Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Adobe ColdFusion RCE & Privilege Escalation Vulnerabilities Patched
Adobe addresses critical ColdFusion vulnerabilities, including RCE and Privilege Escalation flaws. Patching is essential for all administrators.
Progress ShareFile Zero-Day Flaw Prompts Emergency Shutdown
Progress Software confirms a high-severity zero-day vulnerability in ShareFile Storage Zone Controllers led to emergency shutdowns. Patch now.
RabbitMQ Flaws: OAuth Secret Leak & Cross-Tenant Data Exposure
Two RabbitMQ access control flaws enable OAuth secret leakage, cross-tenant data exposure, and potential messaging infrastructure takeover risks.
Joomla Extensions RCE: CISA Warns of Active Exploitation
CISA alerts on actively exploited RCE vulnerabilities in Joomla's iCagenda and Balbooa Forms extensions, urging immediate patching to prevent arbitrary file uploads.
Threat Recap: Unpatched Exploits, Citrix Bleed 2, AI Attacks
Analysis of current cyber threats including persistent unpatched vulnerabilities, the emergence of Citrix Bleed 2 ransomware, and AI's role in attacker toolchains.
CVE-2024-45519: Zimbra Collaboration Suite RCE Patch Guidance
Zimbra patches a critical RCE vulnerability (CVE-2024-45519) affecting the postjournal service. Security teams should prioritize patching and monitoring.
Joomla RCE via CVE-2026-48939 and CVE-2026-38294 — Mitigation Guide
CISA adds CVE-2026-48939 and CVE-2026-38294 to KEV after zero-day exploitation of Joomla iCagenda and Balbooa Forms extensions. Patch immediately.
RedHook Android Malware: Abusing Wireless ADB for Local Shell Access
RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.
June 2026 CVE Landscape: Analyzing the 49% Surge in Critical Risks
Analyzing the June 2026 CVE landscape, which saw 60 high-impact vulnerabilities and a 49% increase in critical risks requiring immediate remediation.
Wireshark 4.6.7 Update: Resolving 12 Critical Dissector Vulnerabilities
Wireshark 4.6.7 addresses 12 vulnerabilities and 16 bugs. Learn how to apply the Wireshark 4.6.7 patch guidance to prevent dissector crashes and DoS attacks.
Zimbra Classic Web Client Stored XSS Leads to Session Hijacking
Zimbra warns of a critical stored XSS vulnerability in the Classic Web Client allowing attackers to execute malicious code via crafted emails.
Jen Ellis: Connecting Cyber Researchers to Political Machinery
A look at Jen Ellis' work bridging the gap between security researchers and policy makers, emphasizing vulnerability disclosure and researcher protections.
U-Boot Vulnerabilities: How to Mitigate CVE-2024-42433 Firmware Flaws
Six vulnerabilities in the U-Boot bootloader, including CVE-2024-42433, allow for stealthy firmware attacks and bypass of secure boot on embedded devices.
Progress ShareFile Storage Zone Controller Security Threat - Shut Down Now
Progress Software urges customers to shut down ShareFile Storage Zone Controllers immediately following reports of a credible external security threat.
Analyzing Microsoft BitLocker Security Wrapper Vulnerabilities
New security vulnerabilities identified in a Microsoft BitLocker security wrapper pose a risk to organizations and potentially ATMs, potentially leading to compromise.
Zimbra Classic Web Client XSS: Critical Flaw Under Active Exploit
A critical XSS vulnerability in Zimbra Classic Web Client is under active exploitation, allowing credential theft and session hijacking.
XRING Flaw: Unpatched XQUIC HTTP/3 Server DoS Vulnerability
An unpatched flaw, dubbed XRING, in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers with minimal, legal traffic, posing a significant DoS risk.
Ill Bloom Vulnerability: Weak Randomness Drains Crypto Wallets
Attackers are exploiting 'Ill Bloom,' a critical flaw in crypto wallet recovery phrase generation due to weak randomness, draining $3.1 million.
Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities
Iranian state-sponsored cyber operations are broadening targets beyond critical infrastructure. All organizations must secure Internet-facing systems.
Windows Defender RoguePlanet Zero-Day Threat: Patch Now
Microsoft addresses the 'RoguePlanet' Windows Defender zero-day, with a PoC released by researcher Nightmare-Eclipse. Patching is critical.
Athena: A New Clearinghouse for Actionable Threat Intelligence
Runtime Rebel announces Athena, a operational cybersecurity clearinghouse sharing findings and fixes to enhance organizational defenses and streamline vulnerability…
CVE-2026-50656: Microsoft Defender Privilege Escalation – Patch Now
Microsoft patches 'RoguePlanet' vulnerability, CVE-2026-50656, in Defender's Malware Protection Engine, enabling privilege escalation. Update immediately.
Chrome 150 Update: Patching 27 Vulnerabilities, Critical Use-After-Free Flaws
Google Chrome 150 update patches 27 vulnerabilities, including two critical use-after-free bugs.
Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide
Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.