Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
FortiClient EMS Critical Flaw Exploited for Credential Stealing
Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.
CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation
Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.
Actively Exploited CVEs: Daemon Tools Lite, TanStack, Nx Console
CISA added three vulnerabilities—CVE-2026-8398, CVE-2026-45321, CVE-2026-48027—to its KEV Catalog due to active exploitation. Prioritize patching.
AI-Assisted Exploit Development Shorthand Vulnerability Windows
AI tools enable attackers to develop exploits for newly disclosed CVEs in hours, outpacing traditional vulnerability scanner detection capabilities.
CVE-2024-45404: Pretalx Logic Flaw Enables Full Account Takeover
Researchers discover a critical logic flaw in Pretalx versions prior to 2024.1.0 that allows attackers to hijack organizer accounts and manipulate events.
RevEng.AI Secures $15M for AI-Powered Software Binary Analysis
RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.
CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw
CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.
CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day
CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.
Windows 11 KB5089573: Performance and Reliability Fixes for 24H2/25H2
Microsoft releases KB5089573 preview for Windows 11 24H2 and 25H2, addressing Task Manager bugs, ReFS performance issues, and Sandbox stability errors.
DrayTek Vigor RCE: Patching CVE-2024-41585 Command Injection
Critical OS command injection in DrayTek Vigor routers allows unauthenticated RCE. Learn how to patch CVE-2024-41585 and protect your network edge.
CVE-2023-47359 & More: Critical Vulnerabilities in ABB Ability Camera Connect
Multiple critical and high-severity vulnerabilities in ABB Ability Camera Connect (VLC component <=1.5.0.14) could lead to RCE or DoS. Update to 1.5.0.15 now.
CVE-2026-7251: Hard-coded Password in Eppendorf BioFlo 320
Critical hard-coded password vulnerability (CVE-2026-7251) in Eppendorf BioFlo 320 bioreactors allows full remote control. Patch immediately.
KnowledgeDeliver RCE via CVE-2024-52648 — Mitigation Guide
Attackers are exploiting a critical zero-day vulnerability (CVE-2024-52648) in KnowledgeDeliver LMS to deploy Godzilla web shells. Secure your servers now.
CVE-2026-45659: SharePoint RCE via Deserialization - Patch Now
Microsoft addresses CVE-2026-45659, a high-severity RCE flaw in SharePoint Server caused by untrusted data deserialization. Learn how to mitigate this risk.
Drupal 7.x SQL Injection CVE-2014-3704 — Active Exploitation Alert
CISA adds Drupalgeddon SQL injection (CVE-2014-3704) to KEV catalog, mandating federal agencies to patch critical legacy systems against active exploits.
CVE-2026-5426: KnowledgeDeliver LMS Zero-Day Exploited for Godzilla Shell
Attackers exploited a zero-day in KnowledgeDeliver LMS (CVE-2026-5426) using hard-coded ASP.NET keys to deploy Godzilla web shells and Cobalt Strike Beacons.
Ghost CMS CVE-2022-41654: Over 700 Websites Compromised
Attackers are exploiting a critical Ghost CMS vulnerability to inject malicious scripts into sites belonging to Harvard, Oxford, and DuckDuckGo.
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.
CVE-2026-5426: RCE via ViewState Deserialization in KnowledgeDeliver
Attackers exploit CVE-2026-5426 in the KnowledgeDeliver LMS to achieve RCE via shared ASP.NET machine keys. Immediate key rotation and patching are required.
Wireshark 4.6.6: Fixing Critical Vulnerability and Dissector Bugs
Wireshark 4.6.6 release addresses one security vulnerability and 11 functional bugs. Learn how this update secures packet analysis and prevents dissector crashes.
CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign
A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.
Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws
Anthropic's Claude Mythos AI identifies over 10,000 critical and high-severity vulnerabilities in systemically important software via Project Glasswing.
Underminr Vulnerability: Bypassing DNS Filtering via Trusted Domains
The Underminr vulnerability affects 88 million domains, allowing attackers to hide C2 traffic and bypass DNS filtering using shared infrastructure.
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.