Vulnerabilities
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.
Hi, what are you looking for?
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations.
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations.
Noteworthy stories that might have slipped under the radar: Siemens ROX II industrial switch vulnerabilities, Russian Zimbra webmail espionage campaign, Stadler Rail ransomware extortion...
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you...
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts.
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues.
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
Many of the vulnerabilities fixed with the July 2026 Critical Patch Update were likely discovered by AI.
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects.
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations.
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities.
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.