Home/Blog/Vulnerabilities

Vulnerabilities

Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.

228 articles

CVE-2025-8088: WinRAR — Silent Credential Theft & Espionage (June 2026)
vulnerabilities

CVE-2025-8088: WinRAR — Silent Credential Theft & Espionage (June 2026)

CVE-2025-8088 is a high-severity WinRAR vulnerability enabling remote code execution, actively exploited in 2026 by Russia-aligned APTs against Ukrainian government, military, and judicial entities. Patch immediately to prevent compromise.

Jun 15, 20262 min read
Read More
CVE-2026-35273: Multi-Vendor UEFI Shim — Secure Boot Bypass Risk (June 2026)
vulnerabilities

CVE-2026-35273: Multi-Vendor UEFI Shim — Secure Boot Bypass Risk (June 2026)

CVE-2026-35273 is a critical Secure Boot bypass in outdated UEFI shim bootloaders, enabling early boot-phase code execution and persistent compromise. Immediate patching is essential.

Jun 15, 20262 min read
Read More
CVE-2026-20253: Splunk Enterprise — Unauthenticated RCE via PostgreSQL (June 2026)
vulnerabilities

CVE-2026-20253: Splunk Enterprise — Unauthenticated RCE via PostgreSQL (June 2026)

CVE-2026-20253 is a critical Splunk Enterprise vulnerability (CVSS 9.8) enabling unauthenticated remote code execution; patch to 10.0.7 or 10.2.4 immediately.

Jun 14, 20262 min read
Read More
CVE-2026-48558: SimpleHelp OIDC — Remote Endpoint Hijack Risk (June 2026)
vulnerabilities

CVE-2026-48558: SimpleHelp OIDC — Remote Endpoint Hijack Risk (June 2026)

CVE-2026-48558 is a critical authentication bypass in SimpleHelp's remote management software (CVSS 10.0), allowing attackers to gain admin access and hijack endpoints. Patch immediately to prevent exploitation.

Jun 14, 20262 min read
Read More
CVE-2026-50751: Check Point VPN — Remote Auth Bypass Enables Ransomware (June 2026)
vulnerabilities

CVE-2026-50751: Check Point VPN — Remote Auth Bypass Enables Ransomware (June 2026)

CVE-2026-50751 (critical) is an authentication bypass in Check Point Remote Access VPN and Mobile Access, exploited in the wild since May 2026. All affected systems require immediate patching to prevent unauthorized access and ransomware deployment.

Jun 13, 20262 min read
Read More
CVE-2026-10520: Ivanti Sentry — Critical Remote Takeover Risk (June 2026)
vulnerabilities

CVE-2026-10520: Ivanti Sentry — Critical Remote Takeover Risk (June 2026)

CVE-2026-10520 is a critical OS command injection flaw in Ivanti Sentry, actively exploited to backdoor internet-exposed gateways. CISA mandates federal agencies patch within three days.

Jun 13, 20262 min read
Read More
CVE-2026-23111: Linux Kernel nf_tables — Local Root Escalation Risk (June 2026)
vulnerabilities

CVE-2026-23111: Linux Kernel nf_tables — Local Root Escalation Risk (June 2026)

CVE-2026-23111 is a high-severity Linux kernel vulnerability enabling local privilege escalation to root via nf_tables. Public exploits exist; patch immediately and reboot.

Jun 12, 20262 min read
Read More
CVE-2026-20253: Splunk Enterprise — Unauthenticated File Manipulation, RCE, SSRF, XSS (June 2026)
vulnerabilities

CVE-2026-20253: Splunk Enterprise — Unauthenticated File Manipulation, RCE, SSRF, XSS (June 2026)

CVE-2026-20253 and related Splunk Enterprise flaws (CVSS 9.8/8.8) are under active exploitation, enabling unauthenticated file manipulation and remote code execution. Immediate patching is critical.

Jun 12, 20262 min read
Read More
CVE-2026-5027: Langflow Path Traversal — Unauthenticated File Write Risk (June 2026)
vulnerabilities

CVE-2026-5027: Langflow Path Traversal — Unauthenticated File Write Risk (June 2026)

CVE-2026-5027 is a high-severity path traversal flaw in Langflow, enabling unauthenticated attackers to write arbitrary files on exposed servers. Immediate patching is critical to prevent compromise.

Jun 11, 20262 min read
Read More
CVE-2026-10520, CVE-2026-10523: Ivanti Sentry — Remote Root Code Execution Risk (June 2024)
vulnerabilities

CVE-2026-10520, CVE-2026-10523: Ivanti Sentry — Remote Root Code Execution Risk (June 2024)

CVE-2026-10520 and CVE-2026-10523 are critical vulnerabilities in Ivanti Sentry enabling remote root code execution; no exploitation reported, but immediate patching is required.

Jun 11, 20262 min read
Read More
CVE-2026-42271: BerriAI LiteLLM — Unauthenticated RCE Chain Exposed (June 2026)
vulnerabilities

CVE-2026-42271: BerriAI LiteLLM — Unauthenticated RCE Chain Exposed (June 2026)

CVE-2026-42271 (CVSS 10.0, critical) enables command injection in BerriAI LiteLLM, and is being actively exploited in the wild. Immediate patching is required to prevent unauthenticated remote code execution via a chained Starlette flaw (CVE-2026-48710).

Jun 10, 20262 min read
Read More
CVE-2026-50751: Check Point VPN — Authentication Bypass Enables Ransomware (May 2026)
vulnerabilities

CVE-2026-50751: Check Point VPN — Authentication Bypass Enables Ransomware (May 2026)

CVE-2026-50751 is a critical authentication bypass in Check Point VPN/firewall appliances, exploited since May 2026 for ransomware attacks. Immediate patching is required to prevent unauthorized VPN access.

Jun 10, 20262 min read
Read More