Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement

Veeam Backup & Replication RCE via CVE-2026-44963 — Patch Guide
A critical RCE flaw (CVE-2026-44963) in Veeam Backup & Replication allows authenticated domain users to execute code. Patch immediately.
Siemens KACO Blueplanet Inverter Vulnerabilities: CVE-2025-40946 & CVE-2026-41125
Critical Siemens KACO Blueplanet Inverters are vulnerable to credential derivation (CVE-2025-40946) and SQL injection (CVE-2026-41125). Update now to mitigate

CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.
LLM-Assisted Exploit Creation: Claude Mythos Accelerates N-Day Attacks
Researchers demonstrate how Claude 3.5 Sonnet can automate exploit development, turning newly disclosed N-day vulnerabilities into functional attacks in hours.
OpenSSL 3.4.1 and 3.0.16 Patches: Fix for CVE-2025-0167 High-Severity Bug
OpenSSL releases patches for 18 vulnerabilities, including a high-severity AI-discovered bug, CVE-2025-0167. Learn how to secure your infrastructure now.
Anthropic Mythos Preview: Advancing AI Offensive Security Performance
XBOW evaluates Anthropic's Mythos Preview model, revealing high efficacy in automated vulnerability discovery, reverse engineering, and exploit development.
SAP NetWeaver and Commerce CVE-2024-21733 Mitigation Guide
SAP releases January 2024 security updates addressing critical vulnerabilities in BusinessObjects, NetWeaver, and Commerce Cloud. Patch now to prevent RCE.

CVE-2025-8088: Russia-Aligned Groups Exploit WinRAR Flaw in Ukraine
Russia-linked actors Earth Dahu and UAC-0226 exploit the CVE-2025-8088 WinRAR path traversal flaw to deploy info-stealers against Ukrainian organizations.
CISA Adds CVE-2026-42271 and CVE-2026-50751 to KEV Catalog
CISA warns of active exploitation involving BerriAI LiteLLM and Check Point Security Gateways. Learn how to mitigate these critical security flaws.
Google Patches CVE-2026-11645: 5th Chrome Zero-Day Exploited in 2026
Google addresses CVE-2026-11645, a critical zero-day vulnerability in Chrome being actively exploited. Learn about patch guidance and detection strategies.
CVE-2024-4947: Google Patches Fifth Chrome Zero-Day of 2024
Google addresses CVE-2024-4947, a high-severity V8 type confusion vulnerability in Chrome being exploited in the wild. Update to version 125.0.6422.60 now.
Check Point CVE-2024-24919: CISA Warns of Ransomware Exploitation
CISA mandates emergency patching for CVE-2024-24919 after Check Point VPN devices were targeted by ransomware gangs to gain initial network access.