Vulnerabilities briefings
Exploited and exploitable flaws, tracked from disclosure through proof-of-concept to active exploitation, with patch and mitigation guidance.
- Microsoft says a 10.0 Entra ID flaw was never exploited 2026-08-22
- WordPress forces a mass update after a critical Pods flaw 2026-08-21
- Attackers exploit a Zimbra bug to run commands on servers 2026-08-21
- Two hex digits bring a dead credit card back to life 2026-08-21
- Google patches critical Chrome remote desktop flaw 2026-08-21
- Abandoned e-learning platform has 13 flaws and no patch 2026-08-20
- US warns two critical TrueConf server flaws are exploited 2026-08-20
- Elementor Pro bug lets strangers take over WordPress sites 2026-08-20
- Free tool turns Windows Defender's own driver into a weapon 2026-08-20
- Joomla fixes upload bug that can run code on servers 2026-08-20
- A shared Splunk report can leak an admin session 2026-08-20
- Critical Citrix NetScaler bug lets attackers bypass login 2026-08-19
- Malicious file names run commands in the nnn file manager 2026-08-19
- Critical GitLab bug lets strangers delete public projects 2026-08-19
- Oracle ships 943 security fixes, one rated a perfect 10 2026-08-19
- Hackers exploit critical VMware vCenter and Windows bugs 2026-08-18
- Apple patches an image bug that can run code on iPhones 2026-08-18
- A zip bomb hidden in a .docx crashes Carbone servers 2026-08-18
- A booby-trapped image can run code on a WordPress site 2026-08-18
- Old iPhones just got 122 security fixes in one update 2026-08-18
- Forminator flaw exposes 600,000 WordPress sites to takeover 2026-08-17
- Hackers get root on Macs through Screen Sharing flaw 2026-08-17
- Ivanti bug can expose database logins to eavesdroppers 2026-08-17
- Hackers now attack a SharePoint flaw that skips the login 2026-08-17
- New ColdFusion flaw scores a perfect 10 for severity 2026-08-17
- Microsoft patches six security flaws in Edge browser 2026-08-17
- Apple fixed this zip bug in 2008. Upstream never did. 2026-08-15
- Metasploit ships working exploits for flaws under attack 2026-08-15
- A 61-character username can take over a WordPress site 2026-08-14
- 249 WordPress flaws in a week, 32 with no fix yet 2026-08-14
- Citrix NetScaler bug lets attackers hijack VPN gateways 2026-08-14
- Rogue VPN gateway can run code on Palo Alto clients 2026-08-14
- Critical flaw gives root on Haiwell industrial gateways 2026-08-13
- Two bugs let a bad Go proxy sneak past checksum checks 2026-08-13
- rsync ships 33 CVE fixes, one lets clients fake their IP 2026-08-13
- Brain and nerve stimulators take orders from strangers 2026-08-13
- Docker flaw lets a container take over the host machine 2026-08-13
- MongoDB patches 25 flaws across server and driver builds 2026-08-13
- Fortinet patches 8 bugs, worst is a FortiWeb login bypass 2026-08-12
- Critical SAP flaw lets anyone take over Commerce Cloud 2026-08-12
- Hackers are crashing Cisco firewalls through the VPN 2026-08-12
- Microsoft fixes 421 flaws as new Defender zero-day drops 2026-08-12
- Fertility monitor flaws expose reproductive health data 2026-08-11
- Zoom's drawing tool let anyone in a call hijack your laptop 2026-08-11
- AI helped find SharePoint bugs behind a server takeover 2026-08-11
- Traefik bug lets attackers reach protected admin pages 2026-08-11
- F5 BIG-IP DNS flaw has no patch, only workarounds 2026-08-11
- Booby-trapped fonts can crash or hijack Emacs on Android 2026-08-10
- Linux kernel bug hands any local user root on most distros 2026-08-10
- Metabase zero-day exploited, public exploit code is out 2026-08-10
- Public exploit lets macOS printing bug write files as root 2026-08-10
- WPMU DEV flaw lets attackers take over WordPress sites 2026-08-09
