
CVE-2026-20349: Cisco Secure Firewall — Remote DoS Zero-Day Exploited (August 2026)
CVE-2026-20349 is a critical zero-day in Cisco Secure Firewall ASA and FTD, enabling remote unauthenticated denial-of-service. Cisco urges immediate patching.
Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.
229 articles

CVE-2026-20349 is a critical zero-day in Cisco Secure Firewall ASA and FTD, enabling remote unauthenticated denial-of-service. Cisco urges immediate patching.

CVE-2026-65400 is a high-severity flaw in macOS Screen Sharing allowing remote root access and cryptominer deployment. Patch immediately—active exploitation confirmed.

CVE-2007-3010, CVE-2016-6277, and 16 other CVEs are being actively exploited (high severity) by Evooo1Bot to turn Linux-based edge devices into SOCKS5 proxies. Patch all affected devices immediately to prevent compromise.

CVE-2026-73570 is a critical, actively exploited remote code execution flaw in Zimbra Collaboration Suite. CISA requires urgent patching; apply fixes immediately.

CVE-2026-12569 is a high-severity remote code execution flaw in PTC Windchill and FlexPLM, exploited by Cl0p ransomware for mass data theft. Patch immediately to prevent compromise.

CVE-2024-3094 (high severity) enables automated credential theft and supply chain compromise via malicious npm package scripts. Patch or quarantine affected packages immediately.

CVE-2026-76034 and CVE-2026-76036 are critical Chrome vulnerabilities enabling remote code execution outside the sandbox. Patch immediately—no workarounds.

CVE-2021-33044 and CVE-2021-33045 are critical authentication bypass flaws (CVSS up to 9.8) in Dahua cameras, exploited in Operation CameraSwarm to compromise over 14,530 devices. Immediate firmware patching is required.

CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, and CVE-2026-65400 are critical, actively exploited flaws in Microsoft, VMware, and Apple products enabling remote code execution and device takeover. CISA urges immediate patching by all organizations.

CVE-2026-15826 is a critical authentication bypass in Cozmoslabs User Profile Builder (≤3.16.4) enabling admin takeover on 40,000+ WordPress sites. Patch immediately.

CVE-2025-6514 (High) exposes plaintext credentials and enables prompt injection attacks on MCP servers. Patch or mitigate immediately to prevent enterprise breaches.

CVE-2026-69414 is a high-severity privilege escalation vulnerability in Microsoft Defender that bypasses the July 2026 RoguePlanet patch. No official fix is available; immediate mitigation is required.