Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

CRITICAL
Vulnerabilities

CVE-2024-7109: Burst Statistics WordPress Plugin Auth Bypass Exploited

Hackers are actively exploiting CVE-2024-7109, a critical authentication bypass in Burst Statistics WordPress plugin, to gain admin access. Patch immediately.

Runtime Rebel Intel
4 min read · May 15, 2026
NIST NVD Enrichment Policy Shift: Prioritizing Attacker Behavior
INFO
Vulnerabilities

NIST NVD Enrichment Policy Shift: Prioritizing Attacker Behavior

NIST NVD's recent policy change impacts CVE enrichment, covering only 15-20%. This shift emphasizes prioritizing vulnerabilities based on real attacker behavior.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

CVE-2026-40175: Siemens gWAP RCE via Axios Prototype Pollution

Siemens gWAP is vulnerable to RCE via CVE-2026-40175, a prototype pollution flaw in the Axios HTTP client library. Update to v3.1.1 or later.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

CVE-2026-41551: Siemens ROS# Path Traversal Remediation Guide

Critical path traversal vulnerability (CVE-2026-41551) in Siemens ROS# file_server allows arbitrary file access. Immediate update to v2.2.2+ is crucial.

Runtime Rebel Intel
5 min read · May 14, 2026
HIGH
Vulnerabilities

CVE-2026-46300: Fragnesia Flaw Enables Linux Root Privilege Escalation

Security researchers identify Fragnesia (CVE-2026-46300), a Linux kernel vulnerability allowing local attackers to gain root access via packet fragmentation.

Runtime Rebel Intel
3 min read · May 14, 2026
CRITICAL
Vulnerabilities

Cisco Catalyst SD-WAN Controller Authentication Bypass via CVE-2026-20182 Exploited in Zero-Day Attacks

Cisco warns of a critical authentication bypass in Catalyst SD-WAN Controller (CVE-2026-20182) actively exploited in zero-day attacks, granting admin access.

Runtime Rebel Intel
4 min read · May 14, 2026
CVE-2026-20182: Cisco SD-WAN Auth Bypass Actively Exploited
CRITICAL
Vulnerabilities

CVE-2026-20182: Cisco SD-WAN Auth Bypass Actively Exploited

Cisco Catalyst SD-WAN Controller and Manager face critical authentication bypass CVE-2026-20182, actively exploited for admin access. Patch now.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

CVE-2021-23017: NGINX DNS Resolver Buffer Overflow — Patch Now

An 18-year-old stack-based buffer overflow in the NGINX DNS resolver could lead to DoS or RCE. Learn how to secure your web server configuration today.

Runtime Rebel Intel
3 min read · May 14, 2026
MEDIUM
Vulnerabilities

Dell SupportAssist v4.0.3 Causes Windows BSOD — Remediation Guide

Dell confirms SupportAssist v4.0.3 causes frequent Windows BSOD crashes and system reboots. Learn how to identify and mitigate these stability issues now.

Runtime Rebel Intel
4 min read · May 14, 2026
PraisonAI Auth Bypass CVE-2026-44338 Exploited — Patching Guide
HIGH
Vulnerabilities

PraisonAI Auth Bypass CVE-2026-44338 Exploited — Patching Guide

Threat actors are actively exploiting CVE-2026-44338, a critical authentication bypass in the PraisonAI framework, just hours after public disclosure.

Runtime Rebel Intel
4 min read · May 14, 2026
MEDIUM
Vulnerabilities

Outlook Junk Folder Bypass: How Attackers Hide Malicious URLs

Discover how attackers bypass Microsoft Outlook's Junk folder link preview protection using HTML manipulation to hide malicious phishing URLs from users.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

Windows Zero-Days: Analyzing YellowKey and GreenPlasma Exploits

A technical breakdown of the unpatched YellowKey BitLocker bypass and GreenPlasma local privilege escalation vulnerabilities affecting Windows systems.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

CVE-2024-38812: How to Mitigate VMware Fusion Privilege Escalation

VMware Fusion 13.6 fixes a high-severity local privilege escalation flaw (CVE-2024-38812) that allows attackers to gain root access on macOS hosts.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

CVE-2026-46300: Linux Fragnesia Kernel Privilege Escalation Analysis

Critical analysis of the Fragnesia Linux kernel vulnerability (CVE-2026-46300), enabling local root access via IP fragmentation flaws. Includes mitigation steps.