- Belgian banking ID extension let any site steal your PIN 2026-08-09
- Nearly a third of July's exploited bugs predate 2025 2026-08-08
- Fake clearances can be injected into cockpit datalink 2026-08-08
- Attackers exploit a critical Progress LoadMaster flaw 2026-08-07
- Public exploit lands for critical TeamCity server bug 2026-08-07
- WordPress bug runs code on the server if an admin clicks 2026-08-07
- Cloudflare runtime bugs leak tenant data in self-hosted lab 2026-08-07
- Update Chrome now to fix 41 security flaws 2026-08-07
- Safari's Private Relay leaks your real IP, researchers say 2026-08-06
- Windows Defender's own driver can be turned against it 2026-08-06
- AI helped turn an 18-year-old flaw into a container escape 2026-08-06
- New KVM bug lets a guest VM break out onto the host 2026-08-06
- Critical Jenkins flaw breaks the agent to server barrier 2026-08-06
- Cisco patches critical IOS XE flaws it found itself 2026-08-06
- CISA says attackers are exploiting critical TeamCity bug 2026-08-05
- Attackers keep access to SharePoint servers after patching 2026-08-05
- CISA says hackers exploit critical IBM Langflow AI flaw 2026-08-04
- Car alarm flaw lets attackers unlock and immobilize cars 2026-08-04
- DNA analyzer flaw lets attackers alter genetic test results 2026-08-04
- Smart-building protocol flaw is under attack, CISA says 2026-08-04
- Hackers exploit an N-able RMM login bypass, CISA warns 2026-08-03
- Critical Rails bug now has a working Metasploit exploit 2026-08-03
- Malware can steal Google passkeys and hijack accounts 2026-08-03
- Attackers weaponize most public exploits within 48 hours 2026-08-03
- Four SharePoint flaws joined CISA's exploited list in July 2026-08-03
- CISA flags four critical Joomla add-on bugs as exploited 2026-08-02
- One-click installs expose databases with a default password 2026-08-01
- Fuel terminal controllers ship with an open root debug port 2026-07-31
- Critical Rails flaw lets attackers steal app secrets 2026-07-31
- Critical VMware bugs let attackers take over virtual server fleets 2026-07-30
- Azure database flaw could have unlocked every customer database 2026-07-30
- Kubernetes storage flaws let one tenant read another tenant's files 2026-07-30
- CISA warns hackers are abusing a built-in Cisco firewall password 2026-07-29
- Critical JetBrains TeamCity bug lets attackers hijack build servers 2026-07-29
- CISA says hackers are exploiting Fortinet and Arista flaws 2026-07-29
- A second critical Fastjson flaw lets attackers run code on servers 2026-07-29
- Hackers exploit a critical Check Point flaw to hijack management servers 2026-07-25
- Critical login bypass hits Siemens and Rockwell industrial software 2026-07-22
- Hackers exploit critical Fastjson flaw to run code on servers 2026-07-22
- CISA flags four flaws under active attack, including two in WordPress 2026-07-22
- Hackers now exploit a critical WordPress flaw to hijack sites 2026-07-20
- Critical WordPress flaw lets attackers take over sites without logging in 2026-07-18
- Shark robot vacuum flaw exposes home cameras and Wi-Fi passwords 2026-07-17
- Chained Siemens switch zero-days give attackers root on OT networks 2026-07-17
- CISA flags a new SharePoint flaw as actively exploited 2026-07-17
- Old signed bootloaders let attackers bypass Secure Boot on most PCs 2026-07-17
- CISA flags critical bugs in Rockwell and ABB industrial gear 2026-07-15
- Hackers exploit SonicWall remote access appliances, CISA warns 2026-07-14
- Microsoft fixes 622 flaws in July, two already under active attack 2026-07-14
- SharePoint flaw lets attackers bypass login and impersonate any user 2026-07-14
