Vulnerabilities
The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls.
Hi, what are you looking for?
The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls.
Google paid over $3.7 million for Chrome vulnerabilities, and more than $3.5 million for cloud security defects.
The flaws can be exploited to manipulate data and bypass security restrictions, potentially leading to code execution.
The issue allows attackers to inject SQL queries and extract sensitive information from the database.
Critical- and high-severity flaws could be exploited to execute arbitrary shell commands or elevate privileges.
The security defects could lead to denial-of-service (DoS) conditions, command execution, or device takeover.
The bugs allowed unauthenticated attackers to execute arbitrary code, steal credentials, and take over servers.
The bugs could lead to arbitrary code execution, privilege escalation, or authentication rate-limit bypass.
Microsoft has fixed a critical vulnerability, but none of the flaws fixed this Patch Tuesday has been exploited in the wild.
Adobe has rolled out patches for 80 vulnerabilities across 8 products, including Commerce, Illustrator, Acrobat Reader, and Premiere Pro.
A code injection bug in FS-QUO and an insecure deserialization flaw in NetWeaver could lead to arbitrary code execution.
CISA has added the high-severity authentication bypass vulnerability to its KEV list, along with SolarWinds and Workspace One bugs.
WatchTowr reports seeing exploitation attempts for CVE-2026-20127 from numerous unique IP addresses.
The nation-state-grade iOS exploit kit targets 23 vulnerabilities affecting iOS 13 to 17.2.1.
The vulnerability was disclosed and mitigated in 2021 but its in-the-wild exploitation has only now come to light.
Less than half of the total zero-days have been attributed to a threat actor, but spyware vendors and China are in the lead.
The networking giant has added the recently patched CVE-2026-20128 and CVE-2026-20122 to the list of exploited vulnerabilities.
Cisco has rolled out patches for 48 vulnerabilities in Firewall ASA, Secure FMC, and Secure FTD products.
A patch bypass for an authenticated code execution bug, the flaw leads to zero-click remote code execution attacks.
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.