CISA added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog after active exploitation was observed.
Microsoft released a patch for a critical vulnerability in Entra ID that is actively exploited in targeted attacks, affecting identity and access management security.
CISA has included two actively exploited TrueConf Server vulnerabilities in its Known Exploited Vulnerabilities Catalog, emphasizing critical risks to federal agencies and beyond.
CISA warns that threat actors are actively exploiting a critical vulnerability in the MLflow AI engineering platform, posing risks to federal agencies and beyond.
Citrix has patched critical authentication bypass vulnerabilities affecting NetScaler ADC and Gateway, impacting specific FIPS and NDcPP builds used on gateway and AAA servers.
US government agencies warn of an active cyber threat exploiting Siemens S7 Series programmable logic controllers using AI-assisted scripts, risking critical infrastructure disruption and safety.
CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
CISA has added a critical Ray Framework vulnerability enabling browser remote code execution to its Known Exploited Vulnerabilities catalog, noting ongoing exploitation.
CISA confirms ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability, posing increased risk to enterprise environments.
CISA added the actively exploited Ray-Project code injection vulnerability CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, highlighting urgent remediation needs.
CVE-2026-54121 enables a standard domain user to escalate privileges by exploiting an Enterprise Certificate Authority to become a Domain Controller, exposing risks in PKI infrastructure trust models.
A high-severity out-of-bounds read vulnerability in Siemens Parasolid parsing X_T files allows potential arbitrary code execution, affecting versions prior to V38.0.235 and V38.1.230.
Two medium-to-high severity vulnerabilities in Johnson Controls Airwall could allow attackers to decrypt sensitive data and read arbitrary files, impacting critical infrastructure security.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched just three days ago is now actively exploited, posing a critical security risk.
Siemens patched a critical remote code execution vulnerability in multiple versions of its Siveillance Video Management Servers that threatens critical infrastructure.
Threat actors are exploiting the critical directory traversal vulnerability CVE-2026-59310 in VMware vCenter, enabling remote code execution and requiring immediate attention from defenders.
The 'ShieldBreak' zero-day exploit targeting Microsoft Defender enables attackers to obtain SYSTEM-level privileges on affected systems following the August 2026 Patch Tuesday.
A critical SharePoint vulnerability (CVE-2026-55040) enables unauthenticated remote code execution, facilitated by AI, affecting several SharePoint Server versions.
Cisco alerts on a high-severity denial-of-service vulnerability in Secure Firewall ASA and Threat Defense VPN software actively exploited to crash devices, threatening enterprise network stability.
Microsoft's August 2026 Patch Tuesday addresses 400 security flaws, including one actively exploited zero-day and two publicly disclosed zero-day vulnerabilities.
CISA has added CVE-2026-8037, a critical Progress LoadMaster command injection vulnerability actively exploited in the wild, to its Known Exploited Vulnerabilities Catalog, requiring prioritized remediation by federal agencies under BOD 26-04.
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
Cisco released patches for 12 critical vulnerabilities in Catalyst SD-WAN and IOS XE software impacting devices in all configurations.
High-severity vulnerabilities in ABB Ability Zenon IIoT services using MongoDB 4.2 allow unauthorized access, denial of service, and potential data compromise.
HashiCorp, Veeam, and the Django Software Foundation released patches for 11 vulnerabilities, including a critical CVSS 10.0 cross-tenant bug affecting Terraform MCP Server, Veeam Service Provider Console, and Django software.
A critical vulnerability in cPanel (CVE-2026-58048) allowed authenticated hosting customers to execute SQL commands with root database privileges, risking full database control.
A high-severity vulnerability in Thermo Fisher Applied Biosystems Genetic Analyzers allows modification of DNA data output files, risking inaccurate test results in healthcare settings.
CISA added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog due to active exploitation, prioritizing federal agency remediation under BOD 26-04.
A firmware vulnerability in Coldcard hardware wallets enabled attackers to steal approximately $70 million in Bitcoin by draining over 1,000 addresses in under an hour.
Adobe Campaign Classic includes a critical CVSS 10.0 vulnerability (CVE-2026-48449) that allows arbitrary code execution without user interaction.
A critical vulnerability in Azure Cosmos DB enabled attackers to escape the Gremlin query sandbox and gain full read/write access to multiple customer databases.
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote code execution, posing significant risk to enterprise environments.
Cisco disclosed a high-severity zero-day vulnerability in its Secure Firewall Management Center involving static credentials, actively exploited to gain unauthorized access.
A critical Active Storage vulnerability in Ruby on Rails allows unauthenticated attackers to read arbitrary server files through malicious image uploads, risking exposure of sensitive data.
A critical vulnerability in the Ruflo open-source agent platform allows unauthenticated remote code execution and poisoning of AI memory, posing significant risks to AI model operations.
Broadcom published updates for critical VMware vulnerabilities in ESX, vCenter, Workstation, and Fusion enabling authentication bypass and VM escape with high severity.
Arista released a patch for a critical command injection zero-day vulnerability currently exploited in on-premises VeloCloud Orchestrator deployments, affecting enterprise network management.
A critical stack buffer overflow in OpenSSL affects Siemens Desigo CC versions V7, V8, and V9 before 9.0.1, posing risks of remote code execution or denial of service.
