Skip to main content

Coverage

Vulnerabilities

1245 articles on vulnerability disclosures and exploits

Advertisement

MEDIUM
Vulnerabilities

OpenLDAP and lldpd Vulnerabilities: Analyzing DoS Risks

Detailed analysis of CVE-2025-25164 in OpenLDAP and CVE-2025-25330 in lldpd, focusing on NULL pointer dereference and memory leak impacts on infrastructure.

Runtime Rebel Intel
4 min read · Feb 27, 2026
Cisco SD-WAN Zero-Day Under Exploitation for 3 Years
CRITICAL
Vulnerabilities

Cisco SD-WAN Zero-Day Under Exploitation for 3 Years

A critical zero-day vulnerability, CVE-2026-20127, in Cisco SD-WAN has been actively exploited by a sophisticated threat actor for three years.

Runtime Rebel Intel
4 min read · Feb 27, 2026
HIGH
Vulnerabilities

GetProcessHandleFromHwnd API: UAC Bypass Implications

Investigate the GetProcessHandleFromHwnd API's role in a Quick Assist UAC bypass. Understand its mechanism, UIAccess implications, and defender recommendations.

Runtime Rebel Intel
4 min read · Feb 26, 2026
MEDIUM
Vulnerabilities

Multiple DoS/RCE Vulnerabilities in Yokogawa CENTUM VP R6, R7

CISA alerts to multiple medium-severity vulnerabilities in Yokogawa CENTUM VP R6 and R7, allowing DoS and RCE via crafted packets in critical infrastructure…

Runtime Rebel Intel
5 min read · Feb 26, 2026
HIGH
Vulnerabilities

Critical Authentication Flaws in Chargemap EV Infrastructure

CISA warns of critical vulnerabilities in Chargemap EV charging stations, including unauthenticated WebSocket access and session hijacking (CVE-2026-25851).

Runtime Rebel Intel
3 min read · Feb 26, 2026
CRITICAL
Vulnerabilities

Trend Micro Patches Critical RCE Flaws in Apex One Security Platform

Trend Micro addresses two critical vulnerabilities, CVE-2023-32524 and CVE-2023-32525, in its Apex One platform that allow for remote code execution.

Runtime Rebel Intel
4 min read · Feb 26, 2026
HIGH
Vulnerabilities

Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking

Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.

Runtime Rebel Intel
4 min read · Feb 26, 2026
Threat Intelligence Analysis: Kali Linux AI Integration and Browser Crash Traps
HIGH
Threat Intel

Threat Intelligence Analysis: Kali Linux AI Integration and Browser Crash Traps

Analysis of Kali Linux Claude AI integration, Chrome browser crash traps, and the ongoing exploitation of WinRAR vulnerabilities by LockBit affiliates.

Runtime Rebel Intel
4 min read · Feb 26, 2026
HIGH
Threat Intel

US Sanctions Russian Exploit Broker Operation Zero

US Treasury sanctions Russian exploit broker Operation Zero and its owner Sergey Zaytsev for facilitating zero-day trades with Russian intelligence agencies.

Runtime Rebel Intel
4 min read · Feb 26, 2026
HIGH
Vulnerabilities

Zyxel Fixes Critical RCE Vulnerability in UPnP Implementation

Zyxel releases patches for CVE-2024-42057, a command injection flaw in the UPnP function of several VMG and fiber router models, allowing unauthenticated RCE.

Runtime Rebel Intel
3 min read · Feb 26, 2026
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access
CRITICAL
Vulnerabilities

Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access

CVE-2026-20127 is a critical CVSS 10.0 flaw in Cisco SD-WAN controllers exploited since 2023, allowing unauthenticated remote administrative access.

Runtime Rebel Intel
4 min read · Feb 26, 2026
CRITICAL
Threat Intel

Cisco SD-WAN Exploitation: Critical Authentication Bypass & Escalation

CISA alerts on active global exploitation of Cisco SD-WAN, leveraging CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Vulnerabilities

CISA Adds Two Cisco SD-WAN Exploits to KEV Catalog

CISA adds CVE-2022-20775 (Path Traversal) and CVE-2026-20127 (Auth Bypass) affecting Cisco SD-WAN to its Known Exploited Vulnerabilities Catalog.

Runtime Rebel Intel
4 min read · Feb 25, 2026
CRITICAL
Vulnerabilities

Critical Cisco SD-WAN Zero-Day Exploited Since 2023

Cisco Catalyst SD-WAN critical authentication bypass (CVE-2026-20127) actively exploited since 2023, enabling remote compromise and rogue peer addition.

Runtime Rebel Intel
4 min read · Feb 25, 2026
Claude Code Flaws Enable RCE & API Key Exfiltration
HIGH
Vulnerabilities

Claude Code Flaws Enable RCE & API Key Exfiltration

Multiple security flaws in Anthropic's Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.

Runtime Rebel Intel
5 min read · Feb 25, 2026
HIGH
Threat Intel

Ex-L3Harris Executive Sentenced for Selling Zero-Days to Russia

Former Trenchant CEO James Michael Robinson sentenced to 90 months for stealing zero-day exploits and selling them to a Russian state-linked broker.

Runtime Rebel Intel
4 min read · Feb 25, 2026
INFO
Threat Intel

US Treasury Sanctions Russian Broker for Stolen Zero-Day Exploits

The US sanctions Artem Kruglov and associated firms for brokering stolen hacking tools and zero-day exploits for Russian intelligence services.

Runtime Rebel Intel
4 min read · Feb 25, 2026
L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker
HIGH
Threat Intel

L3Harris Insider Sentenced for Selling Zero-Days to Russian Broker

Former defense contractor Peter Williams sentenced to seven years for selling eight zero-day exploits to Russian broker Operation Zero for millions in profit.

Runtime Rebel Intel
4 min read · Feb 25, 2026
CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog
HIGH
Vulnerabilities

CISA Adds FileZen CVE-2026-25108 Command Injection to KEV Catalog

CISA confirms active exploitation of FileZen CVE-2026-25108, an OS command injection flaw. Organizations must patch immediately to prevent command execution.

Runtime Rebel Intel
4 min read · Feb 25, 2026
SolarWinds Patches Four Critical RCE Flaws in Serv-U File Transfer
HIGH
Vulnerabilities

SolarWinds Patches Four Critical RCE Flaws in Serv-U File Transfer

SolarWinds addresses four critical vulnerabilities (CVSS 9.1) in Serv-U 15.5, including CVE-2025-40538, which allows unauthorized root code execution.

Runtime Rebel Intel
4 min read · Feb 25, 2026
January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
CRITICAL
Vulnerabilities

January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws

Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.

Runtime Rebel Intel
5 min read · Feb 25, 2026
HIGH
Vulnerabilities

macOS coreaudiod Type Confusion Exploitation: CVE-2024-54529

Analysis of CVE-2024-54529, a critical type confusion vulnerability in macOS coreaudiod, detailing its exploitation and necessary mitigations.

Runtime Rebel Intel
4 min read · Feb 25, 2026
HIGH
Vulnerabilities

Windows Administrator Protection Bypassed via UI Access Abuse

Analysis of UI Access abuse techniques that bypassed Windows Administrator Protection, a new UAC feature, detailing historical context and fixes.

Runtime Rebel Intel
4 min read · Feb 25, 2026
MEDIUM
Vulnerabilities

Open Redirects: Overlooked Vulnerability Impact & Analysis

An analysis of open redirect vulnerabilities, their historical context in OWASP, common exploitation vectors like phishing, and essential mitigation strategies.

Runtime Rebel Intel
4 min read · Feb 25, 2026