Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
phpBB Authentication Bypass: Admin Login Vulnerability Patched
A decade-old authentication bypass in phpBB forum software, affecting versions up to 3.3.11, allowed attackers to log in as any user, including administrators.
CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters
Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.
CVE-2026-28742 & Others: Naxclow IoT Platform Critical Flaws
CISA warns of multiple critical vulnerabilities in Naxclow IoT Platform, including hard-coded cryptographic keys, authorization bypasses, and credential exposure.
Ivanti Sentry Max-Severity Flaw Exploited Within 24 Hours
A critical Ivanti Sentry vulnerability was actively exploited within 24 hours of public disclosure. Defenders must patch immediately to prevent compromise.
Chrome 149 Update Patches 28 Vulnerabilities — Mitigation Guide
Google addresses 28 security flaws in Chrome 149, including critical use-after-free bugs. Learn about technical impacts and enterprise patching requirements.
Ivanti Sentry CVE-2023-35081: CISA Issues Urgent 3-Day Patch Mandate
CISA adds CVE-2023-35081 to its KEV catalog, ordering federal agencies to patch Ivanti Sentry path traversal flaws to prevent remote code execution.
Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide
ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.
Yarbo Mobile App & Cloud: Critical Robot Fleet Vulnerabilities
Critical vulnerabilities CVE-2026-10557 & CVE-2026-7368 in Yarbo mobile app and cloud allow attackers to control robot fleets via hard-coded credentials.
CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters
Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.
CISA BOD 26-04: Prioritizing KEV Catalog Vulnerability Patching
CISA's BOD 26-04 mandates federal agencies prioritize patching vulnerabilities in the KEV catalog. Learn its impact and how to enhance your vulnerability management.
CISA Mandates Critical Ivanti & ActiveMQ Patching in 3 Days
CISA's BOD 26-04 requires federal agencies to patch critical, exploited Ivanti Connect Secure and Apache ActiveMQ vulnerabilities within 72 hours.
AI and the Collapse of the Vulnerability Management Buffer
AI-driven exploitation has eliminated the time buffer between vulnerability discovery and weaponization, prompting a strategic shift toward BAS.
CISA KEV Update: Active Exploitation of Arista, Cisco, and Chrome
CISA adds CVE-2026-7473, CVE-2026-11645, and CVE-2026-20245 to its Known Exploited Vulnerabilities catalog following evidence of active exploitation.
CISA Updates Federal Patching Mandates to Combat AI-Driven Threats
CISA updates federal directive to require 3-day patching for critical flaws, addressing the rapid exploitation speeds enabled by artificial intelligence.
June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now
Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.
Windows Server 2025 BitLocker Recovery Bug: Mitigation Guide
Microsoft resolves a Windows Server 2025 bug causing systems to boot into BitLocker recovery modes following recent security updates. Patching guidance inside.
CVE-2024-5027: Langflow Path Traversal Exploited in Attacks
Security researchers observe active exploitation of CVE-2024-5027, a high-severity path traversal flaw in the Langflow AI platform allowing arbitrary file writes.
FortiSandbox Command Injection (CVE-2026-25089) & Critical Vendor Patches
Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.
Bridging the Gap: Addressing Automated Pentest Blind Spots
Automated penetration tests often miss critical vulnerabilities. Learn why a hybrid approach combining automation with expert-driven manual testing is essential for…
ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances
ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances.
Adobe Addresses 123 Vulnerabilities: Focus on Experience Manager RCE
Adobe's extensive patch cycle resolves 123 vulnerabilities across multiple products, with a critical focus on Experience Manager arbitrary code execution flaws.
Microsoft Patch Tuesday: 200 Vulnerabilities Addressed
Microsoft addressed 200 vulnerabilities in its latest Patch Tuesday, including three publicly disclosed flaws. Prompt patching is essential for defense.
Protobuf.js RCE Vulnerabilities: Node.js Security Mitigation Guide
Six high-severity vulnerabilities in protobuf.js enable RCE and DoS in Node.js apps. Learn how to detect and mitigate these Proto6 flaws in your environment.
Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.