Coverage
Vulnerabilities
1245 articles on vulnerability disclosures and exploits
Advertisement
CVE-2026-34197: Apache ActiveMQ Exploit Added to CISA KEV Catalog
CISA alerts organizations to the active exploitation of CVE-2026-34197 in Apache ActiveMQ. Federal agencies must patch this input validation flaw immediately.
Cursor AI RCE via Indirect Prompt Injection — Mitigation Guide
Security researchers demonstrate how indirect prompt injection in Cursor AI could lead to full shell access on developer workstations. Patch immediately.
Windows Server Domain Controllers Hit by LSASS Reboot Loops
Microsoft confirms LSASS crashes causing persistent reboot loops on Windows Server Domain Controllers following the April 2024 security update cycle.
NIST Limits NVD Enrichment Amid 263% Surge in CVE Submissions
NIST scales back enrichment of the National Vulnerability Database (NVD) due to a 263% volume increase, impacting vulnerability management workflows.
CVE-2026-5387: AVEVA Pipeline Simulation Privilege Escalation
Unauthenticated attackers can exploit CVE-2026-5387 in AVEVA Pipeline Simulation <=2025_SP1_build_7.1.9497.6351 to modify critical ICS simulation parameters and training…
Apache ActiveMQ CVE-2026-34197: CISA KEV Update & Mitigation
CISA adds high-severity CVE-2026-34197 in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog. Learn how to secure your message broker infrastructure.
Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware
Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.
Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation
Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.
AI-Powered Exploitation: Scaling Enterprise Defense at Machine Speed
As AI models accelerate vulnerability discovery and exploit development, enterprises must transition to automated security operations to mitigate growing risks.
CVE-2024-36985: Splunk Enterprise RCE via File Upload - Patch Guide
Splunk patches a high-severity RCE vulnerability (CVE-2024-36985) allowing low-privileged users to execute code on Windows-based Enterprise instances.
Cisco Webex Services CVE-2024-20419: Manual Patch Guidance
Cisco identifies a critical improper certificate validation flaw in Webex Services. This advisory details the required manual remediation steps for admins.
Cisco Patches Critical RCE and SSO Flaws in ISE and Webex Services
Cisco releases patches for four critical vulnerabilities, including CVE-2026-20184, which allows RCE and user impersonation in Identity Services and Webex.
Claude Code and Gemini CLI: Prompt Injection via Code Comments
Research reveals how Claude Code, Gemini CLI, and GitHub Copilot agents are vulnerable to prompt injection attacks via malicious source code comments.
Windows Server 2025 KB5082063 Update Fails to Install — Analysis
Microsoft is investigating reports of KB5082063 failing to install on Windows Server 2025, leaving systems potentially vulnerable to unpatched threats.
NGINX-UI Critical Flaw: Attackers Can Alter NGINX Configs
A critical flaw in nginx-ui allows attackers to remotely restart, create, modify, and delete NGINX configuration files, posing significant risk to web servers.
CVE-2024-57353: Nginx UI Auth Bypass Actively Exploited — Patch Now
Attackers are exploiting CVE-2024-57353, a critical authentication bypass in Nginx UI, to achieve full server takeover. Update to v2.0.0.beta.39 immediately.
Nginx UI CVE-2026-33032: Critical RCE Exploited in the Wild
Exploitation of CVE-2026-33032 in the Nginx UI management tool allows for remote takeover. Learn how to detect and mitigate this critical security threat.
CVE-2022-21882: CISA Warns of Windows Task Host Exploit in the Wild
CISA adds CVE-2022-21882 to the KEV catalog. Learn how to mitigate this Windows Task Host privilege escalation vulnerability affecting Win32k.sys.
Microsoft Awards $2.3M for Cloud and AI Vulnerabilities at Zero Day Quest
Microsoft pays $2.3 million for nearly 700 vulnerability submissions targeting Azure, Microsoft 365, and AI services during the Zero Day Quest event.
SAP CVE-2026-27681: Critical SQL Injection Vulnerability Patch Guidance
April Patch Tuesday addresses a critical 9.9 CVSS SQL injection vulnerability in SAP Business Warehouse and updates for Microsoft, Adobe, and Fortinet.
CVE-2026-33032: Critical nginx-ui Authentication Bypass Under Attack
Threat actors are exploiting CVE-2026-33032, a critical authentication bypass in nginx-ui (MCPwn), allowing full server takeover and Nginx configuration control.
Ivanti Neurons for ITSM Patches CVE-2024-45504 and CVE-2024-45505
Ivanti addresses two high-severity flaws in Neurons for ITSM, CVE-2024-45504 and CVE-2024-45505, preventing session persistence and cross-user data exposure.
Windows Update Triggers BitLocker Recovery: Mitigation and Analysis
Microsoft confirms April security updates cause unexpected BitLocker recovery prompts on Windows Servers. Learn how to resolve the boot issues and recover keys.
SharePoint Zero-Day Fixed in Microsoft April 2026 Security Updates
Microsoft addresses 169 vulnerabilities, including an actively exploited SharePoint zero-day. Learn how to secure your environment against these flaws.