Coverage
Vulnerabilities
903 articles on vulnerability disclosures and exploits
Advertisement
CVE-2026-3094: Delta CNCSoft-G2 Out-of-bounds Write RCE
Delta Electronics CNCSoft-G2 is vulnerable to an out-of-bounds write (CVE-2026-3094) allowing remote code execution. Update to V2.1.0.39.
WordPress User Registration & Membership Plugin: Admin Account Exploit
Critical vulnerability in WordPress User Registration & Membership plugin actively exploited to create unauthorized admin accounts. Immediate update or removal is

CVE-2026-20122: Cisco Catalyst SD-WAN Manager Exploited in the Wild
Cisco confirms active exploitation of CVE-2026-20122 in Catalyst SD-WAN Manager, allowing authenticated attackers to perform arbitrary file overwrites.
2025 Zero-Day Exploitation Review: Enterprise & OS Targets Dominate
GTIG's 2025 zero-day review reveals 90 in-the-wild exploits, with a record 48% targeting enterprise tech and a surge in OS vulnerabilities. Includes actor TTPs.
Google Forecasts 90 Enterprise Zero-Day Exploits in 2025
Google predicts half of the 90 exploited zero-day vulnerabilities in 2025 will target enterprises. Understand attribution and proactive defense strategies.
Google Reports 90 Zero-Day Exploits in 2025: Enterprise Focus
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited throughout 2025, with nearly half targeting enterprise software and appliances.
Microsoft Outlook CVE-2025-21418: Mitigating NTLM Relay Attacks
Analysis of CVE-2025-21418 in Microsoft Outlook. Learn how attackers bypass security features to leak NTLM hashes and the steps needed for mitigation.
Reclaim Security Secures $20M to Automate Vulnerability Remediation
Reclaim Security raises $20 million to solve the remediation gap, focusing on automating fixes and reducing mean time to remediate for enterprise SOC teams.
Cisco Catalyst SD-WAN Manager Exploitation: Patch CVE-2024-20437 Now
Cisco confirms active exploitation of two high-severity flaws in Catalyst SD-WAN Manager, involving hardcoded credentials and authentication bypass.
Cisco Catalyst SD-WAN Manager CVE-2023-20252 — Mitigation Guide
Cisco warns of active exploitation targeting Catalyst SD-WAN Manager vulnerabilities CVE-2023-20252 and CVE-2023-20253. Immediate patching is required.

VMware Aria Operations Command Injection Exploitation: Cloud Risk
A critical command injection vulnerability in VMware Aria Operations is actively exploited, granting attackers broad access to cloud environments. Immediate patching is
Mail2Shell Zero-Click RCE Threatens FreeScout Servers
A critical Mail2Shell zero-click vulnerability in FreeScout helpdesk allows unauthenticated remote code execution, granting full server control. Immediate patching is