CVE
17 articles
Advertisement
Articles17
Linux 'pedit COW' (CVE-2026-46331) Hands Local Users Root via Page-Cache Corruption — Patch and Reboot
CVE-2026-46331, nicknamed pedit COW, is a Linux kernel local privilege-escalation flaw in the traffic-control...
CY
30 Jun
Cisco Unified CM SSRF Flaw CVE-2026-20230 Is Now Being Exploited — Patch by 28 June and Check for Compromise
CISA added CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager, to its...
CY
30 Jun
Three Maximum-Severity Ubiquiti UniFi OS Flaws Are Being Exploited — Patch via Bulletin 064 and Check for Compromise
CISA added three maximum-severity Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, -34909 and -34910) to its...
CY
30 Jun
Joomla JCE Flaw CVE-2026-48907 (CVSS 10.0) Is Being Actively Exploited — Patch and Check for Compromise
CISA added CVE-2026-48907, a maximum-severity flaw in the Widget Factory Joomla Content Editor extension (JCE...
CY
19 Jun
Palo Alto GlobalProtect Flaw CVE-2026-0257 Is Under Active Exploitation — Patch or Mitigate Now
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication-bypass flaw in PAN-OS...
CY
19 Jun
CSA Flags GlobalProtect Auth-Bypass CVE-2026-0257 as Critical While Attackers Forge VPN Cookies in the Wild
Singapore's CSA rates a GlobalProtect authentication-bypass flaw critical (9.1) — sterner than Palo Alto's own...
CY
7 Jun
CISA orders agencies to patch an actively exploited Palo Alto firewall flaw by 1 June
Attackers are exploiting a flaw in Palo Alto Networks' PAN-OS that lets them slip past security controls and o...
CY
1 Jun
LiteSpeed cPanel Plugin Zero-Day CVE-2026-48172: Maximum-Severity Root Escalation Under Active Exploitation
CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA...
CY
1 Jun
This week's bugs to patch: a critical OTRS flaw and a Linux root hole on CISA's list
A short, practical read of the week's most urgent vulnerabilities: a critical pre-authentication flaw in the O...
CY
1 Jun
Threat Brief, Week of 18 May 2026: State-Backed Espionage in Malaysia, a Malware-Signing Takedown, and the Defender Itself Under Fire
Our weekly read of the threat landscape: a state-backed actor ran a bespoke espionage operation against Malays...
CY
30 May
An LLM Agent Drove This Real Intrusion: Marimo RCE to Database Dump in Under an Hour
On 10 May an internet-exposed marimo notebook was breached through CVE-2026-39987 — and then an autonomous LLM...
CY
30 May
Cisco Patches Sixth SD-WAN Zero-Day of 2026 — UAT-8616 Attribution from Talos
Cisco shipped an emergency advisory for CVE-2026-20182 on 15 May 2026, a peering authentication bypass in Cata...
CY
18 May
CISA Orders Federal Agencies to Patch Linux Kernel "Copy Fail" Zero-Day Within Two Weeks
A 732-byte Python script is all an unprivileged local user needs to take root on Ubuntu 24.04, RHEL 10.1, SUSE...
CY
18 May
Critical Palo Alto Firewall Zero-Day Actively Exploited by State-Sponsored Hackers — CISA Orders Patch by 9 May
CVE-2026-0300, a critical PAN-OS buffer overflow enabling unauthenticated root-level RCE, is being actively ex...
CY
8 May
Critical GitHub RCE Flaw CVE-2026-3854 Lets Attackers Execute Code With a Single Git Push — Patch Now
CVE-2026-3854, a CVSS 9.8 RCE flaw in GitHub Enterprise Server, allows unauthenticated code execution via a si...
CY
8 May
AI-Assisted Attacks Are the New Normal: Mandiant M-Trends 2026 Shows Exploit Windows Have Inverted
Mandiant's M-Trends 2026 report confirms 28.3% of CVEs are now exploited within 24 hours of disclosure — and d...
CY
8 May
AI Has Made Cyber Exploits Faster Than Patches — 28% of CVEs Now Exploited Within 24 Hours
Mandiant's M-Trends 2026 report reveals that time-to-exploit has gone negative: exploits now routinely arrive...
CY
4 May
Advertisement