Network Security
Successful exploitation of the flaws could lead to code execution, server-side request forgery attacks, and denial-of-service conditions.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
Successful exploitation of the flaws could lead to code execution, server-side request forgery attacks, and denial-of-service conditions.
Attackers could inject prompts into a GitHub issue and take over the AI agent designed to automatically triage the issue.
Containing fixes for critical-severity vulnerabilities, the monthly rollouts will focus on addressing priority issues faster.
CVE-2026-0300 affects the Captive Portal service of PAN-OS software on PA and VM series firewalls.
Dubbed Bleeding Llama, the heap out-of-bounds read issue can be exploited remotely, without authentication.
CVE-2026-0073 affects Android’s System component and it can be exploited without any user interaction.
The most severe of these security defects could allow remote attackers to execute arbitrary code.
The security defects allow unauthenticated, remote attackers to execute arbitrary code through crafted requests.
The vulnerabilities were reported to Meta through its bug bounty program and were patched with updates released earlier this year.
CISA has added the bug to its KEV list, and Microsoft has observed limited exploitation, mainly associated with PoC testing.
The attacks likely target CVE-2026-41940, a recently patched zero-day leading to administrative access.
The maximum reward for a zero-click Pixel Titan M exploit with persistence has increased to $1.5 million.
The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls.
The authentication bypass flaw allows attackers to gain administrative access to vulnerable servers.
Affecting the kernel’s authencesn cryptographic template, the vulnerability was introduced in 2017 and impacts all distributions.
Some of the vulnerabilities discovered by Aisle can be exploited to access and alter sensitive patient information.
The browser refreshes resolve critical and high-severity vulnerabilities that could lead to arbitrary code execution.
The remote code execution flaw CVE-2026-3854 was found to impact GitHub.com and GitHub Enterprise Server.
A fake RPC server can be used to listen for RPC requests and impersonate the target service to elevate privileges to System.
The initial vulnerability was exploited by Russia-linked APT28 in attacks against Ukraine and EU countries.