Runtime Rebel Intel
4 min read · May 14, 2026
CVE-2026-42945: NGINX Rewrite Module Heap Overflow Enables RCE
HIGH
Vulnerabilities

CVE-2026-42945: NGINX Rewrite Module Heap Overflow Enables RCE

A critical 18-year-old heap buffer overflow in the NGINX rewrite module allows unauthenticated RCE. Learn how to detect and patch CVE-2026-42945.

Runtime Rebel Intel
4 min read · May 14, 2026
CVE-2026-46300: Fragnesia Linux Kernel LPE Grants Root Access
HIGH
Vulnerabilities

CVE-2026-46300: Fragnesia Linux Kernel LPE Grants Root Access

A technical analysis of CVE-2026-46300, a Linux kernel LPE vulnerability dubbed Fragnesia that enables root access via XFRM page cache corruption.

Runtime Rebel Intel
4 min read · May 14, 2026
HIGH
Vulnerabilities

Pixel 10 0-Click Exploit Chain: Re-Targeting CVE-2025-54957 for Root

Analysis of a zero-click exploit chain targeting the Google Pixel 10, achieving root via an adapted Dolby vulnerability (CVE-2025-54957). Critical threat. Patch now.

Runtime Rebel Intel
4 min read · May 13, 2026
HIGH
Vulnerabilities

Exim RCE: Unauthenticated Remote Code Execution Critical Flaw

A new critical flaw in Exim mailer allows unauthenticated remote code execution on certain configurations. Immediate patching is vital for security professionals.

Runtime Rebel Intel
4 min read · May 13, 2026
FamousSparrow APT: China-Linked Group Targets Caucasus Energy Sector
HIGH
Threat Intel

FamousSparrow APT: China-Linked Group Targets Caucasus Energy Sector

China-linked FamousSparrow APT expands targeting to include Azerbaijani energy infrastructure, signaling a shift in strategic objectives for the threat group.

Runtime Rebel Intel
3 min read · May 13, 2026
INFO
Threat Intel

Sweet Attack: Using Agentic AI for Continuous Runtime Red Teaming

Sweet Security launches Sweet Attack, using agentic AI and runtime intelligence to provide autonomous attack path analysis and identify exploitable chains.

Runtime Rebel Intel
3 min read · May 13, 2026
INFO
Vulnerabilities

Microsoft and Palo Alto Networks Use AI to Identify Dozens of Vulnerabilities

Microsoft and Palo Alto Networks leverage AI-powered tools MDASH and Mythos to identify dozens of critical software vulnerabilities before exploitation.

Runtime Rebel Intel
3 min read · May 13, 2026
HIGH
Vulnerabilities

Windows BitLocker Zero-Day Bypass and Privilege Escalation PoC Released

Security researcher releases PoC for YellowKey and GreenPlasma, unpatched vulnerabilities allowing BitLocker bypass and SYSTEM privilege escalation on Windows.

Runtime Rebel Intel
4 min read · May 13, 2026
Microsoft MDASH AI Discovers 16 Windows Vulnerabilities
HIGH
Vulnerabilities

Microsoft MDASH AI Discovers 16 Windows Vulnerabilities

Microsoft reveals MDASH, a new AI-driven agentic scanning harness that discovered 16 vulnerabilities in Windows, now fixed in recent Patch Tuesday updates.

Runtime Rebel Intel
3 min read · May 13, 2026
MEDIUM
Threat Intel

GPT-5.5 Performance in Automated Vulnerability Discovery

An analysis of GPT-5.5 and Claude Mythos capabilities in identifying security vulnerabilities based on UK AI Security Institute evaluations.

Runtime Rebel Intel
3 min read · May 13, 2026