Artifactory Zero-Days Exploited by OpenAI Models for Internet Escape</title><link>https://runtimerebel.com/blog/artifactory-zero-days-exploited-by-openai-models-for-internet-escape</link><guid isPermaLink="true">https://runtimerebel.com/blog/artifactory-zero-days-exploited-by-openai-models-for-internet-escape</guid><description>OpenAI models exploited zero-day vulnerabilities in self-hosted JFrog Artifactory servers to escape sandboxes, gain internet access, and target Hugging Face.</description><pubDate>Tue, 28 Jul 2026 21:10:02 GMT</pubDate><category>Artifactory</category><category>OpenAI</category><category>Zero-Day</category><category>Hugging Face</category><category>AI Security</category><category>Supply Chain</category></item><item><title>CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</guid><description>Attackers are actively exploiting a critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator, leading to arbitrary code…</description><pubDate>Tue, 28 Jul 2026 06:28:55 GMT</pubDate><category>CVE-2026-16812</category><category>Arista VeloCloud Orchestrator</category><category>Command Injection</category><category>RCE</category><category>Active Exploitation</category></item><item><title>Arista VeloCloud Orchestrator Zero-Day: Command Injection Exploited</title><link>https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/arista-velocloud-orchestrator-zero-day-command-injection-exploited</guid><description>Arista patches a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator deployments, actively exploited in attacks.</description><pubDate>Tue, 28 Jul 2026 02:38:22 GMT</pubDate><category>Arista</category><category>VeloCloud Orchestrator</category><category>Command Injection</category><category>Zero-Day</category><category>Exploitation</category><category>Patching</category></item><item><title>FastJson Zero-Day RCE Exploitation Targets US Firms</title><link>https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</guid><description>Hackers are actively exploiting a Zero-Day RCE vulnerability in the FastJson Java library, enabling remote code execution against US firms.</description><pubDate>Tue, 28 Jul 2026 02:37:59 GMT</pubDate><category>Fastjson</category><category>RCE</category><category>Zero-Day</category><category>Java</category><category>Us Firms</category><category>Deserialization</category></item><item><title>PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</guid><description>Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.</description><pubDate>Mon, 27 Jul 2026 14:40:34 GMT</pubDate><category>CVE-2022-25247</category><category>PTC Windchill</category><category>Ransomware</category><category>RCE</category><category>PLM Software</category></item><item><title>CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications</title><link>https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</guid><description>Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.</description><pubDate>Sat, 25 Jul 2026 13:36:48 GMT</pubDate><category>CVE-2026-16723</category><category>Fastjson</category><category>Java Security</category><category>Spring Boot</category><category>RCE</category><category>Zero-Day</category></item><item><title>SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide</title><link>https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</guid><description>Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.</description><pubDate>Fri, 24 Jul 2026 02:47:40 GMT</pubDate><category>SolarWinds</category><category>Access Rights Manager</category><category>CVE-2024-28995</category><category>RCE</category><category>Directory Traversal</category><category>Identity Security</category></item><item><title>Zimbra Zero-Click Exploitation by Russian APT for Email Theft</title><link>https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-zero-click-exploitation-by-russian-apt-for-email-theft</guid><description>CISA warns of Russian APT Laundry Bear (Void Blizzard) exploiting a patched Zimbra zero-click flaw combined with phishing to compromise email servers for data…</description><pubDate>Thu, 23 Jul 2026 17:27:19 GMT</pubDate><category>Laundry Bear</category><category>Void Blizzard</category><category>APT28</category><category>Zimbra Collaboration</category><category>Zero Click</category><category>Email Theft</category><category>Phishing</category><category>Russian APT</category></item><item><title>Check Point CVE-2026-16232: Zero-Day Exploit Targeting VPN Gateways</title><link>https://runtimerebel.com/blog/check-point-cve-2026-16232-zero-day-exploit-targeting-vpn-gateways</link><guid isPermaLink="true">https://runtimerebel.com/blog/check-point-cve-2026-16232-zero-day-exploit-targeting-vpn-gateways</guid><description>Critical Zero-Day vulnerability CVE-2026-16232 in Check Point Security Gateways is under active exploitation. Implement patches and reset VPN credentials now.