Skip to main content

Coverage

Vulnerabilities

903 articles on vulnerability disclosures and exploits

Advertisement

VU
HIGH
Vulnerabilities

CVE-2024-2123 & CVE-2024-2510: Avada Builder Patch Guidance

Critical flaws in Avada Builder WordPress plugin (CVE-2024-2123, CVE-2024-2510) allow for credential theft and LFI. Immediate update to version 3.11.7 required.

Runtime Rebel Intel
3 min read·May 15, 2026
OpenClaw "Claw Chain" Flaws: Data Theft and Persistence Risks
HIGH
Vulnerabilities

OpenClaw "Claw Chain" Flaws: Data Theft and Persistence Risks

Researchers at Cyera have identified the Claw Chain, a set of four OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistent access.

Runtime Rebel Intel
3 min read·May 15, 2026
ID
LOW
Identity & Access

Bypassing AI-Based Age Verification via Facial Obfuscations

Research reveals that AI-driven age estimation systems can be bypassed using physical facial alterations, highlighting flaws in biometric verification models.

Runtime Rebel Intel
3 min read·May 15, 2026
20 Years of Cybersecurity: Strategic Insights from Industry Pioneers
INFO
Threat Intel

20 Years of Cybersecurity: Strategic Insights from Industry Pioneers

Leading cybersecurity experts reflect on two decades of evolving threats, bug bounties, and the critical transition toward identity-centric security models.

Runtime Rebel Intel
3 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-42897: Microsoft Exchange Server Zero-Day Exploited in Wild

Microsoft warns of CVE-2026-42897, a critical Exchange Server zero-day exploited in the wild. Implement Extended Protection mitigations immediately to secure systems.

Runtime Rebel Intel
3 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability

Microsoft warns of CVE-2024-49040, a zero-day spoofing vulnerability in Exchange Server exploited to bypass security filters and impersonate trusted senders.

Runtime Rebel Intel
4 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

PAN-OS RCE via CVE-2024-3400 — Critical Vulnerability Mitigation Guide

Exploit analysis and mitigation for CVE-2024-3400, a critical command injection flaw in Palo Alto Networks PAN-OS GlobalProtect allowing unauthenticated RCE.

Runtime Rebel Intel
3 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

Cisco SD-WAN RCE via CVE-2026-20182 — Mitigation Guide

Cisco patches CVE-2026-20182, the sixth SD-WAN zero-day exploited in 2026. Learn how threat actor UAT-8616 leverages this flaw for targeted attacks.

Runtime Rebel Intel
3 min read·May 15, 2026
VU
HIGH
Vulnerabilities

Chrome 148 Update: Patching Critical Use-After-Free Vulnerabilities

Google releases Chrome 148 addressing critical-severity use-after-free vulnerabilities. Learn how these memory corruption bugs impact browser security and remediation

Runtime Rebel Intel
3 min read·May 15, 2026
Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit
CRITICAL
Vulnerabilities

Cisco Catalyst SD-WAN Authentication Bypass: CVE-2026-20182 Exploit

CISA adds CVE-2026-20182 to its KEV catalog after reports of active exploitation against Cisco Catalyst SD-WAN Controllers. Critical patch required.

Runtime Rebel Intel
3 min read·May 15, 2026
CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server
CRITICAL
Vulnerabilities

CVE-2026-42897: How Attackers Exploit Microsoft Exchange Server

Microsoft warns of active exploitation of CVE-2026-42897, a critical spoofing and XSS vulnerability in on-premise Exchange Server triggered via email.

Runtime Rebel Intel
3 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited

Hackers are actively exploiting CVE-2024-7109, a critical authentication bypass in Burst Statistics WordPress plugin, to gain admin access. Patch immediately.

Runtime Rebel Intel
4 min read·May 15, 2026