Home/Blog/Vulnerabilities

Vulnerabilities

Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.

171 articles

CVE-2026-20296,20297,20298,53412: Splunk & Zoom — Credential Theft, Account Takeover Risk (June 2026)
vulnerabilities

CVE-2026-20296,20297,20298,53412: Splunk & Zoom — Credential Theft, Account Takeover Risk (June 2026)

CVE-2026-20296, CVE-2026-20297, CVE-2026-20298, and CVE-2026-53412 are critical flaws in Splunk and Zoom, enabling credential theft and account takeover. Immediate patching is required.

Jul 17, 20262 min read
Read More
CVE-2026-6875: ServiceNow AI Platform — Unauthenticated RCE Risk (July 2026)
vulnerabilities

CVE-2026-6875: ServiceNow AI Platform — Unauthenticated RCE Risk (July 2026)

CVE-2026-6875 is a critical unauthenticated remote code execution vulnerability in ServiceNow’s AI platform. Immediate patching is required to prevent exploitation.

Jul 16, 20262 min read
Read More
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA 1000 — Admin Command Execution Risk (July 2026)
vulnerabilities

CVE-2026-15409 & CVE-2026-15410: SonicWall SMA 1000 — Admin Command Execution Risk (July 2026)

CVE-2026-15409 and CVE-2026-15410 are critical zero-days in SonicWall SMA 1000, enabling admin-level command execution and SSRF. Patching is mandatory and urgent.

Jul 16, 20262 min read
Read More
CVE-2026-44747: SAP NetWeaver ABAP — Critical Memory Corruption Risk (July 2026)
vulnerabilities

CVE-2026-44747: SAP NetWeaver ABAP — Critical Memory Corruption Risk (July 2026)

CVE-2026-44747 is a critical (CVSS 9.9) out-of-bounds write vulnerability in SAP NetWeaver Application Server ABAP, patched in July 2026. Immediate patching is required to prevent memory corruption and potential data breaches.

Jul 15, 20262 min read
Read More
CVE-2026-56164, CVE-2026-56155: Microsoft SharePoint & AD FS — Active Exploitation, Privilege Escalation (July 2026)
vulnerabilities

CVE-2026-56164, CVE-2026-56155: Microsoft SharePoint & AD FS — Active Exploitation, Privilege Escalation (July 2026)

CVE-2026-56164 and CVE-2026-56155 are critical Microsoft zero-days under active attack, enabling privilege escalation in SharePoint Server and AD FS. Immediate patching is mandatory due to confirmed exploitation.

Jul 15, 20262 min read
Read More
CVE-2018-0171, CVE-2008-4128: Cisco Smart Install — Grid Attack Attempt Thwarted (June 2024)
vulnerabilities

CVE-2018-0171, CVE-2008-4128: Cisco Smart Install — Grid Attack Attempt Thwarted (June 2024)

CVE-2018-0171 and CVE-2008-4128 are critical Cisco Smart Install flaws actively exploited by Russian state-linked actors; patch all affected devices immediately.

Jul 14, 20262 min read
Read More
CVE-2025-32711: OpenClaw GPT-5.4 — AI Memory Poisoning via Email (July 2026)
vulnerabilities

CVE-2025-32711: OpenClaw GPT-5.4 — AI Memory Poisoning via Email (July 2026)

CVE-2025-32711 is a high-severity flaw in OpenClaw AI agents allowing persistent memory poisoning via a single email. Patch or mitigate immediately.

Jul 14, 20262 min read
Read More
CVE-2026-XXXXX: Ubiquiti UniFi — Remote Code Execution Risk (July 2026)
vulnerabilities

CVE-2026-XXXXX: Ubiquiti UniFi — Remote Code Execution Risk (July 2026)

CVE-2026-XXXXX is a critical UniFi vulnerability allowing remote code execution and denial of service. Ubiquiti has released urgent patches; update immediately.

Jul 13, 20262 min read
Read More
CVE-2023-24489: Progress ShareFile Storage Zone — Immediate Shutdown Ordered (July 2026)
vulnerabilities

CVE-2023-24489: Progress ShareFile Storage Zone — Immediate Shutdown Ordered (July 2026)

CVE-2023-24489 is a high-severity vulnerability impacting Progress ShareFile Storage Zone Controllers, prompting an urgent shutdown directive. No patch or workaround is currently available; immediate action is required.

Jul 13, 20262 min read
Read More
CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492: Router Exploits Enable Persistent APT Access (July 2026)
vulnerabilities

CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492: Router Exploits Enable Persistent APT Access (July 2026)

CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 are high-severity router vulnerabilities exploited by UAT-7810 for persistent access. Patch all affected devices immediately.

Jul 12, 20262 min read
Read More
CVE-2026-39861: Anthropic/OpenAI Coding Agents — Silent Malicious Code Execution (July 2026)
vulnerabilities

CVE-2026-39861: Anthropic/OpenAI Coding Agents — Silent Malicious Code Execution (July 2026)

CVE-2026-39861 (High) enables silent execution of attacker-supplied code via Anthropic Claude Code and OpenAI Codex in autonomous review modes. Patch or disable autonomous execution immediately.

Jul 12, 20262 min read
Read More
CVE-2026-3844: WordPress Breeze Plugin — Mass Webshell Backdooring (July 2026)
vulnerabilities

CVE-2026-3844: WordPress Breeze Plugin — Mass Webshell Backdooring (July 2026)

CVE-2026-3844 (CVSS: High) enables remote attackers to deploy persistent webshells via the WordPress Breeze plugin. Exploitation is active; patch immediately.

Jul 11, 20262 min read
Read More