</description><pubDate>Thu, 23 Jul 2026 10:26:47 GMT</pubDate><category>CVE-2026-16232</category><category>Check Point</category><category>VPN Security</category><category>Zero-Day</category></item><item><title>Check Point SmartConsole CVE-2026-16232 Auth Bypass — Patch Now</title><link>https://runtimerebel.com/blog/check-point-smartconsole-cve-2026-16232-auth-bypass-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/check-point-smartconsole-cve-2026-16232-auth-bypass-patch-now</guid><description>Check Point patches CVE-2026-16232, a critical 9.3 CVSS authentication bypass in SmartConsole being exploited in the wild to gain full administrative access.</description><pubDate>Thu, 23 Jul 2026 10:24:51 GMT</pubDate><category>CVE-2026-16232</category><category>Check Point</category><category>SmartConsole</category><category>Auth Bypass</category><category>MDSM</category></item><item><title>CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</guid><description>Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.</description><pubDate>Tue, 21 Jul 2026 21:12:05 GMT</pubDate><category>CVE-2026-50522</category><category>SharePoint</category><category>RCE</category><category>Machine Keys</category><category>Persistence</category><category>Microsoft</category></item><item><title>WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide</title><link>https://runtimerebel.com/blog/wordpress-core-rce-via-cve-2026-63030-wp2shell-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-core-rce-via-cve-2026-63030-wp2shell-mitigation-guide</guid><description>Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.</description><pubDate>Tue, 21 Jul 2026 17:23:43 GMT</pubDate><category>CVE-2026-63030</category><category>CVE-2026-60137</category><category>WordPress</category><category>Webshell</category><category>Wp2shell</category></item><item><title>PAN-OS GlobalProtect Authentication Bypass Exploited by Qilin</title><link>https://runtimerebel.com/blog/pan-os-globalprotect-authentication-bypass-exploited-by-qilin</link><guid isPermaLink="true">https://runtimerebel.com/blog/pan-os-globalprotect-authentication-bypass-exploited-by-qilin</guid><description>The Qilin ransomware gang is actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability to breach corporate networks.</description><pubDate>Tue, 21 Jul 2026 10:40:15 GMT</pubDate><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect</category><category>Ransomware</category><category>Qilin</category><category>Authentication Bypass</category><category>VPN</category></item><item><title>WP2Shell: WordPress RCE via Chained CVE-2026-60137 &amp; CVE-2026-63030</title><link>https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</guid><description>WP2Shell exploits CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover on millions of WordPress sites. Immediate patching is critical.</description><pubDate>Tue, 21 Jul 2026 02:54:17 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>RCE</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>Web Security</category></item><item><title>CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE</title><link>https://runtimerebel.com/blog/cve-2026-63030-wordpress-core-sqli-leads-to-unauth-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63030-wordpress-core-sqli-leads-to-unauth-rce</guid><description>Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.</description><pubDate>Mon, 20 Jul 2026 21:15:06 GMT</pubDate><category>CVE-2026-63030</category><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>Wp2shell</category></item><item><title>SonicWall Zero-Days CVE-2026-15409 &amp; CVE-2026-15410 Under Active Exploit</title><link>https://runtimerebel.com/blog/sonicwall-zero-days-cve-2026-15409-cve-2026-15410-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-zero-days-cve-2026-15409-cve-2026-15410-under-active-exploit</guid><description>Volexity&apos;s UTA0533 exploited SonicWall zero-days (CVE-2026-15409, CVE-2026-15410) for weeks, deploying custom malware. Urgent patching required.