Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

CRITICAL
Vulnerabilities

CVE-2024-38094: 1,300+ SharePoint Servers At Risk of RCE

Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2024-38094, a critical RCE vulnerability actively exploited by threat actors.

Runtime Rebel Intel
3 min read · Apr 22, 2026
HIGH
Vulnerabilities

CVE-2023-38171: ASP.NET Core Privilege Escalation — Mitigation Guide

Microsoft issues emergency OOB security updates for a critical ASP.NET Core privilege escalation flaw. Learn how to patch affected systems now.

Runtime Rebel Intel
3 min read · Apr 22, 2026
CVE-2026-5752: Root RCE and Sandbox Escape in Cohere AI Terrarium
HIGH
Vulnerabilities

CVE-2026-5752: Root RCE and Sandbox Escape in Cohere AI Terrarium

CVE-2026-5752 is a critical CVSS 9.3 flaw in Cohere AI's Terrarium sandbox allowing root-level code execution and container escape via prototype traversal.

Runtime Rebel Intel
3 min read · Apr 22, 2026
Google Antigravity RCE via Prompt Injection — Mitigation Guide
HIGH
Vulnerabilities

Google Antigravity RCE via Prompt Injection — Mitigation Guide

Google patched a critical RCE flaw in its AI-based Antigravity tool, stemming from a prompt injection vulnerability allowing sandbox escape and arbitrary code execution.

Runtime Rebel Intel
4 min read · Apr 21, 2026
BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters
HIGH
Vulnerabilities

BRIDGE:BREAK: 22 Flaws in Lantronix and Silex Serial Converters

Forescout researchers uncover 22 BRIDGE:BREAK vulnerabilities in Lantronix and Silex serial-to-IP converters, risking device hijacking and data tampering.

Runtime Rebel Intel
4 min read · Apr 21, 2026
CRITICAL
Vulnerabilities

CISA KEV Expansion: Exploit Guidance for Cisco, Kentico, and Zimbra

CISA adds 8 vulnerabilities to the KEV catalog, including critical flaws in Cisco ASA and Zimbra. Analyze technical impact and remediation requirements.

Runtime Rebel Intel
4 min read · Apr 21, 2026
HIGH
Vulnerabilities

Progress MOVEit and LoadMaster Patched Against Critical RCE and Bypass

Progress Software releases critical patches for MOVEit Transfer and LoadMaster addressing RCE and authentication bypass vulnerabilities like CVE-2024-5806.

Runtime Rebel Intel
4 min read · Apr 21, 2026
CRITICAL
Vulnerabilities

CVE-2023-46604: Apache ActiveMQ RCE Exploited by HelloKitty - Patch Now

Over 6,400 Apache ActiveMQ servers are exposed to RCE via CVE-2023-46604. Threat actors like HelloKitty are actively exploiting this high-severity flaw.

Runtime Rebel Intel
4 min read · Apr 21, 2026
CRITICAL
Vulnerabilities

CISA KEV Update: Eight New Vulnerabilities in Cisco, TeamCity, and Zimbra

CISA adds eight vulnerabilities to the KEV Catalog, including flaws in Cisco SD-WAN and JetBrains TeamCity, requiring immediate federal agency remediation.

Runtime Rebel Intel
3 min read · Apr 21, 2026
CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild
HIGH
Vulnerabilities

CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild

CISA adds 8 vulnerabilities to its KEV catalog, including PaperCut and Cisco SD-WAN Manager flaws, with federal patching deadlines set for May 2026.

Runtime Rebel Intel
3 min read · Apr 21, 2026
Securing Serial-to-IP Devices: Mitigating Thousands of OT Bugs
HIGH
Vulnerabilities

Securing Serial-to-IP Devices: Mitigating Thousands of OT Bugs

Industrial serial-to-IP converters are riddled with thousands of vulnerabilities, posing a significant risk to legacy infrastructure and OT environments.

Runtime Rebel Intel
4 min read · Apr 20, 2026
CVE-2026-5760: SGLang RCE via Malicious GGUF Models - Patch Now
HIGH
Vulnerabilities

CVE-2026-5760: SGLang RCE via Malicious GGUF Models - Patch Now

Critical CVE-2026-5760 command injection in SGLang allows remote code execution via GGUF files. High-performance LLM serving environments are at risk.

