Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now
Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.
CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability Exploit
Microsoft addresses CVE-2024-49040, an actively exploited spoofing zero-day in Exchange Server 2016 and 2019 that bypasses anti-phishing protections.
Windows Server 2025 BitLocker Recovery Bug: Mitigation Guide
Microsoft resolves a Windows Server 2025 bug causing systems to boot into BitLocker recovery modes following recent security updates. Patching guidance inside.
CVE-2024-5027: Langflow Path Traversal Exploited in Attacks
Security researchers observe active exploitation of CVE-2024-5027, a high-severity path traversal flaw in the Langflow AI platform allowing arbitrary file writes.

FortiSandbox Command Injection (CVE-2026-25089) & Critical Vendor Patches
Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.

Bridging the Gap: Addressing Automated Pentest Blind Spots
Automated penetration tests often miss critical vulnerabilities. Learn why a hybrid approach combining automation with expert-driven manual testing is essential for

ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances
ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances. Threat actors exploited this vulnerability; immediate patching is
Adobe Addresses 123 Vulnerabilities: Focus on Experience Manager RCE
Adobe's extensive patch cycle resolves 123 vulnerabilities across multiple products, with a critical focus on Experience Manager arbitrary code execution flaws.
Microsoft Patch Tuesday: 200 Vulnerabilities Addressed
Microsoft addressed 200 vulnerabilities in its latest Patch Tuesday, including three publicly disclosed flaws. Prompt patching is essential for defense.

Protobuf.js RCE Vulnerabilities: Node.js Security Mitigation Guide
Six high-severity vulnerabilities in protobuf.js enable RCE and DoS in Node.js apps. Learn how to detect and mitigate these Proto6 flaws in your environment.
Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.
SAP NetWeaver & Commerce Cloud: Urgent Critical Patches Released
SAP addresses 15 vulnerabilities, including four critical flaws in NetWeaver AS Java and Commerce Cloud, requiring immediate patching to prevent remote exploitation.