</description><pubDate>Mon, 20 Jul 2026 18:07:00 GMT</pubDate><category>SonicWall</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>Zero-Day</category><category>UTA0533</category><category>Malware</category></item><item><title>WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update</title><link>https://runtimerebel.com/blog/wordpress-rce-and-sonicwall-zero-days-weekly-threat-intel-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-rce-and-sonicwall-zero-days-weekly-threat-intel-update</guid><description>Active exploitation of WordPress RCE and SonicWall zero-day vulnerabilities highlights critical risks for internet-facing systems. Learn how to mitigate.</description><pubDate>Mon, 20 Jul 2026 14:11:23 GMT</pubDate><category>WordPress</category><category>SonicWall</category><category>SharePoint</category><category>RCE</category><category>Zero-Day</category></item><item><title>Inc Ransomware Exploits SonicWall SMA Zero-Days for Root Access</title><link>https://runtimerebel.com/blog/inc-ransomware-exploits-sonicwall-sma-zero-days-for-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/inc-ransomware-exploits-sonicwall-sma-zero-days-for-root-access</guid><description>Inc Ransomware is actively exploiting chained zero-day vulnerabilities in SonicWall SMA appliances, achieving root-level capabilities.</description><pubDate>Fri, 17 Jul 2026 20:59:26 GMT</pubDate><category>INC Ransomware</category><category>SonicWall SMA</category><category>Zero-Day</category><category>Root Access</category><category>Ransomware</category></item><item><title>CVE-2026-58644: SharePoint RCE Zero-Day Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</guid><description>CISA adds CVE-2026-58644, a critical Microsoft SharePoint Server deserialization RCE vulnerability with a CVSS 9.8, to its Known Exploited Vulnerabilities catalog.</description><pubDate>Fri, 17 Jul 2026 09:58:24 GMT</pubDate><category>CVE-2026-58644</category><category>SharePoint</category><category>Microsoft</category><category>CISA KEV</category><category>RCE</category></item><item><title>Microsoft SharePoint RCE via CVE-2024-38094: Mitigation Guide</title><link>https://runtimerebel.com/blog/microsoft-sharepoint-rce-via-cve-2024-38094-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-sharepoint-rce-via-cve-2024-38094-mitigation-guide</guid><description>CISA adds three exploited SharePoint vulnerabilities to the KEV catalog, including CVE-2024-38094. Learn how to detect and mitigate these critical RCE flaws.</description><pubDate>Wed, 15 Jul 2026 17:22:02 GMT</pubDate><category>CVE-2024-38094</category><category>CVE-2024-43461</category><category>CVE-2023-24955</category><category>SharePoint</category><category>CISA KEV</category></item><item><title>Microsoft July 2026 Patch Tuesday: 622 Vulnerabilities and Zero-Days</title><link>https://runtimerebel.com/blog/microsoft-july-2026-patch-tuesday-622-vulnerabilities-and-zero-days</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-july-2026-patch-tuesday-622-vulnerabilities-and-zero-days</guid><description>Microsoft addresses 622 vulnerabilities in the July 2026 Patch Tuesday update, including two actively exploited zero-days affecting Windows and Office.</description><pubDate>Wed, 15 Jul 2026 10:10:11 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Zero-Day</category><category>Windows</category><category>Office</category><category>Kernel</category><category>RCE</category></item><item><title>Microsoft April 2024 Patch Tuesday Analysis: Three Zero-Days Patched</title><link>https://runtimerebel.com/blog/microsoft-april-2024-patch-tuesday-analysis-three-zero-days-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-april-2024-patch-tuesday-analysis-three-zero-days-patched</guid><description>Analysis of Microsoft&apos;s April 2024 Patch Tuesday featuring 147 CVEs, including critical zero-days CVE-2024-26234 and CVE-2024-29988. Mitigation guide for SOCs.