Vulnerabilities
120 articles RSS
Microsoft Discloses CVE-2026-45497, a Command-Injection RCE in 365 Copilot Already Fixed Server-Side With No Customer Action
Microsoft rated the Copilot command-injection flaw Critical, with a 7.7 CVSS base score. It was already mitigated in the cloud and not exploited.
Cisco Discloses Another Exploited SD-WAN Manager Zero-Day, CVE-2026-20245, With No Patch Yet and a Crafted File Path to Root
Cisco says CVE-2026-20245, a 7.8-rated command-injection flaw in Catalyst SD-WAN Manager, is being exploited to gain root. No patch or workaround is available; Mandiant reported it.
CISA Adds Four-Year-Old Linux Kernel cgroups Container-Escape Flaw CVE-2022-0492 to KEV Catalog Citing Active Exploitation
CISA added the 2022 Linux kernel cgroups release_agent flaw CVE-2022-0492 to its KEV catalog on June 2, 2026, with a June 5 federal patch deadline.
Google Confirms Limited Exploitation of an Android Framework Integer-Overflow Flaw, CVE-2025-48595, in June Security Bulletin
Google's June 2026 Android update patches a Framework privilege-escalation zero-day under limited, targeted exploitation. CISA added it to the KEV catalog with a June 5 federal deadline.
Belgium's Cyber Agency Says Critical Windows Netlogon Flaw CVE-2026-41089 Is Now Being Exploited — Microsoft Disputes It
Belgium's CCB warns the 9.8-rated Netlogon RCE is exploited in the wild, threatening domain controllers. Microsoft says it has no evidence.
Attackers Exploit CVE-2026-35616 in FortiClient EMS to Deploy EKZ Infostealer Disguised as a Fortinet Patch
Arctic Wolf found attackers abusing a critical 9.8-CVSS FortiClient EMS authentication bypass to silently push EKZ Infostealer to every managed endpoint via legitimate VPN scripting workflows.
Trend Micro Patches Apex One Zero-Day CVE-2026-34926 Exploited in the Wild, CISA Orders Federal Agencies to Patch by June 4
A directory traversal flaw in Trend Micro Apex One lets an attacker with admin server access inject malicious code into managed endpoints. CISA added it to KEV on May 21 with a June 4 federal deadline.
Ghost CMS SQL Injection CVE-2026-26980 Exploited to Hijack 700 Sites in Large-Scale ClickFix Campaign
A patched SQL injection in Ghost CMS (versions 3.24.0–6.19.0) has been exploited at scale to compromise 700+ websites, including Harvard and Oxford, turning them into ClickFix malware distribution points.
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector for First Time in 19 Years
The 2026 DBIR finds 31% of breaches now begin with unpatched vulnerabilities -- surpassing credential abuse for the first time in the report's 19-year history -- as median patch time climbs to 43 days and ransomware reaches 48% of all breaches.
MiniPlasma: A Five-Year-Old Windows Zero-Day Resurfaces With Working PoC, Granting SYSTEM Privileges on Fully Patched Systems
A researcher named Chaotic Eclipse released a working exploit for an unpatched Windows privilege escalation flaw in the Cloud Filter driver, confirmed to grant SYSTEM access on fully patched Windows 11.
Microsoft Confirms Active Exploitation of Unpatched Exchange Server CVE-2026-42897 as CISA Adds It to KEV With May 29 Deadline
Microsoft has disclosed an actively exploited cross-site scripting flaw in on-premises Exchange Server's Outlook Web Access. No patch has shipped; CISA gave federal agencies until May 29 to apply mitigations.
DepthFirst's AI Scanner Surfaces NGINX Rift, an 18-Year-Old Heap Overflow in the Rewrite Module That Enables Unauthenticated RCE
An LLM-powered scanner from security startup DepthFirst flagged a heap buffer overflow that had sat undetected in NGINX's rewrite module for roughly 18 years, prompting F5 to ship coordinated patches on May 13.