Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement

NIST NVD Enrichment Policy Shift: Prioritizing Attacker Behavior
NIST NVD's recent policy change impacts CVE enrichment, covering only 15-20%. This shift emphasizes prioritizing vulnerabilities based on real attacker behavior.
CVE-2026-40175: Siemens gWAP RCE via Axios Prototype Pollution
Siemens gWAP is vulnerable to RCE via CVE-2026-40175, a prototype pollution flaw in the Axios HTTP client library. Update to v3.1.1 or later.
CVE-2026-41551: Siemens ROS# Path Traversal Remediation Guide
Critical path traversal vulnerability (CVE-2026-41551) in Siemens ROS# file_server allows arbitrary file access. Immediate update to v2.2.2+ is crucial.
CVE-2026-46300: Fragnesia Flaw Enables Linux Root Privilege Escalation
Security researchers identify Fragnesia (CVE-2026-46300), a Linux kernel vulnerability allowing local attackers to gain root access via packet fragmentation.
Cisco Catalyst SD-WAN Controller Authentication Bypass via CVE-2026-20182 Exploited in Zero-Day Attacks
Cisco warns of a critical authentication bypass in Catalyst SD-WAN Controller (CVE-2026-20182) actively exploited in zero-day attacks, granting admin access.

CVE-2026-20182: Cisco SD-WAN Auth Bypass Actively Exploited
Cisco Catalyst SD-WAN Controller and Manager face critical authentication bypass CVE-2026-20182, actively exploited for admin access. Patch now.
CVE-2021-23017: NGINX DNS Resolver Buffer Overflow — Patch Now
An 18-year-old stack-based buffer overflow in the NGINX DNS resolver could lead to DoS or RCE. Learn how to secure your web server configuration today.
Anthropic Claude Mythos: Scaling AI-Driven Vulnerability Discovery
Anthropic restricts Claude Mythos Preview access due to its advanced ability to find software vulnerabilities, signaling a shift in automated security research.
Dell SupportAssist v4.0.3 Causes Windows BSOD — Remediation Guide
Dell confirms SupportAssist v4.0.3 causes frequent Windows BSOD crashes and system reboots. Learn how to identify and mitigate these stability issues now.

PraisonAI Auth Bypass CVE-2026-44338 Exploited — Patching Guide
Threat actors are actively exploiting CVE-2026-44338, a critical authentication bypass in the PraisonAI framework, just hours after public disclosure.
Outlook Junk Folder Bypass: How Attackers Hide Malicious URLs
Discover how attackers bypass Microsoft Outlook's Junk folder link preview protection using HTML manipulation to hide malicious phishing URLs from users.
Windows Zero-Days: Analyzing YellowKey and GreenPlasma Exploits
A technical breakdown of the unpatched YellowKey BitLocker bypass and GreenPlasma local privilege escalation vulnerabilities affecting Windows systems.