Runtime Rebel Intel
3 min read · Apr 20, 2026
INFO
Vulnerabilities

Prioritizing Vulnerabilities with EPSS: Managing the CVE Flood

Learn how the Exploit Prediction Scoring System (EPSS) provides a data-driven approach to prioritize vulnerability remediation amid rising CVE volumes.

Runtime Rebel Intel
4 min read · Apr 20, 2026
HIGH
Vulnerabilities

TP-Link Archer AX21 RCE via CVE-2023-1389 — Mitigation Guide

Hackers continue targeting discontinued TP-Link Archer AX21 routers with CVE-2023-1389, though many exploitation attempts currently fail to execute payloads.

Runtime Rebel Intel
4 min read · Apr 20, 2026
MEDIUM
Vulnerabilities

Microsoft Releases OOB Updates to Fix Windows Server Boot Issues

Microsoft issues emergency out-of-band updates to resolve critical authentication failures and boot loops caused by the April 2026 security patches.

Runtime Rebel Intel
4 min read · Apr 20, 2026
HIGH
Vulnerabilities

Android Dirty Stream Path Traversal: Detecting and Patching App Exploits

Microsoft identifies Dirty Stream vulnerabilities in Android apps, allowing path traversal and unauthorized file manipulation. Learn how to secure your apps.

Runtime Rebel Intel
4 min read · Apr 20, 2026
INFO
Vulnerabilities

NIST to Prioritize High-Impact CVEs Amid NVD Enrichment Backlog

NIST adjusts National Vulnerability Database operations to focus on significant flaws, leaving lower-priority vulnerabilities without official metadata.

Runtime Rebel Intel
3 min read · Apr 19, 2026
LOW
Vulnerabilities

Edge Update Breaks Microsoft Teams Right-Click Paste Functionality

A recent Microsoft Edge browser update has disabled the right-click paste feature in the Microsoft Teams desktop client, impacting global user productivity.

Runtime Rebel Intel
3 min read · Apr 18, 2026
HIGH
Vulnerabilities

protobuf.js RCE via CVE-2023-32731 — Mitigation Guide

Technical breakdown of CVE-2023-32731, a critical prototype pollution vulnerability in protobuf.js that enables remote code execution in JavaScript environments.

Runtime Rebel Intel
4 min read · Apr 18, 2026
Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet
HIGH
Threat Intel

Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet

Security researchers identify Nexcorium, a new Mirai variant targeting TBK DVRs and EoL TP-Link routers via CVE-2024-3721 for large-scale DDoS attacks.

Runtime Rebel Intel
4 min read · Apr 18, 2026
NIST NVD Data Enrichment Cutbacks: Implications for Cyber Teams
INFO
Threat Intel

NIST NVD Data Enrichment Cutbacks: Implications for Cyber Teams

NIST's reduction in NVD CVE data enrichment poses challenges for cyber teams' vulnerability management. Learn the implications and proposed industry solutions.

Runtime Rebel Intel
5 min read · Apr 18, 2026
Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited
CRITICAL
Vulnerabilities

Microsoft Defender Zero-Days BlueHammer and RedSun Actively Exploited

Huntress warns of active exploitation of three Microsoft Defender vulnerabilities, including BlueHammer and RedSun, allowing for privilege escalation.

Runtime Rebel Intel
4 min read · Apr 17, 2026
INFO
Threat Intel

Claude Mythos Preview: Anthropic Limits Access to Vulnerability AI

Anthropic restricts Claude Mythos Preview access to critical infrastructure providers due to its advanced capability to exploit zero-day vulnerabilities.

Runtime Rebel Intel
3 min read · Apr 17, 2026
CRITICAL
Vulnerabilities

CVE-2023-46604: Apache ActiveMQ RCE Exploited in the Wild

CISA warns of active exploitation for CVE-2023-46604, a critical RCE flaw in Apache ActiveMQ used by ransomware groups. Update to version 5.18.3 or later.

Runtime Rebel Intel
3 min read · Apr 17, 2026