
CVE-2025-66336: Apache Doris — SQL Injection Enables Data Breach (June 2024)
CVE-2025-66336 is a high-severity SQL injection flaw in Apache Doris that permits arbitrary SQL execution and data compromise. Patch as soon as possible.
Security vulnerabilities remain the most common entry point for cyber attacks. This section tracks newly discovered CVEs, zero-day vulnerabilities, and actively exploited flaws affecting enterprise infrastructure, cloud environments, and software supply chains.
171 articles

CVE-2025-66336 is a high-severity SQL injection flaw in Apache Doris that permits arbitrary SQL execution and data compromise. Patch as soon as possible.

CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 (high severity) are actively exploited to hijack D-Link DIR-850L and DIR-818LW routers. Patch or replace affected devices immediately.

CVE-2026-45257 is a high-severity flaw in FreeBSD’s Kernel TLS (KTLS) that could expose encrypted network data. Immediate patching is critical to prevent data compromise.

CVE-2026-20181 (critical) enables authenticated admin users to execute arbitrary OS commands as root on Cisco ISE and ISE-PIC. Patch immediately to prevent privilege escalation and data exposure.

CVE-2023-3519, CVE-2025-5777, CVE-2023-48788, and CVE-2024-57727 are critical vulnerabilities exploited by INC ransomware in active campaigns since 2023. Patch immediately to prevent compromise.

CVE-2025-20701 (critical) allows attackers within Bluetooth range to eavesdrop on Beats Studio Buds microphones without user consent. Patch immediately—Apple firmware update required.

CVE-2026-20253 is a critical Splunk Enterprise vulnerability enabling unauthenticated remote file creation/truncation, now under active exploitation. CISA requires patching by June 21, 2026.

CVE-2023-52271, CVE-2025-61155, and CVE-2025-1055 (high severity) enable stealthy C2 traffic via Microsoft Teams TURN relays. Immediate review and patching are critical.

CVE-2026-50656 is a high-severity zero-day in Microsoft Defender enabling SYSTEM-level privilege escalation. Patch ETA pending; immediate mitigation required.

CVE-2026-20266 and CVE-2026-20265 are critical Splunk AI Toolkit flaws (CVSS 9.1) enabling OS command injection and data exfiltration. Patch to 5.7.4 immediately.

CVE-2023-24932 (high severity) enables stealthy remote access on Windows via kernel-level malware. Active exploitation reported; patch immediately.

CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 are critical Fortinet FortiSandbox vulnerabilities (CVSS: critical) exploited for unauthenticated remote code execution. Immediate patching is mandatory.