Coverage
Vulnerabilities
1230 articles on vulnerability disclosures and exploits
Advertisement
CVE-2026-59346: VMware Workstation & Fusion RCE Patch
Broadcom patches critical arbitrary code execution flaws (CVE-2026-59346, CVE-2026-59347) in VMware Workstation and Fusion, impacting host systems from compromised VMs.
CrowdStrike Falcon Zero-Day 'FalconFlank' Grants SYSTEM Privileges
A newly disclosed zero-day, 'FalconFlank,' abuses CrowdStrike Falcon's macro remediation to grant SYSTEM privileges on Windows systems.
MikroTik RouterOS Unauthenticated SSH Exploit: Critical Advisory
Attackers are exploiting a critical vulnerability in MikroTik RouterOS via internet-exposed SSH to gain full administrative control without authentication.
39 Methods Compromise Passkey Authentication: Threat Analysis
Discover 39 published methods compromising passkey authentication, focusing on ecosystem flaws, UI manipulation, and enrollment abuse.
Zero-Day Exploitation: StyleSmuggler RCE in Magento, Adobe Commerce
Attackers are exploiting an unpatched zero-day (StyleSmuggler) in Magento Open Source and Adobe Commerce for unauthenticated RCE, installing backdoors.
CVE-2026-63077: JetBrains Cadence Breach Exposes Credentials
JetBrains Cadence suffered a data breach via unpatched TeamCity (CVE-2026-63077), exposing AWS credentials, source code, and user data. Immediate action required.
SonicWall SMA 1000 Zero-Days: Unauthenticated RCE Explained
Zero-day vulnerabilities in SonicWall SMA 1000 series appliances enable unauthenticated remote code execution, posing critical risks to organizations.
AI's Impact on Vulnerability Discovery & Vendor Readiness
AI-driven vulnerability discovery is overwhelming software vendors, exposing secure-by-design failures and challenging traditional disclosure models.
CVE-2026-19490: Citrix NetScaler Auth Bypass Under Attack
Critical Citrix NetScaler authentication bypass (CVE-2026-19490) is actively exploited in the wild, allowing remote unprivileged access.
Recorded Future's Automated Signatures Combat AI Exploits
Recorded Future launches Automated Signature Creation to rapidly detect and prioritize vulnerabilities, closing the gap against AI-accelerated exploitation.
Exchange Exploit, Dropbox Breach, & Cloud Phishing Campaigns
SecurityWeek's roundup highlights a critical Exchange Server exploit, Dropbox account compromises, and cloud phishing. Urgent action is advised.
Voting System Vulnerability: Ballot Order Correlation Risk
A voting system vulnerability, nearly four years old, enables ballot order recovery.
CVE-2026-6471: PostgreSQL Takeover via Logical Decoding Flaw
CVE-2026-6471, a 12-year-old PostgreSQL vulnerability, allows attackers with low replication privileges to achieve RCE and full database server takeover.
Chrome Zero-Day CVE-2026-85046 Actively Exploited: Patch Now
Google released an urgent update for a critical Chrome zero-day, CVE-2026-85046, actively exploited in V8 engine type confusion attacks.
WordPress RCE Exploited via CVE-2026-14894 & CVE-2026-32475
Attackers exploit critical RCE flaws in WordPress Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to deploy web shells and seize sites.
Cloudflare Enhances Vulnerability Management with AI & Context
Cloudflare introduces a new service leveraging AI and real-world operational context to prioritize and remediate vulnerabilities in customer codebases.
H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion
Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.
CVE-2026-73749: HPE ArubaOS-CX RCE Flaw Patched
HPE patches a critical remote code execution flaw, CVE-2026-73749, in ArubaOS-CX switches. Unauthenticated attackers can exploit a buffer overflow.
Critical Cisco Nexus 9000 RCE (CVE-2026-20212) & IOS XR Hardening
Cisco addresses a critical RCE flaw (CVE-2026-20212) in Nexus 9000 switches, alongside significant IOS XR hardening updates.
Plex Media Server & Desktop: Patch Critical Security Flaws
Plex advises users to immediately update Plex Media Server to v1.43.3 and Plex Desktop to v1.115.0 to resolve multiple undisclosed security vulnerabilities.
AI Vulnerability Surge: Enterprise Security Strategies
New research suggests the anticipated increase in AI vulnerabilities can be managed by enterprise security teams with effective strategies.
Google, Anthropic, and OpenAI Launch Cyber AI Models and Safeguards
Google, Anthropic, and OpenAI unveil advanced cybersecurity AI models like Gemini 3.8 Flash Cyber, focusing on defense and strict access controls.
CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.
CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection
Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.