Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

FortiClient EMS Critical Flaw Exploited for Credential Stealing
CRITICAL
Vulnerabilities

FortiClient EMS Critical Flaw Exploited for Credential Stealing

Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.

Runtime Rebel Intel
5 min read · May 28, 2026
CRITICAL
Vulnerabilities

CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation

Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.

Runtime Rebel Intel
3 min read · May 28, 2026
CRITICAL
Vulnerabilities

Actively Exploited CVEs: Daemon Tools Lite, TanStack, Nx Console

CISA added three vulnerabilities—CVE-2026-8398, CVE-2026-45321, CVE-2026-48027—to its KEV Catalog due to active exploitation. Prioritize patching.

Runtime Rebel Intel
5 min read · May 27, 2026
AI-Assisted Exploit Development Shorthand Vulnerability Windows
HIGH
Threat Intel

AI-Assisted Exploit Development Shorthand Vulnerability Windows

AI tools enable attackers to develop exploits for newly disclosed CVEs in hours, outpacing traditional vulnerability scanner detection capabilities.

Runtime Rebel Intel
3 min read · May 27, 2026
HIGH
Vulnerabilities

CVE-2024-45404: Pretalx Logic Flaw Enables Full Account Takeover

Researchers discover a critical logic flaw in Pretalx versions prior to 2024.1.0 that allows attackers to hijack organizer accounts and manipulate events.

Runtime Rebel Intel
3 min read · May 27, 2026
INFO
Supply Chain

RevEng.AI Secures $15M for AI-Powered Software Binary Analysis

RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.

Runtime Rebel Intel
4 min read · May 27, 2026
CRITICAL
Vulnerabilities

CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw

CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.

Runtime Rebel Intel
4 min read · May 27, 2026
CRITICAL
Vulnerabilities

CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day

CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.

Runtime Rebel Intel
4 min read · May 27, 2026
INFO
Vulnerabilities

Windows 11 KB5089573: Performance and Reliability Fixes for 24H2/25H2

Microsoft releases KB5089573 preview for Windows 11 24H2 and 25H2, addressing Task Manager bugs, ReFS performance issues, and Sandbox stability errors.

Runtime Rebel Intel
3 min read · May 27, 2026
HIGH
Vulnerabilities

DrayTek Vigor RCE: Patching CVE-2024-41585 Command Injection

Critical OS command injection in DrayTek Vigor routers allows unauthenticated RCE. Learn how to patch CVE-2024-41585 and protect your network edge.

Runtime Rebel Intel
3 min read · May 27, 2026
HIGH
Vulnerabilities

CVE-2023-47359 & More: Critical Vulnerabilities in ABB Ability Camera Connect

Multiple critical and high-severity vulnerabilities in ABB Ability Camera Connect (VLC component <=1.5.0.14) could lead to RCE or DoS. Update to 1.5.0.15 now.

Runtime Rebel Intel
5 min read · May 26, 2026
HIGH
Vulnerabilities

CVE-2026-7251: Hard-coded Password in Eppendorf BioFlo 320

Critical hard-coded password vulnerability (CVE-2026-7251) in Eppendorf BioFlo 320 bioreactors allows full remote control. Patch immediately.

Runtime Rebel Intel
5 min read · May 26, 2026
CRITICAL
Vulnerabilities

KnowledgeDeliver RCE via CVE-2024-52648 — Mitigation Guide

Attackers are exploiting a critical zero-day vulnerability (CVE-2024-52648) in KnowledgeDeliver LMS to deploy Godzilla web shells. Secure your servers now.

Runtime Rebel Intel
3 min read · May 26, 2026
CVE-2026-45659: SharePoint RCE via Deserialization - Patch Now
HIGH
Vulnerabilities

CVE-2026-45659: SharePoint RCE via Deserialization - Patch Now

Microsoft addresses CVE-2026-45659, a high-severity RCE flaw in SharePoint Server caused by untrusted data deserialization. Learn how to mitigate this risk.

Runtime Rebel Intel
3 min read · May 26, 2026
HIGH
Vulnerabilities

Drupal 7.x SQL Injection CVE-2014-3704 — Active Exploitation Alert

CISA adds Drupalgeddon SQL injection (CVE-2014-3704) to KEV catalog, mandating federal agencies to patch critical legacy systems against active exploits.

Runtime Rebel Intel
3 min read · May 26, 2026
CVE-2026-5426: KnowledgeDeliver LMS Zero-Day Exploited for Godzilla Shell
CRITICAL
Vulnerabilities

CVE-2026-5426: KnowledgeDeliver LMS Zero-Day Exploited for Godzilla Shell

Attackers exploited a zero-day in KnowledgeDeliver LMS (CVE-2026-5426) using hard-coded ASP.NET keys to deploy Godzilla web shells and Cobalt Strike Beacons.

Runtime Rebel Intel
4 min read · May 26, 2026
CRITICAL
Vulnerabilities

Ghost CMS CVE-2022-41654: Over 700 Websites Compromised

Attackers are exploiting a critical Ghost CMS vulnerability to inject malicious scripts into sites belonging to Harvard, Oxford, and DuckDuckGo.

Runtime Rebel Intel
3 min read · May 25, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Vulnerabilities

CVE-2026-5426: RCE via ViewState Deserialization in KnowledgeDeliver

Attackers exploit CVE-2026-5426 in the KnowledgeDeliver LMS to achieve RCE via shared ASP.NET machine keys. Immediate key rotation and patching are required.

Runtime Rebel Intel
3 min read · May 25, 2026
MEDIUM
Vulnerabilities

Wireshark 4.6.6: Fixing Critical Vulnerability and Dissector Bugs

Wireshark 4.6.6 release addresses one security vulnerability and 11 functional bugs. Learn how this update secures packet analysis and prevents dissector crashes.

Runtime Rebel Intel
4 min read · May 24, 2026
HIGH
Vulnerabilities

CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign

A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.

Runtime Rebel Intel
3 min read · May 24, 2026
Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws
HIGH
Vulnerabilities

Anthropic Project Glasswing Uncovers 10,000 High-Severity Flaws

Anthropic's Claude Mythos AI identifies over 10,000 critical and high-severity vulnerabilities in systemically important software via Project Glasswing.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Vulnerabilities

Underminr Vulnerability: Bypassing DNS Filtering via Trusted Domains

The Underminr vulnerability affects 88 million domains, allowing attackers to hide C2 traffic and bypass DNS filtering using shared infrastructure.

Runtime Rebel Intel
4 min read · May 23, 2026
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog

CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.

Runtime Rebel Intel
3 min read · May 23, 2026