CVE-2026-76460: Cisco ISE Flaw Actively Exploited
CVE-2026-76460: Cisco ISE Flaw Actively Exploited CVE-2026-76460 represents a critical security flaw in Cisco’s Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Because the...
CVE-2026-76461: Cisco Email Gateway Flaw Exploited
CVE-2026-76461: Cisco Email Gateway Flaw Exploited Cisco has confirmed active exploitation of CVE-2026-76461, a critical SQL injection vulnerability in Cisco Secure Email Gateway that can lead to oper...
CVE-2026-27540 WooCommerce Flaw Exploited
CVE-2026-27540 WooCommerce Flaw Exploited Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPres...
GitLab CVE-2026-85706 Added to CISA KEV
GitLab CVE-2026-85706 Added to CISA KEV CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve arbitrary files from affected s...
Cisco FMC CVE-2026-20079 Actively Exploited
Cisco FMC CVE-2026-20079 Actively Exploited Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) w...
ShieldCrash PoC: Microsoft Defender Fix Bypass
ShieldCrash PoC: Microsoft Defender Fix Bypass Microsoft recently fixed CVE-2026-69414 (ShieldBreak), a High-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine. N...
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days Microsoft’s September 2026 Patch Tuesday release addresses 974 vulnerabilities, including two actively exploited zero-days. Both zero-days are Wind...
FBI Investigates Nexus Claim of 153M+ Driver’s License Records
FBI Investigates Nexus Claim of 153M+ Driver’s License Records Update 7/9/2026: ShinyHunters Seeks to Purchase the Nexus Dataset A Dark Web service called Nexus has claimed to offer access to more tha...
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited Attackers are actively exploiting an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows unaut...
N-able N-central HF4 Fixes Critical RCE After Series of Authentication...
N-able N-central HF4 Fixes Critical RCE After Series of Authentication Flaws N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to fix CVE-2026-86218, a critical pre-authentication remo...
CVE-2026-73749: HPE ArubaOS-CX RCE
CVE-2026-73749: HPE ArubaOS-CX RCE HPE patched CVE-2026-73749, a critical unauthenticated Remote Code Execution (RCE) vulnerability in HPE Aruba Networking AOS-CX, also known as ArubaOS-CX. The flaw a...
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw Cisco has disclosed a critical vulnerability, CVE-2026-20212, in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthent...
Elementor Pro RCE Flaw Under Active Attack
Elementor Pro RCE Flaw Under Active Attack A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’...
FalconFlank: CrowdStrike Falcon 0-Day PoC
FalconFlank: CrowdStrike Falcon 0-Day PoC FalconFlank is an alleged privilege escalation zero-day vulnerability in CrowdStrike Falcon Sensor for Windows, published with working Proof-of-Concept (PoC) ...
JFrog Artifactory CVE-2026-82329 Exploited
JFrog Artifactory CVE-2026-82329 Exploited A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is under active exploitation, posing an immediate threat to s...
SonicWall CVE-2026-83548 Leads to CISA Alert
SonicWall CVE-2026-83548 Leads to CISA Alert SonicWall disclosed two actively exploited vulnerabilities in SMA1000 Series appliances: CVE-2026-83548, a pre-authentication server-side request forgery f...
Langflow and Rails Exploitation Raises Credential Risks
Langflow and Rails Exploitation Raises Credential Risks Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. CVE-2026-0768 allows unauthenticated attack...
PaperCut RCE Chain: CVE-2026-82078 Exploited
PaperCut RCE Chain: CVE-2026-82078 Exploited PaperCut disclosed two vulnerabilities in PaperCut NG and PaperCut MF that can be chained into a pre-authentication Remote Code Execution (RCE) path agains...
ServiceNow Patches Multiple CVSS 10.0 Flaws
ServiceNow Patches Multiple CVSS 10.0 Flaws ServiceNow disclosed four vulnerabilities affecting its AI Platform and related Now Platform components on August 27, 2026. Three received vendor-assigned C...
Anthropic Links Claude Session Theft to Infostealer Malware
Anthropic Links Claude Session Theft to Infostealer Malware An affected Claude user has shared a warning from Anthropic stating that infostealer malware can steal active Claude login sessions from inf...
