Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

Citrix NetScaler CVE-2026-3055: Critical Data Leak Patch Guidance
CRITICAL
Vulnerabilities

Citrix NetScaler CVE-2026-3055: Critical Data Leak Patch Guidance

Citrix releases critical security updates for NetScaler ADC and Gateway to address CVE-2026-3055, an unauthenticated memory overread and data leak flaw.

Runtime Rebel Intel
3 min read · Mar 24, 2026
HIGH
Vulnerabilities

CVE-2024-3400: Exploiting Palo Alto Networks PAN-OS — Patch Now

Technical analysis of CVE-2024-3400, a critical command injection vulnerability in PAN-OS firewalls. Learn exploit mechanics, detection, and mitigation steps.

Runtime Rebel Intel
3 min read · Mar 24, 2026
HIGH
Threat Intel

M-Trends 2026: Evolving Ransomware, Persistence, and SaaS Attack Vectors

M-Trends 2026 reveals critical shifts in adversary TTPs: destructive ransomware, zero-day exploitation for persistence, and voice phishing for SaaS access.

Runtime Rebel Intel
5 min read · Mar 23, 2026
AWS Bedrock AI Agent Security: Analysis of Eight Attack Vectors
HIGH
Cloud Security

AWS Bedrock AI Agent Security: Analysis of Eight Attack Vectors

Research identifies eight critical attack vectors in AWS Bedrock, focusing on risks to integrated enterprise data and automated Lambda function execution.

Runtime Rebel Intel
4 min read · Mar 23, 2026
MEDIUM
Vulnerabilities

Microsoft Xbox One Hardware Security Defeated via Bliss Exploit

Security researchers have bypassed Microsoft Xbox One hardware security using the Bliss voltage glitching exploit, enabling unsigned code execution.

Runtime Rebel Intel
3 min read · Mar 23, 2026
HIGH
Vulnerabilities

QNAP Patches Four Pwn2Own Vulnerabilities in QTS and QuTS hero

QNAP releases security updates for four vulnerabilities, including CVE-2024-50387 and CVE-2024-50388, exploited during the Pwn2Own Ireland 2024 competition.

Runtime Rebel Intel
3 min read · Mar 23, 2026
CRITICAL
Vulnerabilities

CVE-2021-35587: Critical RCE in Oracle Identity Manager Patched

Oracle issues emergency patches for CVE-2021-35587, a critical RCE flaw in Identity Manager with a 9.8 CVSS score. Immediate mitigation is required.

Runtime Rebel Intel
3 min read · Mar 23, 2026
Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance
CRITICAL
Vulnerabilities

Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance

Threat actors are exploiting a critical CVSS 10.0 vulnerability, CVE-2025-32975, in Quest KACE Systems Management Appliances exposed to the internet.

Runtime Rebel Intel
3 min read · Mar 23, 2026
HIGH
Vulnerabilities

PHP 8.1 End-of-Life: Security Risks and Upgrade Path Analysis

PHP 8.1 has reached its end-of-life status. Learn about the security implications of running unsupported software and the technical steps for remediation.

Runtime Rebel Intel
4 min read · Mar 23, 2026
CRITICAL
Vulnerabilities

Quest KACE SMA CVE-2025-32975: Potential Exploitation in Education

Quest KACE Systems Management Appliance (SMA) faces potential active exploitation via CVE-2025-32975, primarily targeting the education sector. Patch now.

Runtime Rebel Intel
4 min read · Mar 21, 2026
Oracle Fusion Middleware RCE Flaw: Immediate Patch Required
HIGH
Vulnerabilities

Oracle Fusion Middleware RCE Flaw: Immediate Patch Required

A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware's Identity and Web Services Managers demands immediate patching.

Runtime Rebel Intel
4 min read · Mar 20, 2026
HIGH
Vulnerabilities

Oracle Identity Manager RCE via CVE-2026-21992 — Patch Now

Oracle issued an emergency patch for CVE-2026-21992, a critical unauthenticated RCE flaw in Identity Manager and Web Services Manager. Immediate patching is required.

