Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

CRITICAL
Vulnerabilities

CVE-2024-21182: Oracle WebLogic Server Under Active Exploitation

CISA added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its KEV Catalog due to active exploitation. Immediate patching required.

Runtime Rebel Intel
5 min read · Jun 1, 2026
HIGH
Threat Intel

AI Reshapes Vulnerability Disclosure: Urgent Action for Remediation

AI models accelerate vulnerability discovery, challenging traditional disclosure.

Runtime Rebel Intel
4 min read · Jun 1, 2026
Palo Alto PAN-OS GlobalProtect VPN: Active Auth Bypass Exploitation
CRITICAL
Vulnerabilities

Palo Alto PAN-OS GlobalProtect VPN: Active Auth Bypass Exploitation

Urgent advisory on the active exploitation of an authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect VPN. Patch immediately.

Runtime Rebel Intel
5 min read · Jun 1, 2026
CRITICAL
Vulnerabilities

CVE-2026-41089: Critical Windows Netlogon Vulnerability Under Attack

Attackers are actively targeting CVE-2026-41089, a critical Windows Netlogon RCE vulnerability. Immediate patching and log monitoring are required.

Runtime Rebel Intel
3 min read · Jun 1, 2026
CRITICAL
Vulnerabilities

CVE-2020-1472: How Attackers Exploit Windows Netlogon RCE — Patch Now

Threat actors are actively exploiting Zerologon (CVE-2020-1472), a critical Windows Netlogon RCE vulnerability that allows for full domain takeover.

Runtime Rebel Intel
4 min read · Jun 1, 2026
INFO
Vulnerabilities

Closing the Window: Why Faster Vulnerability Alerts are Critical

Attackers exploit vulnerabilities faster than ever. Learn why reducing the window of exposure through automated alerts is essential for modern cybersecurity.

Runtime Rebel Intel
4 min read · Jun 1, 2026
PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap
HIGH
Threat Intel

PAN-OS Exploitation and Linux Auth Flaws: Weekly Threat Recap

An analysis of active PAN-OS exploitation, a new Linux authentication flaw, and the rise of AI-powered OAuth phishing kits targeting enterprise environments.

Runtime Rebel Intel
3 min read · Jun 1, 2026
WP Maps Pro Flaw Exploited for Admin Account Creation — Patch Now
CRITICAL
Vulnerabilities

WP Maps Pro Flaw Exploited for Admin Account Creation — Patch Now

Attackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on affected sites.

Runtime Rebel Intel
3 min read · Jun 1, 2026
HIGH
Vulnerabilities

CVE-2024-10642: WP Maps Pro Exploited to Create WordPress Admin Accounts

Attackers are exploiting a critical privilege escalation flaw in the WP Maps Pro WordPress plugin to create rogue admin accounts without authentication.

Runtime Rebel Intel
3 min read · May 31, 2026
CRITICAL
Vulnerabilities

CVE-2024-5910: Palo Alto GlobalProtect Auth Bypass Exploited - Patch Now

Palo Alto Networks warns that attackers are exploiting CVE-2024-5910, a critical authentication bypass in GlobalProtect gateway. Learn how to secure your PAN-OS.

Runtime Rebel Intel
4 min read · May 30, 2026
HIGH
Vulnerabilities

Flowise RCE via CVE-2024-31621 — Mitigation Guide

Exploit code is public for a critical RCE vulnerability in Flowise. Attackers use malicious chatflow imports to compromise self-hosted servers.

Runtime Rebel Intel
4 min read · May 30, 2026
HIGH
Vulnerabilities

CVE-2024-52336: How CIFSwitch Grants Root Access on Linux Systems

The CVE-2024-52336 vulnerability, known as CIFSwitch, allows local privilege escalation to root by abusing CIFS key requests in the Linux kernel.

