Vulnerabilities
CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
CVE-2026-9082 can be exploited without authentication for information disclosure, privilege escalation, and remote code execution.
The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition.
More than 200 vulnerabilities patched in recent Chrome releases are marked as ‘reported by Google’.
New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking.
The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches.
Drupal says attackers may develop an exploit for the vulnerability within hours or days.
The security defect can be exploited remotely, without authentication, to execute arbitrary code and leak sensitive information.
Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root.
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.
Four vulnerabilities in OpenClaw can be chained together to steal credentials, escape the sandbox, and plant persistent backdoors.
The researcher dropped the MiniPlasma exploit that uses the original proof-of-concept (PoC) code targeting the bug.
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.
The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.
Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.
The company’s latest quarterly advisory describes high and medium-severity issues in BIG-IP, BIG-IQ, and NGINX.