Vulnerabilities Arista Urges Immediate Patching of Exploited VCO Zero-Day Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. Ionut Arghire5 days ago
Vulnerabilities Critical F5 BIG-IP Vulnerability Exploited as Zero-Day Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. Ionut Arghire5 days ago
Vulnerabilities Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. Ionut ArghireSeptember 17, 2026
Mobile & Wireless Pixel Modem Zero-Day Exploited in Targeted Attacks Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. Eduard KovacsSeptember 16, 2026
Email Security Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. Eduard KovacsSeptember 15, 2026
Vulnerabilities BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. Ionut ArghireSeptember 12, 2026
Vulnerabilities N-able Patches Critical Zero-Day in N-central Administrators are advised to check their deployments for newly created user accounts they don’t recognize. Ionut ArghireSeptember 8, 2026
Vulnerabilities Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. Ionut ArghireSeptember 7, 2026
Vulnerabilities Google Patches 6th Chrome Zero-Day of 2026 Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. Ionut ArghireSeptember 4, 2026
Vulnerabilities SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. Eduard KovacsSeptember 2, 2026
Vulnerabilities PaperCut Exploitation Escalates to Active Intrusions CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. Eduard KovacsSeptember 1, 2026
Endpoint Security Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. Eduard KovacsAugust 31, 2026
Vulnerabilities More Details Emerge on Exploited PaperCut Vulnerabilities PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578. Eduard KovacsAugust 31, 2026
Vulnerabilities PaperCut Releases Emergency Patch for Exploited Zero-Day A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations. Eduard KovacsAugust 28, 2026
Vulnerabilities Hackers Exploiting Unpatched GeoServer Zero-Day The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. Ionut ArghireAugust 14, 2026
Vulnerabilities Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. Ionut ArghireAugust 13, 2026
Vulnerabilities Fresh Windows Zero-Day Exploited in North Korean Cyberattacks The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. Ionut ArghireAugust 12, 2026
Vulnerabilities Cisco Patches Firewall Zero-Day Exploited for DoS Attacks CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. Eduard KovacsAugust 12, 2026
Vulnerabilities August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges. Ionut ArghireAugust 11, 2026
Vulnerabilities Metabase Patches Vulnerability Exploited as Zero-Day The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. Ionut ArghireAugust 10, 2026