Skip to main content

Coverage

Vulnerabilities

903 articles on vulnerability disclosures and exploits

Advertisement

CVE-2026-31635: DirtyDecrypt Linux Kernel LPE PoC Released
HIGH
Vulnerabilities

CVE-2026-31635: DirtyDecrypt Linux Kernel LPE PoC Released

Exploit code for DirtyDecrypt (CVE-2026-31635) has been released, allowing local privilege escalation via vulnerabilities in the Linux kernel crypto API.

Runtime Rebel Intel
4 min read·May 19, 2026
VU
CRITICAL
Vulnerabilities

ChromaDB RCE via CVE-2024-34359 — Mitigation and Patch Guide

Discover how unauthenticated attackers exploit CVE-2024-34359 in ChromaDB for remote code execution. Learn detection strategies and patch requirements now.

Runtime Rebel Intel
3 min read·May 19, 2026
Drupal Core Security Update May 2026: Critical Patch Advisory
CRITICAL
Vulnerabilities

Drupal Core Security Update May 2026: Critical Patch Advisory

Drupal warns of an urgent core security update on May 20, 2026. Security teams must prepare for immediate patching to prevent exploit development.

Runtime Rebel Intel
4 min read·May 19, 2026
VU
CRITICAL
Vulnerabilities

Universal Robots PolyScope 5 RCE via CVE-2024-8153 — Patch Now

Critical OS command injection vulnerability in Universal Robots PolyScope 5 allows attackers to compromise industrial robot fleets. Patch to version 5.19.0.

Runtime Rebel Intel
3 min read·May 19, 2026
OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence
HIGH
Vulnerabilities

OpenClaw 'Claw Chain' Vulnerabilities: Credential Theft, Persistence

Analysis of 'Claw Chain' vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks. Patching guidance

Runtime Rebel Intel
4 min read·May 19, 2026
CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack

Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.

Runtime Rebel Intel
5 min read·May 19, 2026
Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use
CRITICAL
Threat Intel

Microsoft Exchange Zero-Day and npm Supply Chain Worm Under Active Use

Critical security briefing on the active exploitation of an Exchange Server zero-day, npm supply chain worms, and Cisco network control vulnerabilities.

Runtime Rebel Intel
3 min read·May 18, 2026
VU
HIGH
Vulnerabilities

YellowKey: Bypassing Windows 11 BitLocker TPM Protections

Technical analysis of YellowKey, a zero-day exploit bypassing Windows 11 BitLocker. Learn how physical access allows attackers to extract encryption keys.

Runtime Rebel Intel
4 min read·May 18, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-41662: Chaining OpenClaw Flaws for Sandbox Escape

CyberArk researchers uncover the Claw Chain in OpenClaw, allowing attackers to escape sandboxes, steal credentials, and deploy persistent backdoors.

Runtime Rebel Intel
3 min read·May 18, 2026
Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws
CRITICAL
Vulnerabilities

Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws

Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.

Runtime Rebel Intel
3 min read·May 18, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-31079: Critical NGINX RCE Vulnerability Exploitation

Active exploitation of CVE-2024-31079 in the NGINX HTTP/3 module allows for RCE and DoS. Security teams must patch NGINX Open Source and Plus immediately.

Runtime Rebel Intel
3 min read·May 18, 2026
VU
HIGH
Vulnerabilities

DirtyDecrypt: How Attackers Exploit Linux Kernel rxgk for Root Access

Learn about DirtyDecrypt, a local privilege escalation vulnerability in the Linux rxgk module. Discover how to detect and mitigate this root access threat.

Runtime Rebel Intel
3 min read·May 18, 2026