§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesMultiple Chrome and Edge extensions delivered malware modules that steal crypto wallets, browser data, and inject ClickFix social engineering.
GlobalProtect (Palo Alto Networks) has local privilege escalation flaws (CVE-2026-0251) enabling local code execution and privilege gains.
Ubiquiti patched 22 vulnerabilities in UniFi products, including three rated 10.0, requiring urgent firmware updates to prevent RCE.
CISA added six actively exploited vulnerabilities to its KEV catalog affecting Microsoft, Linux, Red Hat and Citrix products.
Critical Avada WordPress theme vulnerability enables unauthenticated zero-click PHP remote code execution on affected sites.
GPUThor Rowhammer technique bypasses NVIDIA ECC on RTX A6000 GPUs to escalate privileges and gain host root access.
CISA added a Microsoft SQL Server RCE (CVE-2019-1068) to KEV after observed exploitation allowing code execution under SQL Server service.
PaperCut NG/MF zero-day is actively exploited across all versions; vendor issued emergency patches and confirmed customer incidents.
CISA mandates immediate patching of Citrix NetScaler (CVE-2026-8452) after active exploitation; federal agencies have an urgent deadline.
SANS roundup: UK power plant outage, car proxy-malware botnet, and N-able Passportal/Keycloak vulnerability fixes.
Iran-linked cyberattack on a UK power plant underscores vulnerabilities in critical national infrastructure and small energy assets.
Get these articles delivered to your inbox.
Subscribe free