Network Security
Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.
Hi, what are you looking for?
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.
The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs.
Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation.
Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks.
The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.
Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.
The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources.
The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode.
The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14.
Claroty researchers have analyzed the security of Vertiv UPS network cards and the Trane Tracer SC+ HVAC controller.
Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.
The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7.
Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution.
In addition, Rockwell Automation announced some enhancements to its SecureOT cybersecurity solution for OT.
Organizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices.
Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.
Nearly half of the security holes, most allowing arbitrary code execution, have been fixed in Adobe’s Experience Manager product.
A total of 18 vulnerabilities have been patched in the latest OpenSSL releases, including many that were potentially discovered by AI.
Public LLM models with safeguards turned off can also build working exploits, increasing patch gap risks.