Runtime Rebel Intel
4 min read · Mar 20, 2026
CRITICAL
Vulnerabilities

CVE-2026-20131: Cisco FMC/SCC Deserialization Vulnerability Under Active Attack

CISA adds CVE-2026-20131, a critical deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC), to KEV Catalog due…

Runtime Rebel Intel
4 min read · Mar 20, 2026
CRITICAL
Vulnerabilities

CISA Adds 5 KEVs: Apple Buffer Overflow, Code Injections Exploited

CISA's KEV Catalog updated with 5 actively exploited vulnerabilities impacting Apple products, Craft CMS, and Laravel Livewire. Immediate patching is critical.

Runtime Rebel Intel
5 min read · Mar 20, 2026
Interlock Ransomware Targets Cisco Firewalls via CVE-2024-20481
HIGH
Threat Intel

Interlock Ransomware Targets Cisco Firewalls via CVE-2024-20481

Interlock ransomware operators exploited a critical Cisco ASA vulnerability before public disclosure. Learn how to detect and mitigate these targeted attacks.

Runtime Rebel Intel
4 min read · Mar 20, 2026
MEDIUM
Threat Intel

Android Security Safeguards and UK Cyber Reporting Mandates

Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.

Runtime Rebel Intel
3 min read · Mar 20, 2026
CRITICAL
Vulnerabilities

CVE-2024-20481: Critical Cisco FMC RCE Exploited in the Wild

CISA mandates federal agencies patch CVE-2024-20481, a 9.8 CVSS RCE vulnerability in Cisco Secure Firewall Management Center, following active exploitation.

Runtime Rebel Intel
3 min read · Mar 20, 2026
CVE-2026-33017: Critical Langflow RCE Exploited within 20 Hours
CRITICAL
Vulnerabilities

CVE-2026-33017: Critical Langflow RCE Exploited within 20 Hours

CVE-2026-33017 is a critical RCE vulnerability in Langflow currently under active exploitation. Learn how to secure your AI orchestration and detect attacks.

Runtime Rebel Intel
3 min read · Mar 20, 2026
MEDIUM
Vulnerabilities

KB5079473 Update Breaks Microsoft Account Sign-ins on Windows 11

Microsoft confirms the KB5079473 March update for Windows 11 disrupts sign-ins for Teams and OneDrive. Technical analysis and remediation for affected systems.

Runtime Rebel Intel
4 min read · Mar 20, 2026
Apple Warns of Coruna and DarkSword Exploit Kits Targeting iOS
HIGH
Threat Intel

Apple Warns of Coruna and DarkSword Exploit Kits Targeting iOS

Apple warns of Coruna and DarkSword exploit kits targeting older iOS versions via malicious web content to steal sensitive data. Update your devices now.

Runtime Rebel Intel
4 min read · Mar 20, 2026
MEDIUM
Vulnerabilities

CVE-2025-13901: Modicon M241, M251, M262 DoS Vulnerability Patch

An unauthenticated DoS vulnerability (CVE-2025-13901) impacts Schneider Electric Modicon M241, M251, M262 controllers. Patch now to prevent ICS disruption.

Runtime Rebel Intel
4 min read · Mar 19, 2026
CRITICAL
Vulnerabilities

Magento PolyShell Vulnerability: Unauthenticated RCE Exposure

A critical flaw dubbed PolyShell affects Magento Open Source and Adobe Commerce 2.x, enabling unauthenticated remote code execution and site takeover.

Runtime Rebel Intel
4 min read · Mar 19, 2026
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
HIGH
Malware

54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers

Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.

Runtime Rebel Intel
3 min read · Mar 19, 2026
MEDIUM
Vulnerabilities

CVE-2025-13902: Patching Schneider Electric Modicon Controllers

Schneider Electric Modicon M241 and M251 controllers face XSS risks via CVE-2025-13902. Learn how to patch firmware and secure industrial control networks.

Runtime Rebel Intel
3 min read · Mar 19, 2026