The Hacker News
INFO
Wed, 17 Jun 2026 23:06:28 +0530
Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation flaw. "Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender
The Hacker News
INFO
Wed, 17 Jun 2026 16:00:00 +0530
Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk. With time-to-exploit now down to a
The Hacker News
INFO
Wed, 17 Jun 2026 11:20:46 +0530
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-48907 (CVSS score: 10.0), is a case of improper access control that could facilitate arbitrary
BleepingComputer Security
INFO
Wed, 17 Jun 2026 11:12:57 -0400
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. [...]
BleepingComputer Security
INFO
Wed, 17 Jun 2026 07:54:21 -0400
Microsoft is investigating a new issue preventing third-party applications from launching Microsoft Office applications or opening documents on up-to-date Windows systems. [...]
BleepingComputer Security
INFO
Wed, 17 Jun 2026 06:09:24 -0400
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a maximum-severity flaw in the Widget Factory Joomla Content Editor (JCE) plugin that is being actively exploited in the wild. [...]
BleepingComputer Security
INFO
Wed, 17 Jun 2026 04:32:29 -0400
Microsoft confirmed that it's working on a security patch for a Defender zero-day vulnerability named "RoguePlanet," disclosed one week ago. [...]
The Hacker News
INFO
Wed, 10 Jun 2026 21:38:42 +0530
Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors. "The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's
The Hacker News
INFO
Wed, 10 Jun 2026 20:40:59 +0530
Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It's tracked as CVE-2026-25089 (CVSS score: 9.1). "An
The Hacker News
INFO
Wed, 10 Jun 2026 20:30:59 +0530
A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrary locations. "The 'POST /api/v2/
Krebs on Security
INFO
Wed, 10 Jun 2026 14:03:44 +0000
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
The Hacker News
INFO
Tue, 16 Jun 2026 16:00:41 +0530
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could
The Hacker News
INFO
Tue, 16 Jun 2026 15:14:34 +0530
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker News. "Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP,
The Hacker News
INFO
Tue, 16 Jun 2026 13:44:55 +0530
The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. "The attack email contained a message impersonating an MS account security alert," the Genians Security Center (GSC) said. "It was designed to create concern over possible
The Hacker News
INFO
Tue, 16 Jun 2026 11:35:58 +0530
Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. "A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or
The Hacker News
INFO
Tue, 16 Jun 2026 11:11:52 +0530
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case of privilege
Krebs on Security
INFO
Tue, 12 May 2026 21:46:45 +0000
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers -- including Apple, Google, Microsoft, Mozilla and Oracle -- fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.
Krebs on Security
INFO
Tue, 09 Jun 2026 22:07:28 +0000
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.
BleepingComputer Security
INFO
Thu, 18 Jun 2026 07:33:00 -0400
Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems. [...]
BleepingComputer Security
INFO
Thu, 18 Jun 2026 06:14:20 -0400
Microsoft has fixed a known issue causing the June 2026 security updates to fail on Windows Server 2016 systems that weren't up to date. [...]
The Hacker News
INFO
Thu, 11 Jun 2026 23:13:52 +0530
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger. "If you ever attempted to use Windows Defender Offline Scan, you're
The Hacker News
INFO
Thu, 11 Jun 2026 22:20:47 +0530
A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis). According to a detailed report
The Hacker News
INFO
Sat, 13 Jun 2026 18:53:03 +0530
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. "In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary
The Hacker News
INFO
Sat, 13 Jun 2026 01:03:25 +0530
Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself. The AUR is Arch Linux's community package collection, and it is separate
Krebs on Security
INFO
Mon, 18 May 2026 20:48:21 +0000
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.
