Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
Apple Patches Legacy iOS 15.8.7 and 16.7.15 Against Coruna Exploits
Apple releases critical security updates for older iPhone and iPad models to mitigate the Coruna exploit chain and kernel-level vulnerabilities.
Google VRP 2025: $17.1 Million Paid for Security Vulnerabilities
Google's Vulnerability Reward Program paid a record $17.1 million in 2025, highlighting critical security research trends in Android, Chrome, and AI systems.
Cisco IOS XR Software Vulnerabilities: CVE-2024-20320 Patch Guide
Cisco addresses high-severity vulnerabilities in IOS XR Software, including SSH privilege escalation and DoS flaws. Essential mitigation steps for network admins.
Zoom and Splunk Patch Critical RCE and PE Vulnerabilities
Security updates for Splunk Enterprise and Zoom Desktop Client address critical vulnerabilities, including a 9.6-rated RCE and high-severity privilege escalation.

Apple Patches CVE-2023-43010 WebKit Vulnerability in Older Devices
Apple backports fixes for CVE-2023-43010 in older iOS and macOS versions to defend against the Coruna exploit kit targeting WebKit memory corruption.

n8n RCE via CVE-2025-68613 — CISA Flags Active Exploitation
CISA adds CVE-2025-68613 to its KEV catalog after reports of active exploitation against n8n workflow automation instances. Patch now to prevent RCE.
IoT Default Credentials: Preventing Unauthorized Admin Access
The SANS ISC highlights the persistent threat of IoT devices compromised by default admin credentials. Learn critical steps to secure your smart devices.
CVE-2024-21410: Protect Microsoft Exchange from NTLM Relay Attacks
Deep dive into CVE-2024-21410, a critical privilege escalation vulnerability in Microsoft Exchange. Learn how to detect exploits and implement EPA mitigations.
CVE-2025-68613: n8n Improper Code Control — Actively Exploited
CISA adds CVE-2025-68613, an n8n vulnerability involving improper control of dynamically-managed code, to its KEV Catalog due to active exploitation. Immediate patching
Elementor Ally Plugin SQLi: Unauthenticated Data Theft Risk
An unauthenticated SQL injection vulnerability in the Elementor Ally WordPress plugin affects over 400,000 sites, risking sensitive data exposure.

n8n RCE Vulnerabilities CVE-2026-27577 and CVE-2026-27493 - Patch Now
Critical vulnerabilities in the n8n workflow automation platform allow unauthenticated remote code execution and sandbox escapes. Update instances immediately.
CVE-2026-0866: Mitigating Zombie Zip File Evasion Techniques
Technical analysis of CVE-2026-0866 'Zombie Zip' exploitation. Learn how archive header discrepancies bypass security scanners and how to defend your perimeter.