A critical DHCPv6 stack overflow vulnerability in OpenWrt's default network service odhcpd allows unauthenticated remote root code execution.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
A critical pre-authentication remote code execution vulnerability in vBulletin forum software has been patched following the public release of an exploit, enabling unauthenticated attackers to execute arbitrary PHP code.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
The Certighost exploit enables low-privileged Active Directory users to obtain Domain Controller certificates and authenticate as domain controllers, risking critical Kerberos credential compromise.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
Multiple high-severity vulnerabilities in Weintek cMT3092X HMI may allow attackers to escalate privileges and steal credentials, impacting critical manufacturing environments.
CISA has added CVE-2026-16232 and CVE-2026-50522 to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation targeting Check Point SmartConsole and Microsoft SharePoint.
CISA has mandated U.S. federal agencies to urgently address a remote code execution vulnerability actively exploited in Langflow, posing critical risks to infrastructure security.
A critical authentication bypass vulnerability in Tycon Systems TPDIN-Monitor-WEB2 allows unauthenticated attackers full administrative control, risking critical infrastructure disruptions.
Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, now actively exploited after a public proof-of-concept was released, enabling remote code execution via deserialization of untrusted data.
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.
F5 released patches for CVE-2026-42533, a critical nginx flaw allowing remote, unauthenticated attackers to trigger a heap buffer overflow that can crash workers or enable remote code execution.
A zero-day vulnerability named LegacyHive enables privilege escalation on fully updated Windows systems, allowing attackers to gain admin-level access.
CISA has directed federal agencies to urgently patch two actively exploited vulnerabilities in Fortinet FortiSandbox, highlighting critical risks to government and enterprise environments.
A critical vulnerability in WordPress core enables unauthenticated attackers to execute code on default installations, prompting urgent patch releases.
CISA issued a warning about three actively exploited vulnerabilities in Internet-exposed on-premises SharePoint Server instances that allow remote compromise.
Zoom has disclosed a critical vulnerability in its Windows desktop client and SDK that enables unauthenticated attackers to hijack user accounts, posing a significant security risk.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.
SAP released updates fixing a critical CVSS 9.9 out-of-bounds write vulnerability in NetWeaver ABAP that may allow authenticated attackers to corrupt memory and manipulate data.
SonicWall disclosed two critical zero-day vulnerabilities in SMA1000 devices being exploited in active attacks, highlighting urgent risk to enterprise network security.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.
Progress Software advises ShareFile customers to shut down Windows servers running Storage Zone Controllers due to a credible security threat, disabling account access as a precaution.
OpenPLC v3 contains a critical authenticated arbitrary file write vulnerability that can lead to native code execution through compiling malicious files. This affects critical infrastructure sectors worldwide and requires urgent mitigation.
Researchers tested 281 popular free Android VPN apps and discovered many leak user traffic, transmit unencrypted data, and include tracking. These apps, collectively installed over 2.4 billion times, fail to meet basic privacy and security standards.
Ubiquiti released updates to fix critical vulnerabilities in UniFi Connect, Talk, Access, Protect, and OS. These flaws could allow privilege escalation and arbitrary command execution.
Threat actors are actively attempting to exploit a critical vulnerability in Gitea Docker images less than two weeks after it was patched. The flaw allows unauthenticated clients to escalate privileges by abusing the 'X-WEBAUTH-USER' header.
A critical use-after-free flaw in Linux's KVM hypervisor allows guest VMs on Intel and AMD systems to corrupt host kernel memory, potentially escaping the virtual environment. The vulnerability, known as Januscape (CVE-2026-53359), includes a public PoC that crashes hosts with a more impactful exploit reportedly in development.
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is now being actively exploited in cyberattacks, according to KEVIntel. This flaw demands immediate attention due to its maximum severity rating.
A new Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), allows unprivileged users to escalate to root, impacting Linux desktops, servers, and Android devices. A patch has already been released.
Security firm runZero disclosed seven vulnerabilities in FatFs, a widely used filesystem library in embedded devices including security cameras and drones. These flaws pose a risk due to FatFs's ubiquity in consumer and industrial firmware.
Attackers have started exploiting a critical CVE-2026-46817 vulnerability in the Oracle E-Business Suite financial application, as reported by Defused. This flaw poses significant risk to enterprises using Oracle EBS.
Hackers are actively exploiting a critical vulnerability in SimpleHelp (CVE-2026-48558) to distribute Djinn Stealer, a new cross-platform information stealer targeting Windows, macOS, and Linux. This campaign represents a novel threat leveraging an undocumented malware strain.
CISA has set a Sunday deadline for federal agencies to patch a critical vulnerability in Cisco Unified Communications Manager Server actively exploited in attacks. Immediate action is urged to prevent further compromise.
CISA has issued a warning about an actively exploited critical code injection vulnerability, CVE-2025-67038, affecting Lantronix EDS5000 Series devices. Federal agencies are urged to apply patches by June 26, 2026, to prevent potential remote code execution.
CISA has issued a warning about hackers actively exploiting severe vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers. These flaws carry a maximum severity rating and pose significant risk to affected organizations.
Mandiant has exposed how attackers exploited a zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN to create rogue root accounts on devices, raising serious security concerns. This vulnerability enables full control of targeted network appliances, potentially impacting enterprise operations.
A high-severity Server-Side Request Forgery vulnerability in Cisco Unified Communications Manager Server, tracked as CVE-2026-20230, is actively being exploited in the wild. Security teams should prioritize detection and mitigation to prevent potential compromise.