The Hacker News
INFO
Mon, 15 Jun 2026 20:39:05 +0530
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were
The Hacker News
INFO
Mon, 15 Jun 2026 11:47:32 +0530
Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited by bad
The Hacker News
INFO
Fri, 12 Jun 2026 23:47:55 +0530
Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no
The Hacker News
INFO
Fri, 12 Jun 2026 15:20:36 +0530
Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, and multi-agent artificial intelligence (AI) agentic applications. "An SQL injection in LangGraph's function could
The Hacker News
INFO
Fri, 12 Jun 2026 12:08:41 +0530
Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a "key financial pipeline used to wash hundreds of millions in illicit profits." The service is estimated to have been used to launder more than €336 million (~$389 million) since the
The Hacker News
INFO
Fri, 12 Jun 2026 01:59:23 +0530
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a
CISA KEV
KNOWN_EXPLOITED
2026-06-16T00:00:00+00:00
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
CISA KEV
KNOWN_EXPLOITED
2026-06-15T00:00:00+00:00
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
CISA KEV
KNOWN_EXPLOITED
2026-06-15T00:00:00+00:00
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
CISA KEV
KNOWN_EXPLOITED
2026-06-12T00:00:00+00:00
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
CISA KEV
KNOWN_EXPLOITED
2026-06-11T00:00:00+00:00
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
CISA KEV
KNOWN_EXPLOITED
2026-06-09T00:00:00+00:00
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CISA KEV
KNOWN_EXPLOITED
2026-06-09T00:00:00+00:00
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
CISA KEV
KNOWN_EXPLOITED
2026-06-09T00:00:00+00:00
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
CISA KEV
KNOWN_EXPLOITED
2026-06-08T00:00:00+00:00
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
CISA KEV
KNOWN_EXPLOITED
2026-06-08T00:00:00+00:00
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
CISA KEV
KNOWN_EXPLOITED
2026-06-05T00:00:00+00:00
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
CISA KEV
KNOWN_EXPLOITED
2026-06-03T00:00:00+00:00
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
CISA KEV
KNOWN_EXPLOITED
2026-06-02T00:00:00+00:00
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CISA KEV
KNOWN_EXPLOITED
2026-06-02T00:00:00+00:00
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
CISA KEV
KNOWN_EXPLOITED
2026-06-01T00:00:00+00:00
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
CISA KEV
KNOWN_EXPLOITED
2026-05-29T00:00:00+00:00
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CISA KEV
KNOWN_EXPLOITED
2026-05-27T00:00:00+00:00
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
CISA KEV
KNOWN_EXPLOITED
2026-05-27T00:00:00+00:00
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
CISA KEV
KNOWN_EXPLOITED
2026-05-27T00:00:00+00:00
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
CISA KEV
KNOWN_EXPLOITED
2026-05-26T00:00:00+00:00
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
CISA KEV
KNOWN_EXPLOITED
2026-05-22T00:00:00+00:00
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
CISA KEV
KNOWN_EXPLOITED
2026-05-21T00:00:00+00:00
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
CISA KEV
KNOWN_EXPLOITED
2026-05-21T00:00:00+00:00
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
CISA KEV
KNOWN_EXPLOITED
2026-05-20T00:00:00+00:00
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
CISA KEV
KNOWN_EXPLOITED
2026-05-15T00:00:00+00:00
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
CISA KEV
KNOWN_EXPLOITED
2026-05-14T00:00:00+00:00
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
CISA KEV
KNOWN_EXPLOITED
2026-05-08T00:00:00+00:00
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.
