Artificial Intelligence OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents. Eduard KovacsAugust 28, 2026
Vulnerabilities Recent Citrix NetScaler Vulnerability Exploited in the Wild CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. Eduard KovacsAugust 27, 2026
Vulnerabilities CISA Warns of Exploited Gitea Vulnerability CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. Eduard KovacsAugust 26, 2026
Vulnerabilities CISA Warns of Exploited Oracle WebLogic Vulnerability The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. Eduard KovacsAugust 25, 2026
Vulnerabilities CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. Ionut ArghireAugust 21, 2026
Vulnerabilities CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities The flaws can be exploited for remote code execution, authentication bypass, and device takeover. Ionut ArghireAugust 19, 2026
Vulnerabilities CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. Ionut ArghireAugust 10, 2026
Vulnerabilities CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. Ionut ArghireAugust 5, 2026
Vulnerabilities Organizations Warned of Exploited Joomla Extension Vulnerabilities Threat actors have been targeting Balbooa Forms and iCagenda Joomla extension flaws for remote code execution. Ionut ArghireJuly 13, 2026
Ransomware BlueHammer Vulnerability Exploited in Ransomware Attacks The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. Eduard KovacsJune 30, 2026
Malware & Threats Critical SimpleHelp Vulnerability Exploited for Malware Delivery The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. Ionut ArghireJune 30, 2026
Vulnerabilities Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands. Ionut ArghireJune 24, 2026
Vulnerabilities Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution. Eduard KovacsJune 19, 2026
Vulnerabilities Joomla, LiteSpeed Vulnerabilities Exploited in Attacks The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers. Ionut ArghireJune 17, 2026
Vulnerabilities Ivanti Sentry Exploitation Attempts Hitting Honeypots The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges. Ionut ArghireJune 12, 2026
Government CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries. Ionut ArghireJune 11, 2026
Vulnerabilities Organizations Warned of Exploited Linux Kernel Vulnerability An improper authentication bug allows attackers to escalate their privileges and escape containers. Ionut ArghireJune 3, 2026
Vulnerabilities Oracle WebLogic Vulnerability Exploited in the Wild The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. Eduard KovacsJune 2, 2026
Vulnerabilities CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges. Ionut ArghireMay 27, 2026
Vulnerabilities Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before. Ionut ArghireApril 21, 2026