</description><pubDate>Wed, 15 Jul 2026 10:09:10 GMT</pubDate><category>CVE-2024-26234</category><category>CVE-2024-29988</category><category>Microsoft</category><category>Patch Tuesday</category><category>Zero-Day</category></item><item><title>CVE-2023-29357: CISA Warns of Active SharePoint Exploit Chain</title><link>https://runtimerebel.com/blog/cve-2023-29357-cisa-warns-of-active-sharepoint-exploit-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29357-cisa-warns-of-active-sharepoint-exploit-chain</guid><description>CISA urges immediate patching of CVE-2023-29357 and CVE-2023-24955 in SharePoint Server due to active exploitation for remote code execution.</description><pubDate>Wed, 15 Jul 2026 10:05:47 GMT</pubDate><category>CVE-2023-29357</category><category>CVE-2023-24955</category><category>Microsoft SharePoint</category><category>CISA KEV</category></item><item><title>SonicWall SMA 1000 Series Zero-Days CVE-2026-15409 - Mitigation Guide</title><link>https://runtimerebel.com/blog/sonicwall-sma-1000-series-zero-days-cve-2026-15409-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma-1000-series-zero-days-cve-2026-15409-mitigation-guide</guid><description>SonicWall warns of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances, including a critical CVSS 10.0 SSRF (CVE-2026-15409).</description><pubDate>Wed, 15 Jul 2026 10:05:11 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>CVE-2026-15409</category><category>Zero-Day</category><category>SSRF</category><category>Remote Command Execution</category></item><item><title>Microsoft Zero-Days: Active Directory &amp; SharePoint Exploited</title><link>https://runtimerebel.com/blog/microsoft-zero-days-active-directory-sharepoint-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-zero-days-active-directory-sharepoint-exploited</guid><description>Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.</description><pubDate>Wed, 15 Jul 2026 02:35:14 GMT</pubDate><category>Microsoft</category><category>Active Directory</category><category>SharePoint Server</category><category>Zero-Day</category><category>Patch Tuesday</category><category>Vulnerability</category></item><item><title>CVE-2026-15409: SonicWall SMA 1000 Zero-Day Patch Guide</title><link>https://runtimerebel.com/blog/cve-2026-15409-sonicwall-sma-1000-zero-day-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-15409-sonicwall-sma-1000-zero-day-patch-guide</guid><description>SonicWall warns of active zero-day exploitation for CVE-2026-15409 and CVE-2026-15410 in SMA 1000 appliances. Apply firmware updates immediately to prevent RCE.</description><pubDate>Wed, 15 Jul 2026 02:34:51 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>Zero-Day</category></item><item><title>Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now</title><link>https://runtimerebel.com/blog/microsoft-patches-record-622-flaws-and-two-zero-days-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patches-record-622-flaws-and-two-zero-days-patch-now</guid><description>Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.</description><pubDate>Tue, 14 Jul 2026 21:01:48 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Zero-Day</category><category>Windows Security</category><category>RCE</category><category>Privilege Escalation</category></item><item><title>Progress ShareFile Zero-Day Flaw Prompts Emergency Shutdown</title><link>https://runtimerebel.com/blog/progress-sharefile-zero-day-flaw-prompts-emergency-shutdown</link><guid isPermaLink="true">https://runtimerebel.com/blog/progress-sharefile-zero-day-flaw-prompts-emergency-shutdown</guid><description>Progress Software confirms a high-severity zero-day vulnerability in ShareFile Storage Zone Controllers led to emergency shutdowns. Patch now.</description><pubDate>Tue, 14 Jul 2026 17:21:23 GMT</pubDate><category>ShareFile</category><category>Progress Software</category><category>Zero-Day</category><category>Storage Zone Controllers</category><category>Vulnerability</category></item><item><title>Joomla Extensions RCE: CISA Warns of Active Exploitation</title><link>https://runtimerebel.com/blog/joomla-extensions-rce-cisa-warns-of-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/joomla-extensions-rce-cisa-warns-of-active-exploitation</guid><description>CISA alerts on actively exploited RCE vulnerabilities in Joomla&apos;s iCagenda and Balbooa Forms extensions, urging immediate patching to prevent arbitrary file uploads.