CISA KEV
KNOWN_EXPLOITED
2026-05-07T00:00:00+00:00
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
CISA KEV
KNOWN_EXPLOITED
2026-05-06T00:00:00+00:00
Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
CISA KEV
KNOWN_EXPLOITED
2026-05-01T00:00:00+00:00
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
CISA KEV
KNOWN_EXPLOITED
2026-04-30T00:00:00+00:00
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CISA KEV
KNOWN_EXPLOITED
2026-04-28T00:00:00+00:00
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
CISA KEV
KNOWN_EXPLOITED
2026-04-28T00:00:00+00:00
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CISA KEV
KNOWN_EXPLOITED
2026-04-24T00:00:00+00:00
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CISA KEV
KNOWN_EXPLOITED
2026-04-24T00:00:00+00:00
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
CISA KEV
KNOWN_EXPLOITED
2026-04-24T00:00:00+00:00
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
CISA KEV
KNOWN_EXPLOITED
2026-04-24T00:00:00+00:00
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
CISA KEV
KNOWN_EXPLOITED
2026-04-23T00:00:00+00:00
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
CISA KEV
KNOWN_EXPLOITED
2026-04-22T00:00:00+00:00
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
CISA KEV
KNOWN_EXPLOITED
2026-04-20T00:00:00+00:00
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CISA KEV
KNOWN_EXPLOITED
2026-04-16T00:00:00+00:00
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CISA KEV
KNOWN_EXPLOITED
2026-04-14T00:00:00+00:00
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
CISA KEV
KNOWN_EXPLOITED
2026-04-14T00:00:00+00:00
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Adobe Acrobat contains a use-after-free vulnerability that allows for code execution
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CISA KEV
KNOWN_EXPLOITED
2026-04-13T00:00:00+00:00
Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.
CISA KEV
KNOWN_EXPLOITED
2026-04-08T00:00:00+00:00
Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
CISA KEV
KNOWN_EXPLOITED
2026-04-06T00:00:00+00:00
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
CISA KEV
KNOWN_EXPLOITED
2026-04-02T00:00:00+00:00
TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
CISA KEV
KNOWN_EXPLOITED
2026-04-01T00:00:00+00:00
Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CISA KEV
KNOWN_EXPLOITED
2026-03-30T00:00:00+00:00
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.
CISA KEV
KNOWN_EXPLOITED
2026-03-27T00:00:00+00:00
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.
CISA KEV
KNOWN_EXPLOITED
2026-03-26T00:00:00+00:00
Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.
CISA KEV
KNOWN_EXPLOITED
2026-03-25T00:00:00+00:00
Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
CISA KEV
KNOWN_EXPLOITED
2026-03-20T00:00:00+00:00
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
CISA KEV
KNOWN_EXPLOITED
2026-03-20T00:00:00+00:00
Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CISA KEV
KNOWN_EXPLOITED
2026-03-20T00:00:00+00:00
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
CISA KEV
KNOWN_EXPLOITED
2026-03-20T00:00:00+00:00
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
CISA KEV
KNOWN_EXPLOITED
2026-03-20T00:00:00+00:00
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
CISA KEV
KNOWN_EXPLOITED
2026-03-19T00:00:00+00:00
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
CISA KEV
KNOWN_EXPLOITED
2026-03-18T00:00:00+00:00
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability in the Classic UI where attackers could abuse Cascading Style Sheets (CSS) @import directives in email HTML.
CISA KEV
KNOWN_EXPLOITED
2026-03-18T00:00:00+00:00
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CISA KEV
KNOWN_EXPLOITED
2026-03-16T00:00:00+00:00
Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.
CISA KEV
KNOWN_EXPLOITED
2026-03-13T00:00:00+00:00
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CISA KEV
KNOWN_EXPLOITED
2026-03-13T00:00:00+00:00
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
CISA KEV
KNOWN_EXPLOITED
2026-03-11T00:00:00+00:00
n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
CISA KEV
KNOWN_EXPLOITED
2026-03-09T00:00:00+00:00
Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
CISA KEV
KNOWN_EXPLOITED
2026-03-09T00:00:00+00:00
SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
CISA KEV
KNOWN_EXPLOITED
2026-03-09T00:00:00+00:00
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.
CISA KEV
KNOWN_EXPLOITED
2026-03-05T00:00:00+00:00
Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
CISA KEV
KNOWN_EXPLOITED
2026-03-05T00:00:00+00:00
Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.
CISA KEV
KNOWN_EXPLOITED
2026-03-05T00:00:00+00:00
Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.