- Microsoft patches Defender zero-day that grants full system control 2026-07-10
- A hidden signing key can let hackers forge any Microsoft login 2026-07-07
- CISA warns hackers are exploiting an Adobe ColdFusion flaw 2026-07-07
- Critical vulnerabilities surged 62% in the second quarter of 2026 2026-07-07
- Critical Oracle, Kemp, and Linux flaws come under active attack 2026-07-06
- Adobe patches a raft of critical ColdFusion code execution flaws 2026-07-03
- CISA warns of active attacks on a Microsoft SharePoint flaw 2026-07-02
- Update Chrome now to patch 382 security bugs, 15 critical 2026-07-02
- CISA warns of critical flaws across industrial control systems 2026-06-30
- New Citrix NetScaler flaw leaks memory from VPN gateways 2026-06-30
- Apple patches WebKit bugs that can be chained to steal data 2026-06-30
- CISA warns SimpleHelp remote-support bug is under active attack 2026-06-30
- Critical Kemp LoadMaster bug lets hackers run code without a login 2026-06-29
- Flaw in popular SSH library libssh2 lets rogue servers attack clients 2026-06-28
- Critical bugs expose medical imaging software, one unpatched 2026-06-26
- Critical flaws let attackers hijack EV charging networks 2026-06-26
- CISA flags Cisco and PTC bugs as actively exploited 2026-06-25
- Update Chrome now to fix four critical browser security flaws 2026-06-25
- Critical FFmpeg flaw lets a malicious video file hijack servers 2026-06-24
- Hackers exploit a new Cisco SD-WAN zero-day to gain root access 2026-06-24
- Siemens patches flaws that let attackers hijack network management servers 2026-06-24
- Hackers exploit Fortinet FortiSandbox flaws to hijack malware analysis servers 2026-06-22
- Node.js fixes TLS flaws that let attackers impersonate trusted servers 2026-06-20
- Hackers abuse a little known Windows installer to deploy malware 2026-06-19
- CISA warns of two actively exploited Cisco and cPanel bugs 2026-06-16
- Critical Splunk bug lets attackers take over servers without a login 2026-06-14
- Critical Ivanti Sentry flaw exploited in the wild after public exploit release 2026-06-12
- Check Point VPN zero-day lets attackers bypass login, now actively exploited 2026-06-12
- Microsoft patches 206 flaws, four critical bugs likely to be exploited 2026-06-10
- Google patches a Chrome zero-day already being used in attacks 2026-06-09
- One Click on a Windows Search Link Can Leak Your Password Hash 2026-06-06
- Hackers Are Breaking Into Palo Alto VPNs Without a Password 2026-06-06
- Fortinet Checks Whether Its Security Tools Are Exposed to a Linux Kernel Flaw 2026-06-06
- New Linux Bug Lets Any Local User Become Root 2026-06-06
- Hackers Break Into Unpatched Cisco SD-WAN Devices to Plant Webshells 2026-06-06
- Hackers Hijack cPanel Servers Through Critical Login Bypass 2026-06-05
- Kaspersky Discloses CVE-2025-68670, a Pre-Auth Stack Overflow in the xrdp Remote Desktop Server 2026-06-05
- OnePlus Websites Compromised via Abandoned AWS S3 Bucket — Stored XSS Active Across Multiple Domains 2026-03-17
- Google Patches Two Chrome Zero-Days Exploited in the Wild — Skia and V8 Under Active Attack 2026-03-15
- CVE-2026-27944: Nginx UI Backup Endpoint Exposes Full Server Secrets Without Authentication 2026-03-08
- FreePBX Patches SQL Injection and Command Injection Trio: CVE-2026-28210, CVE-2026-28284, CVE-2026-28287 2026-03-05
- Six CVEs Fixed in Gogs 0.14.2: Supply Chain Risk via LFS Object Overwrite, XSS Cluster, and Token Leakage 2026-03-05
- CVE-2026-3009 and CVE-2026-3047: Keycloak Authentication Bypass via Disabled Identity Providers and SAML Broker 2026-03-05
- CVE-2026-20127: Active Exploitation at Scale of Cisco Catalyst SD-WAN Zero-Day - Webshell Deployment, Sophisticated Implants, and 50+ Attack IPs Observed 2026-03-05