Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
Recorded Future's Automated Signatures Combat AI Exploits
Recorded Future launches Automated Signature Creation to rapidly detect and prioritize vulnerabilities, closing the gap against AI-accelerated exploitation.
Exchange Exploit, Dropbox Breach, & Cloud Phishing Campaigns
SecurityWeek's roundup highlights a critical Exchange Server exploit, Dropbox account compromises, and cloud phishing. Urgent action is advised.
Voting System Vulnerability: Ballot Order Correlation Risk
A voting system vulnerability, nearly four years old, enables ballot order recovery.
CVE-2026-6471: PostgreSQL Takeover via Logical Decoding Flaw
CVE-2026-6471, a 12-year-old PostgreSQL vulnerability, allows attackers with low replication privileges to achieve RCE and full database server takeover.
Chrome Zero-Day CVE-2026-85046 Actively Exploited: Patch Now
Google released an urgent update for a critical Chrome zero-day, CVE-2026-85046, actively exploited in V8 engine type confusion attacks.
WordPress RCE Exploited via CVE-2026-14894 & CVE-2026-32475
Attackers exploit critical RCE flaws in WordPress Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to deploy web shells and seize sites.
Cloudflare Enhances Vulnerability Management with AI & Context
Cloudflare introduces a new service leveraging AI and real-world operational context to prioritize and remediate vulnerabilities in customer codebases.
H1 2026 Malware & Vulnerability Trends: AI Impact & Evasion
Analysis of H1 2026 malware and vulnerability trends, highlighting AI-assisted exploit development and adversary use of legitimate tools for evasion.
CVE-2026-73749: HPE ArubaOS-CX RCE Flaw Patched
HPE patches a critical remote code execution flaw, CVE-2026-73749, in ArubaOS-CX switches. Unauthenticated attackers can exploit a buffer overflow.
Critical Cisco Nexus 9000 RCE (CVE-2026-20212) & IOS XR Hardening
Cisco addresses a critical RCE flaw (CVE-2026-20212) in Nexus 9000 switches, alongside significant IOS XR hardening updates.
Plex Media Server & Desktop: Patch Critical Security Flaws
Plex advises users to immediately update Plex Media Server to v1.43.3 and Plex Desktop to v1.115.0 to resolve multiple undisclosed security vulnerabilities.
AI Vulnerability Surge: Enterprise Security Strategies
New research suggests the anticipated increase in AI vulnerabilities can be managed by enterprise security teams with effective strategies.
Google, Anthropic, and OpenAI Launch Cyber AI Models and Safeguards
Google, Anthropic, and OpenAI unveil advanced cybersecurity AI models like Gemini 3.8 Flash Cyber, focusing on defense and strict access controls.
CVE-2026-83548: SonicWall SMA1000 SSRF Under Active Exploitation
A critical server-side request forgery (SSRF) vulnerability, CVE-2026-83548, in SonicWall SMA1000 Appliances is under active exploitation.
CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection
Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.
CVE-2026-49869: Kestra OSS OS Command Injection Exploited
CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.
CVE-2026-48710: Kludex Starlette HTTP Smuggling for Auth Bypass
CVE-2026-48710 impacts Kludex Starlette, enabling HTTP request smuggling and authentication bypass via path injection. Actively exploited.
CVE-2026-59822: BerriAI LiteLLM Authentication Bypass
BerriAI LiteLLM is vulnerable to an improper authentication flaw (CVE-2026-59822) actively exploited to bypass authentication.
CVE-2026-84115: Cleo Harmony Auth Bypass Exploit Published
An exploit is published for CVE-2026-84115, an authentication bypass in Cleo Harmony allowing remote privilege escalation. Immediate patching to v5.8.1.11 is urged.
Philippines Nuclear Agency Breached via Unpatched ownCloud Flaws
Threat actors exploit unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing sensitive databases and credentials.
Dark Web Service Nexus Sells 153M+ Driver Licenses
A new dark web service, Nexus, is selling over 153 million drivers' licenses from North America, likely sourced from an identity verification company.
CVE-2026-82329: JFrog Artifactory Auth Bypass to Admin Tokens
Threat actors are exploiting CVE-2026-82329 in JFrog Artifactory, an authentication bypass allowing unauthenticated admin access. Patch immediately.
AI-Assisted PLC Exploit Porting: WAGO RCE via Claude
Forescout researchers used Anthropic's Claude to port a WAGO PLC RCE exploit, demonstrating AI's potential in offensive security but highlighting current challenges.
CVE-2026-62911: Exchange Servers Vulnerable to Mailbox Hijack
Nearly 22,000 Microsoft Exchange Servers remain unpatched against CVE-2026-62911, an auth bypass allowing mailbox hijack attacks.