Runtime Rebel Intel
4 min read · May 30, 2026
CVE-2026-0257: PAN-OS GlobalProtect Auth Bypass Under Exploitation
CRITICAL
Vulnerabilities

CVE-2026-0257: PAN-OS GlobalProtect Auth Bypass Under Exploitation

Palo Alto Networks warns of active exploitation of CVE-2026-0257, an authentication bypass vulnerability affecting PAN-OS and Prisma Access GlobalProtect gateways.

Runtime Rebel Intel
3 min read · May 30, 2026
CRITICAL
Vulnerabilities

CVE-2026-0257: Palo Alto PAN-OS Auth Bypass Under Active Attack

CISA adds CVE-2026-0257, an actively exploited authentication bypass in Palo Alto Networks PAN-OS, to its KEV catalog.

Runtime Rebel Intel
4 min read · May 29, 2026
ChatGPT ChatGPhish Vulnerability: Web Summaries Lead to Phishing
MEDIUM
Vulnerabilities

ChatGPT ChatGPhish Vulnerability: Web Summaries Lead to Phishing

A newly disclosed ChatGPhish vulnerability allows attackers to leverage ChatGPT's Markdown trust for prompt injections and sophisticated phishing campaigns.

Runtime Rebel Intel
4 min read · May 29, 2026
CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation
HIGH
Threat Intel

CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation

Discover how threat actors are leveraging LLM agents to automate post-exploitation tasks after compromising Marimo notebooks via CVE-2026-39987.

Runtime Rebel Intel
3 min read · May 29, 2026
HIGH
Vulnerabilities

Gogs RCE via CVE-2024-39930 — Mitigation and Patch Guide

A critical argument injection in Gogs (CVE-2024-39930) allows authenticated users to achieve RCE via malicious pull requests. Learn how to patch and defend.

Runtime Rebel Intel
4 min read · May 29, 2026
CRITICAL
Vulnerabilities

VMware Workspace ONE Access RCE via CVE-2022-22960 — Patch Now

VMware Workspace ONE Access and Identity Manager face critical RCE vulnerabilities (CVE-2022-22960, CVE-2022-22957) actively exploited.

Runtime Rebel Intel
5 min read · May 29, 2026
CRITICAL
Vulnerabilities

CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer

Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.

Runtime Rebel Intel
4 min read · May 28, 2026
Gogs Authenticated RCE: Arbitrary Code Execution - Mitigation Guide
HIGH
Vulnerabilities

Gogs Authenticated RCE: Arbitrary Code Execution - Mitigation Guide

A critical RCE vulnerability in Gogs allows authenticated users to execute arbitrary code. Runtime Rebel provides an analysis and urgent mitigation guidance.

Runtime Rebel Intel
4 min read · May 28, 2026
MEDIUM
Vulnerabilities

CVE-2026-6332: Schneider Electric EcoStruxure HVAC Source Code Disclosure

A cleartext storage vulnerability in Schneider Electric EcoStruxure Machine Expert HVAC (CVE-2026-6332) exposes sensitive source code. Update to v1.10.0.

Runtime Rebel Intel
5 min read · May 28, 2026
HIGH
Vulnerabilities

CVE-2021-22291: ABB EIBPORT V3 <3.9.2 Session Hijacking Vulnerability

ABB EIBPORT V3 devices are vulnerable to CVE-2021-22291 (XSS/session hijacking), allowing unauthenticated access and configuration changes. Patch immediately.

Runtime Rebel Intel
4 min read · May 28, 2026
HIGH
Vulnerabilities

Gogs Self-Hosted Git RCE via Zero-Day: Mitigation Guide

An unpatched zero-day vulnerability in Gogs self-hosted Git service allows attackers to achieve remote code execution, impacting Internet-facing instances.

Runtime Rebel Intel
4 min read · May 28, 2026
Microsoft Condemns Public Zero-Day Disclosures, Advocates CVD
INFO
Threat Intel

Microsoft Condemns Public Zero-Day Disclosures, Advocates CVD

Microsoft reiterates strong support for Coordinated Vulnerability Disclosure, criticizing immediate public zero-day disclosures after a researcher's account removal.

Runtime Rebel Intel
4 min read · May 28, 2026