Vulnerabilities
The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation.
Apple released security fixes for older devices as well, in iOS 18.7.7, iPadOS 18.7.7, macOS Sequoia 15.7.5, and macOS Sonoma 14.8.5.
The software refresh fixes eight memory safety bugs affecting seven Chrome components.
An out-of-bounds read vulnerability can be exploited remotely without authentication to read sensitive information from memory.
The flaws could allow attackers to access sensitive information, execute code, or cause unexpected behavior.
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.
Insufficient sanitization of CSS content within HTML emails leads to inline script execution when the message is opened in a browser.
The SharePoint remote code execution vulnerability CVE-2026-20963, which Microsoft patched in January, has been exploited in the wild.
Amazon found evidence that the FMC software vulnerability has been exploited since late January, and found links to Russia.
With exploitation of vulnerabilities taking just days, preemptive security must be the new model for defenders.
Targeting six iOS vulnerabilities and leading to full device compromise, the exploit chain is meant for surveillance.
Meta does not plan on fixing the vulnerability because it involves the use of a modified client application.
Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application.
The vulnerability can be exploited remotely, without authentication, to circumvent existing authentication controls.
Google paid over $3.7 million for Chrome vulnerabilities, and more than $3.5 million for cloud security defects.
The flaws can be exploited to manipulate data and bypass security restrictions, potentially leading to code execution.
The issue allows attackers to inject SQL queries and extract sensitive information from the database.