Vulnerabilities
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.
Hi, what are you looking for?
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.
An integer overflow or wraparound in the Qualcomm graphics component, the bug leads to memory corruption.
Improper input sanitization in the framework can be exploited through the Shell tool, allowing attackers to modify system files and steal data.
Malicious extensions could hijack the Gemini Live in Chrome feature to spy on users and steal their files.
Malicious websites could open a WebSocket connection to localhost on the OpenClaw gateway port, brute force passwords, and take control of the agent.
The attacks exploited a post-authentication command injection vulnerability in the endpoint manager’s interface.
An out-of-band security update for Junos OS Evolved patches the remote code execution vulnerability CVE-2026-21902.
Anthropic has patched vulnerabilities whose impact was demonstrated by Check Point via malicious configuration files.
The issue impacts the UPnP function of multiple device models and could be exploited for remote code execution.
TrendAI has fixed eight critical and high-severity issues in Windows and macOS endpoint security products.
Already added to CISA’s KEV catalog, the flaw allows attackers to bypass authentication and gain administrative privileges.
The four security defects could be exploited for remote code execution but require administrative privileges.
Broadcom has patched several vulnerabilities in VMware Aria Operations, including high-severity flaws.
Attackers can inject malicious instructions in a GitHub Issue that are automatically processed by Copilot when launching a Codespace from that issue.
The vulnerability in TeamT5 ThreatSonar Anti-Ransomware was recently added to CISA’s KEV catalog.
Patched in December 2025, the exploited flaw leads to XSS attacks via the animate tags in SVG documents.
The flaw tracked as CVE-2026-2329 can be exploited without authentication for remote code execution with root privileges.
CISA has updated its KEV entry for CVE-2026-1731 to alert organizations of exploitation in ransomware attacks.
Security researchers have seen the vulnerabilities being exploited to deliver shells, conduct reconnaissance, and download malware.
Novee researchers discovered 16 vulnerabilities in Foxit and Apryse PDF tools that could have been exploited via malicious documents or URLs.