Click2Shell: WordPress Flaw Enables RCE Chain
Click2Shell: WordPress Flaw Enables RCE Chain Click2Shell is a vulnerability in WordPress Core that allows a logged-in administrator’s browser to be manipulated into installing and previewing a theme ...
Clop Hack: ShinyHunters Hijacks Data Leak Site
Clop Hack: ShinyHunters Hijacks Data Leak Site ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site ...
CVE-2026-91843: Check Point Root RCE
CVE-2026-91843: Check Point Root RCE Check Point has patched CVE-2026-91843, a critical stack-based buffer overflow flaw in the login process of its Security Management and Log Server products. If exp...
CVE-2026-76460: Cisco ISE Flaw Actively Exploited
CVE-2026-76460: Cisco ISE Flaw Actively Exploited CVE-2026-76460 represents a critical security flaw in Cisco’s Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Because the...
CVE-2026-76461: Cisco Email Gateway Flaw Exploited
CVE-2026-76461: Cisco Email Gateway Flaw Exploited Cisco has confirmed active exploitation of CVE-2026-76461, a critical SQL injection vulnerability in Cisco Secure Email Gateway that can lead to oper...
CVE-2026-27540 WooCommerce Flaw Exploited
CVE-2026-27540 WooCommerce Flaw Exploited Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPres...
GitLab CVE-2026-85706 Added to CISA KEV
GitLab CVE-2026-85706 Added to CISA KEV CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve arbitrary files from affected s...
Cisco FMC CVE-2026-20079 Actively Exploited
Cisco FMC CVE-2026-20079 Actively Exploited Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) w...
ShieldCrash PoC: Microsoft Defender Fix Bypass
ShieldCrash PoC: Microsoft Defender Fix Bypass Microsoft recently fixed CVE-2026-69414 (ShieldBreak), a High-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine. N...
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days Microsoft’s September 2026 Patch Tuesday release addresses 974 vulnerabilities, including two actively exploited zero-days. Both zero-days are Wind...
FBI Investigates Nexus Claim of 153M+ Driver’s License Records
FBI Investigates Nexus Claim of 153M+ Driver’s License Records Update 7/9/2026: ShinyHunters Seeks to Purchase the Nexus Dataset A Dark Web service called Nexus has claimed to offer access to more tha...
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited Attackers are actively exploiting an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows unaut...
N-able N-central HF4 Fixes Critical RCE After Series of Authentication...
N-able N-central HF4 Fixes Critical RCE After Series of Authentication Flaws N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to fix CVE-2026-86218, a critical pre-authentication remo...
CVE-2026-73749: HPE ArubaOS-CX RCE
CVE-2026-73749: HPE ArubaOS-CX RCE HPE patched CVE-2026-73749, a critical unauthenticated Remote Code Execution (RCE) vulnerability in HPE Aruba Networking AOS-CX, also known as ArubaOS-CX. The flaw a...
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw Cisco has disclosed a critical vulnerability, CVE-2026-20212, in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthent...
Elementor Pro RCE Flaw Under Active Attack
Elementor Pro RCE Flaw Under Active Attack A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’...
FalconFlank: CrowdStrike Falcon 0-Day PoC
FalconFlank: CrowdStrike Falcon 0-Day PoC FalconFlank is an alleged privilege escalation zero-day vulnerability in CrowdStrike Falcon Sensor for Windows, published with working Proof-of-Concept (PoC) ...
JFrog Artifactory CVE-2026-82329 Exploited
JFrog Artifactory CVE-2026-82329 Exploited A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is under active exploitation, posing an immediate threat to s...
SonicWall CVE-2026-83548 Leads to CISA Alert
SonicWall CVE-2026-83548 Leads to CISA Alert SonicWall disclosed two actively exploited vulnerabilities in SMA1000 Series appliances: CVE-2026-83548, a pre-authentication server-side request forgery f...
Langflow and Rails Exploitation Raises Credential Risks
Langflow and Rails Exploitation Raises Credential Risks Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. CVE-2026-0768 allows unauthenticated attack...
