CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation
Jun 16, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in t
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Jun 15, 2026
Vulnerability Critical Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. [...]
Weekly Threat Roundup: 2026-06-08 to 2026-06-14
Jun 14, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-06-08 to 2026-06-14. 4 CVE advisories, 3 breach reports, 5 threat news stories.
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Jun 10, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitati
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
Jun 9, 2026
Vulnerability Critical Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
Jun 9, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
Jun 8, 2026
Vulnerability Critical Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protoco
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
Jun 5, 2026
Vulnerability Critical CISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. [...]
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
Jun 3, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation
Jun 2, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, ba
Weekly Threat Roundup: 2026-05-25 to 2026-05-31
May 31, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-05-25 to 2026-05-31. 2 CVE advisories, 5 breach reports, 4 threat news stories.
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
May 30, 2026
Vulnerability Critical Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as C
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
May 29, 2026
Vulnerability Critical An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
May 28, 2026
Vulnerability Critical Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
May 22, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog,
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
May 22, 2026
Vulnerability Critical Drupal is warning that hackers are attempting to exploit a 'highly critical' SQL injection vulnerability announced earlier this week. [...]
Weekly Threat Roundup: 2026-05-11 to 2026-05-17
May 17, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-05-11 to 2026-05-17. 3 CVE advisories, 3 breach reports, 1 threat news stories.
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
May 14, 2026
Vulnerability Critical Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrat
Weekly Threat Roundup: 2026-05-04 to 2026-05-10
May 10, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-05-04 to 2026-05-10. 10 CVE advisories, 5 breach reports, 4 threat news stories.
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
May 7, 2026
Vulnerability Critical Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. [...]
Weekly Threat Roundup: 2026-04-27 to 2026-05-03
May 3, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-04-27 to 2026-05-03. 10 CVE advisories, 5 breach reports, 5 threat news stories.
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
May 3, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) c
Critical cPanel and WHM bug exploited as a zero-day, PoC now available
Apr 30, 2026
Vulnerability Critical The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in attempts since late February. [...]
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)
Apr 27, 2026
Vulnerability Critical TeamPCP supply chain campaign resumed after a 26-day pause with three concurrent compromises (Checkmarx KICS, Bitwarden CLI, xinference PyPI). A new self-propagating npm worm, CanisterSprawl, has also been identified.
Weekly Threat Roundup: 2026-04-20 to 2026-04-26
Apr 26, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-04-20 to 2026-04-26. 10 CVE advisories, 2 breach reports, 5 threat news stories.
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
Apr 25, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
Apr 21, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco C
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
Apr 17, 2026
Vulnerability Critical CISA warned that attackers are now exploiting a high-severity Apache ActiveMQ vulnerability, which was patched earlier this month after going undetected for 13 years. [...]
Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
Apr 13, 2026
Vulnerability Critical Adobe has released an emergency security update for Acrobat Reader to fix a vulnerability, tracked as CVE-2026-34621, that has been exploited in zero-day attacks since at least December. [...]
Weekly Threat Roundup: 2026-04-06 to 2026-04-12
Apr 12, 2026
roundup
Trending
Critical Cybersecurity roundup for 2026-04-06 to 2026-04-12. 10 CVE advisories, 2 breach reports, 4 threat news stories.
Hackers exploit React2Shell in automated credential theft campaign
Apr 5, 2026
Vulnerability Critical Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps. [...]
Critical Citrix NetScaler memory flaw actively exploited in attacks
Mar 30, 2026
Vulnerability Critical Hackers are exploiting a critical severity vulnerability, tracked as CVE-2026-3055, in Citrix NetScaler ADC and NetScaler Gateway appliances to obtain sensitive data. [...]
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
Mar 28, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) c
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Mar 26, 2026
Vulnerability Critical The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
Mar 21, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catal
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
Mar 19, 2026
Vulnerability Critical A critical Microsoft SharePoint vulnerability patched in January is now being exploited in attacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned. [...]
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
Mar 16, 2026
Vulnerability Critical CISA warned U.S. government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks. [...]
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
Mar 12, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting n8n to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of ac
CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
Mar 10, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. Th
Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
Mar 6, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Hikvision and Rockwell Automation products to its Known Exploited Vulnerabilities (KEV)
Bruteforce Scans for CrushFTP , (Tue, Mar 3rd)
Mar 3, 2026
Vulnerability Critical CrushFTP is a Java-based open source file transfer system. It is offered for multiple operating systems. If you run a CrushFTP instance, you may remember that the software has had some serious vulnera
CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog
Mar 3, 2026
Vulnerability Critical The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday
Mar 2, 2026
Vulnerability Critical A Florida woman was sentenced to 22 months in prison for running a massive years-long scheme to traffic thousands of stolen Microsoft Certificate of Authenticity (COA) labels. [...]
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration
Feb 20, 2026
Vulnerability Critical Hackers are actively exploiting the CVE-2026-1731 vulnerability in the BeyondTrust Remote Support product, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns. [...]