Home/Blog/Vulnerabilities

Vulnerabilities

Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.

171 articles

CVE-2026-12957/12958: Amazon Q Developer — Cloud Credential Theft via Malicious Repos (April 2026)
vulnerabilities

CVE-2026-12957/12958: Amazon Q Developer — Cloud Credential Theft via Malicious Repos (April 2026)

CVE-2026-12957 and CVE-2026-12958 are high-severity flaws in Amazon Q Developer for VS Code enabling cloud credential theft via malicious repositories. Patch immediately to prevent compromise.

Jun 29, 20262 min read
Read More
CVE-2026-20230: Cisco Unified Communications Manager — Remote SSRF File Write (June 2026)
vulnerabilities

CVE-2026-20230: Cisco Unified Communications Manager — Remote SSRF File Write (June 2026)

CVE-2026-20230 is a critical SSRF flaw in Cisco Unified Communications Manager Server, actively exploited and under CISA patch deadline for federal agencies.

Jun 28, 20262 min read
Read More
CVE-2026-46529: Atril Software — Single-Click Remote Code Execution (June 2026)
vulnerabilities

CVE-2026-46529: Atril Software — Single-Click Remote Code Execution (June 2026)

CVE-2026-46529 is a critical remote code execution vulnerability in Atril software, enabling attackers to compromise systems with a single user click. Immediate patching is required.

Jun 28, 20262 min read
Read More
CVE-2025-67038: Lantronix EDS5000 — Remote Root Code Execution (June 2026)
vulnerabilities

CVE-2025-67038: Lantronix EDS5000 — Remote Root Code Execution (June 2026)

CVE-2025-67038 is a critical code injection flaw in Lantronix EDS5000, allowing remote root command execution. Active exploitation ongoing; patch immediately.

Jun 27, 20262 min read
Read More
CVE-2021-26855 et al.: Multi-Vendor RCE Flaws Enable Cobalt Strike Deployment (June 2026)
vulnerabilities

CVE-2021-26855 et al.: Multi-Vendor RCE Flaws Enable Cobalt Strike Deployment (June 2026)

CVE-2021-26855, CVE-2023-32315, and related high-severity CVEs are being exploited in the StrikeShark campaign to deploy Cobalt Strike via SharkLoader. Immediate patching is critical to block ongoing attacks.

Jun 27, 20262 min read
Read More
CVE-2026-11374: ManageEngine Account Takeover — Critical Unauthorized Access Risk (June 2026)
vulnerabilities

CVE-2026-11374: ManageEngine Account Takeover — Critical Unauthorized Access Risk (June 2026)

CVE-2026-11374 is a critical zero-day in ManageEngine enabling account takeover and unauthorized access. Immediate patching is required to prevent exploitation.

Jun 26, 20262 min read
Read More
CVE-2026-50160: Hoppscotch API Platform — Unauthenticated Server Takeover (June 2026)
vulnerabilities

CVE-2026-50160: Hoppscotch API Platform — Unauthenticated Server Takeover (June 2026)

CVE-2026-50160 is a critical flaw in self-hosted Hoppscotch API Platform, enabling unauthenticated server takeover. Patch immediately to prevent persistent compromise.

Jun 26, 20262 min read
Read More
CVE-2026-20230: Cisco Unified CM — Webshell RCE in Active Exploitation (June 2026)
vulnerabilities

CVE-2026-20230: Cisco Unified CM — Webshell RCE in Active Exploitation (June 2026)

CVE-2026-20230 is a critical SSRF flaw in Cisco Unified Communications Manager enabling remote code execution via webshell drop; active exploitation confirmed. Immediate patching is mandatory.

Jun 25, 20262 min read
Read More
CVE-2025-54068: Laravel Livewire — Code Execution Risk (June 2025)
vulnerabilities

CVE-2025-54068: Laravel Livewire — Code Execution Risk (June 2025)

CVE-2025-54068 is a high-severity flaw in Laravel Livewire that may permit unauthorized access or code execution. Patch as soon as possible to mitigate risk.

Jun 25, 20262 min read
Read More
CVE-2024-40766: SonicWall SonicOS — Ransomware via Firewall Exploit (September 2024)
vulnerabilities

CVE-2024-40766: SonicWall SonicOS — Ransomware via Firewall Exploit (September 2024)

CVE-2024-40766 (critical) enables remote attackers to compromise SonicWall SonicOS firewalls, leading to rapid ransomware deployment. Patch all affected devices immediately—delays increase risk of total perimeter loss.

Jun 24, 20262 min read
Read More
CVE-2026-20971: Samsung KNOX — Kernel Privilege Escalation Risk (Jan 2026)
vulnerabilities

CVE-2026-20971: Samsung KNOX — Kernel Privilege Escalation Risk (Jan 2026)

CVE-2026-20971 is a high-severity use-after-free flaw in Samsung KNOX, enabling local kernel attacks on Galaxy S9–S25 devices. Patch by January 2026 update.

Jun 24, 20262 min read
Read More
CVE-2026-8461: FFmpeg MagicYUV Decoder — Remote Code Execution via Video Files (June 2024)
vulnerabilities

CVE-2026-8461: FFmpeg MagicYUV Decoder — Remote Code Execution via Video Files (June 2024)

CVE-2026-8461 is a high-severity heap out-of-bounds write in FFmpeg’s MagicYUV decoder, enabling remote code execution or denial-of-service via crafted video files. Patch FFmpeg immediately to mitigate risk.

Jun 23, 20262 min read
Read More