§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesCVE-2026-19478 in GitLab allows unauthenticated modification or deletion of public projects and user data; exploitation observed.
Microsoft developing a Defender patch for ShieldBreak zero-day (CVE-2026-69414) disclosed by researcher 'Nightmare Eclipse'.
CVE-2026-43760 logic flaw in macOS Screen Sharing can be exploited to execute commands as root via file-copy helpers.
CVE-2026-19478 zero-click GitLab vulnerability lacks technical details, complicating detection for self-managed deployments.
CoSnitch vulnerabilities in Microsoft Copilot Personal let a crafted link exfiltrate connected-app data with a single click.
GitLab fixed a critical code injection flaw allowing unauthenticated actors to modify or delete user data and public projects.
Two-stage Unisoc VoLTE exploit chain achieves full Android kernel access via a specially crafted video call payload.
Critical AIT-GUI vulnerabilities allow unauthenticated attackers to issue spacecraft commands and manipulate ground-control scripts.
TWINLOOT Python implant uses SharePoint and Teams to host C2, steal credentials, and pivot inside Microsoft tenant environments.
CVE-2026-15748 arbitrary file upload bug in a WordPress form plugin lets unauthenticated attackers upload executable files on ~300,000 sites.
CISA confirms ransomware groups are exploiting a high-severity Windows Task Host vulnerability previously flagged as actively exploited.
CISA added a critical Ray vulnerability to its Known Exploited Vulnerabilities catalog due to observed active exploitation.
Active exploitation of MLflow SSRF (CVE-2026-64849) leads to cloud credential and secret theft from ML deployments.
SANS warns of exploited flaws in SharePoint, Winsock, VMware vCenter, and other vendor vulnerabilities requiring urgent patching.
Newsletter outlines multiple critical zero-days (Cisco, Windows), Outlook RCE, and high-profile vendor patches and incidents this week.
An unpatched GeoServer SQL-injection zero-day is being exploited in the wild, potentially enabling remote code execution and data theft.
Metabase zero-day impacted Salesforce and ServiceNow portals, exposing long-running data leakage and authentication bypass risk to enterprise tenants.
Get these articles delivered to your inbox.
Subscribe free