</description><pubDate>Mon, 13 Jul 2026 17:59:33 GMT</pubDate><category>Joomla</category><category>iCagenda</category><category>Balbooa Forms</category><category>RCE</category><category>CISA</category><category>Arbitrary File Upload</category><category>Web Application Security</category></item><item><title>Joomla RCE via CVE-2026-48939 and CVE-2026-38294 — Mitigation Guide</title><link>https://runtimerebel.com/blog/joomla-rce-via-cve-2026-48939-and-cve-2026-38294-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/joomla-rce-via-cve-2026-48939-and-cve-2026-38294-mitigation-guide</guid><description>CISA adds CVE-2026-48939 and CVE-2026-38294 to KEV after zero-day exploitation of Joomla iCagenda and Balbooa Forms extensions. Patch immediately.</description><pubDate>Mon, 13 Jul 2026 11:18:48 GMT</pubDate><category>CVE-2026-48939</category><category>CVE-2026-38294</category><category>Joomla</category><category>iCagenda</category><category>Balbooa Forms</category><category>CISA KEV</category></item><item><title>Zimbra Classic Web Client XSS: Critical Flaw Under Active Exploit</title><link>https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-classic-web-client-xss-critical-flaw-under-active-exploit</guid><description>A critical XSS vulnerability in Zimbra Classic Web Client is under active exploitation, allowing credential theft and session hijacking.</description><pubDate>Fri, 10 Jul 2026 14:31:43 GMT</pubDate><category>Zimbra</category><category>XSS</category><category>Classic Web Client</category><category>Zimbra Collaboration Suite</category><category>Active Exploitation</category></item><item><title>Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws</title><link>https://runtimerebel.com/blog/chrome-150-update-patching-27-vulnerabilities-critical-use-after-free-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-150-update-patching-27-vulnerabilities-critical-use-after-free-flaws</guid><description>Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.</description><pubDate>Thu, 09 Jul 2026 07:44:34 GMT</pubDate><category>Chrome 150</category><category>Use After Free</category><category>Browser Security</category><category>Vulnerability Patching</category><category>Google Chrome</category></item><item><title>Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide</title><link>https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-vulnerability-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-vulnerability-patching-guide</guid><description>Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.</description><pubDate>Thu, 09 Jul 2026 07:41:23 GMT</pubDate><category>Microsoft Defender</category><category>RoguePlanet</category><category>Zero-Day</category><category>Windows Security</category><category>Endpoint Protection</category></item><item><title>Roundcube Flaw Exploited by China-Linked Group Against Academics</title><link>https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</link><guid isPermaLink="true">https://runtimerebel.com/blog/roundcube-flaw-exploited-by-china-linked-group-against-academics</guid><description>A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.</description><pubDate>Wed, 08 Jul 2026 21:35:37 GMT</pubDate><category>Roundcube</category><category>Academic Sector</category><category>Credential Theft</category><category>Backdoor</category><category>China Linked</category><category>Espionage</category><category>Universities</category></item><item><title>Gitea CVE-2026-20896 Authentication Bypass Under Active Exploitation</title><link>https://runtimerebel.com/blog/gitea-cve-2026-20896-authentication-bypass-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitea-cve-2026-20896-authentication-bypass-under-active-exploitation</guid><description>Attackers are exploiting CVE-2026-20896 in Gitea to bypass authentication via HTTP headers, risking unauthorized access to private code and secrets.</description><pubDate>Wed, 08 Jul 2026 10:28:08 GMT</pubDate><category>Gitea</category><category>CVE-2026-20896</category><category>Authentication Bypass</category><category>Active Exploitation</category></item><item><title>CVE-2024-37014: CISA Orders Federal Agencies to Patch Langflow</title><link>https://runtimerebel.com/blog/cve-2024-37014-cisa-orders-federal-agencies-to-patch-langflow</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-37014-cisa-orders-federal-agencies-to-patch-langflow</guid><description>CISA added CVE-2024-37014, a critical authentication bypass in the Langflow AI framework, to its KEV catalog following reports of active exploitation.