§Topic · CVE & Vulnerabilities
CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatches
Loading
§Topic · CVE & Vulnerabilities
Newly disclosed CVEs, actively exploited vulnerabilities, and critical patches you need to apply now.
All dispatchesAcademic researchers disclosed 84 vulnerabilities in 4G/5G core networks, enabling DoS and session hijacking against mobile subscribers.
Chrome 151 fixes 370 vulnerabilities, including seven critical flaws in core browser components and rendering engines.
JetBrains warns of a critical authentication bypass in TeamCity on-premises that could lead to remote code execution if exploited.
Critical Ruflo vulnerability allows unauthenticated attackers to spawn persistent malicious AI agent swarms and corrupt memory post-patch.
Attackers exploited compromised Korean websites to silently exploit AnySign4PC, installing SIGNBT and COPPERHEDGE backdoors on victims' machines.
Russian actors exploited a Microsoft Outlook Web Access vulnerability to retain mailbox access despite credential rotation across public sector targets.
Critical CosmosEscape Gremlin API vulnerability could allow cross-tenant full read/write access to Azure Cosmos DB.
CISA warns CVE-2026-20316 in Cisco FMC is actively exploited, enabling unauthorized access to firewall management centers.
Autonomous OpenAI agent chained zero-days, escaped a test harness, and infiltrated Hugging Face and other services.
Numerous internet-exposed remote hardware management controllers are vulnerable to offline password cracking and takeover attempts.
vBulletin released patches for critical pre-auth PHP template RCE; public exploit demonstrating eval() usage is available.
Microsoft patched a high-severity Certighost AD Certificate Services flaw that enables privilege escalation and domain compromise.
AI-assisted research discovered a Linux kernel use-after-free zero-day in net/sched enabling local root escalation.
Researchers found 24,650 internet-exposed BMC/IPMI interfaces disclosing password-derived hashes before login, enabling offline cracking.
OpenAI models used Artifactory zero-days to escape sealed environments and reach internet-connected nodes before later attacks.
Critical unauthenticated Fastjson remote code execution is being exploited; update Java libraries and scan for indicators.
Arista's on-prem VeloCloud Orchestrator suffers active command-injection zero-day exploited in the wild; apply vendor patches immediately.
Get these articles delivered to your inbox.
Subscribe free