
CVE-2025-67038: Lantronix EDS5000 — Remote Root Code Execution (June 2026)
CVE-2025-67038 is a critical code injection flaw in Lantronix EDS5000, allowing remote root command execution. Active exploitation ongoing; patch immediately.
Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.
228 articles

CVE-2025-67038 is a critical code injection flaw in Lantronix EDS5000, allowing remote root command execution. Active exploitation ongoing; patch immediately.

CVE-2021-26855, CVE-2023-32315, and related high-severity CVEs are being exploited in the StrikeShark campaign to deploy Cobalt Strike via SharkLoader. Immediate patching is critical to block ongoing attacks.

CVE-2026-11374 is a critical zero-day in ManageEngine enabling account takeover and unauthorized access. Immediate patching is required to prevent exploitation.

CVE-2026-50160 is a critical flaw in self-hosted Hoppscotch API Platform, enabling unauthenticated server takeover. Patch immediately to prevent persistent compromise.

CVE-2026-20230 is a critical SSRF flaw in Cisco Unified Communications Manager enabling remote code execution via webshell drop; active exploitation confirmed. Immediate patching is mandatory.

CVE-2025-54068 is a high-severity flaw in Laravel Livewire that may permit unauthorized access or code execution. Patch as soon as possible to mitigate risk.

CVE-2024-40766 (critical) enables remote attackers to compromise SonicWall SonicOS firewalls, leading to rapid ransomware deployment. Patch all affected devices immediately—delays increase risk of total perimeter loss.

CVE-2026-20971 is a high-severity use-after-free flaw in Samsung KNOX, enabling local kernel attacks on Galaxy S9–S25 devices. Patch by January 2026 update.

CVE-2026-8461 is a high-severity heap out-of-bounds write in FFmpeg’s MagicYUV decoder, enabling remote code execution or denial-of-service via crafted video files. Patch FFmpeg immediately to mitigate risk.

CVE-2025-66336 is a high-severity SQL injection flaw in Apache Doris that permits arbitrary SQL execution and data compromise. Patch as soon as possible.

CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 (high severity) are actively exploited to hijack D-Link DIR-850L and DIR-818LW routers. Patch or replace affected devices immediately.

CVE-2026-45257 is a high-severity flaw in FreeBSD’s Kernel TLS (KTLS) that could expose encrypted network data. Immediate patching is critical to prevent data compromise.