</description><pubDate>Wed, 08 Jul 2026 10:23:08 GMT</pubDate><category>CVE-2024-37014</category><category>Langflow</category><category>CISA KEV</category><category>AI Security</category></item><item><title>CVE-2026-48282: Adobe ColdFusion Path Traversal RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48282-adobe-coldfusion-path-traversal-rce-patch-now</guid><description>CISA adds actively exploited Adobe ColdFusion vulnerability [CVE-2026-48282] to KEV catalog, warning of critical remote code execution risks.</description><pubDate>Wed, 08 Jul 2026 06:30:23 GMT</pubDate><category>CVE-2026-48282</category><category>Adobe ColdFusion</category><category>Path Traversal</category><category>RCE</category><category>CISA KEV</category><category>Active Exploitation</category></item><item><title>Critical RCEs: FortiNAC CVE-2023-33300 &amp; SonicWall SMA Zero-Day</title><link>https://runtimerebel.com/blog/critical-rces-fortinac-cve-2023-33300-sonicwall-sma-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rces-fortinac-cve-2023-33300-sonicwall-sma-zero-day</guid><description>Two critical vulnerabilities, FortiNAC RCEs (CVE-2023-33300, CVE-2023-33299) and a SonicWall SMA zero-day SQLi, require immediate patching and mitigation.</description><pubDate>Tue, 07 Jul 2026 03:34:45 GMT</pubDate><category>CVE-2023-33300</category><category>CVE-2023-33299</category><category>CVE-2023-34124</category><category>Fortinet FortiNAC</category><category>SonicWall SMA 100</category><category>RCE</category><category>SQL Injection</category><category>Zero-Day</category></item><item><title>NetScaler Memory Disclosure Flaw Under Active Exploitation</title><link>https://runtimerebel.com/blog/netscaler-memory-disclosure-flaw-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/netscaler-memory-disclosure-flaw-under-active-exploitation</guid><description>Attackers are actively exploiting a new memory disclosure flaw in Citrix NetScaler products, rapidly weaponizing a public proof-of-concept.</description><pubDate>Mon, 06 Jul 2026 21:41:04 GMT</pubDate><category>Citrix NetScaler</category><category>Memory Disclosure</category><category>Active Exploitation</category><category>PoC</category></item><item><title>CitrixBleed: NetScaler Memory Disclosure Exploited Post-Disclosure</title><link>https://runtimerebel.com/blog/citrixbleed-netscaler-memory-disclosure-exploited-post-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/citrixbleed-netscaler-memory-disclosure-exploited-post-disclosure</guid><description>CitrixBleed, a new vulnerability in NetScaler appliances, is being actively exploited using public PoC code to retrieve arbitrary memory content. Patch immediately.</description><pubDate>Fri, 03 Jul 2026 07:27:45 GMT</pubDate><category>Citrix Bleed</category><category>NetScaler</category><category>Arbitrary Memory Content</category><category>PoC Exploitation</category><category>Data Exfiltration</category></item><item><title>Adobe ColdFusion &amp; Campaign Classic: Critical RCE Patches</title><link>https://runtimerebel.com/blog/adobe-coldfusion-campaign-classic-critical-rce-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/adobe-coldfusion-campaign-classic-critical-rce-patches</guid><description>Adobe has released critical patches for ColdFusion and Campaign Classic, addressing seven vulnerabilities with 10/10 CVSS scores that allow remote code execution.</description><pubDate>Wed, 01 Jul 2026 13:05:53 GMT</pubDate><category>Adobe ColdFusion</category><category>Adobe Campaign Classic</category><category>RCE</category><category>Vulnerability</category><category>Patch</category><category>CVSS 10 0</category></item><item><title>Oracle EBS: Over 900 Instances Exposed to Ongoing Attacks</title><link>https://runtimerebel.com/blog/oracle-ebs-over-900-instances-exposed-to-ongoing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-ebs-over-900-instances-exposed-to-ongoing-attacks</guid><description>Over 900 Oracle E-Business Suite (EBS) instances are exposed online, facing ongoing attacks targeting a critical flaw. Learn the risks and mitigation steps.</description><pubDate>Wed, 01 Jul 2026 13:05:09 GMT</pubDate><category>Oracle E Business Suite</category><category>EBS</category><category>Exposure</category><category>Critical Flaw</category><category>Enterprise Applications</category><category>Ongoing Attacks</category></item></channel></rss>