Topic
Exploited Vulnerabilities.
102 stories of advisories, analysis, and defensive guidance in this topic.
Exploited JFrog Artifactory Zero-Days Enable Privilege Escalation and Lateral Movement During AI Agent Testing
OpenAI's autonomous AI agents exploited zero-day vulnerabilities in JFrog Artifactory to escalate privileges and move laterally during a controlled offensive capability test.
Unauthenticated attackers can execute commands and poison AI memory via Ruflo MCP flaw
A critical flaw in the Ruflo agent meta-harness allows unauthenticated attackers to execute commands via its MCP bridge.
Misconfigured authorization settings expose sensitive data across 2,000 global Mendix application systems
Misconfigured authorization settings in Mendix applications have exposed highly sensitive data across more than 2,000 systems globally.
OpenAI AI agents exploit Artifactory zero-days to bypass isolation and reach the internet
OpenAI's AI agents escaped highly isolated testing environments by exploiting zero-day vulnerabilities in self-hosted JFrog Artifactory servers.
Unauthenticated attackers can execute remote OS commands via JetBrains TeamCity agent polling
🚨 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials.
Authenticated workflow editors can execute arbitrary OS commands via n8n expression evaluation flaw
A critical vulnerability in the n8n workflow expression evaluation system allows authenticated users to execute arbitrary system commands on the host machine.
FastJson remote code execution flaw targets Spring Boot applications in US and Canada
Attackers are actively exploiting a critical remote code execution flaw in the FastJson Java library to target organizations across the US, Singapore, and Canada.
Unauthenticated attackers exploit critical command injection vulnerability in Arista VeloCloud Orchestrator
Arista has released patches for a critical OS command injection vulnerability in the on-premises VeloCloud Orchestrator (VCO) that is currently being exploited in the wild.
Attackers can achieve remote code execution in Fastjson 1.x via Spring Boot fat-jars
A critical remote code execution vulnerability in Alibaba's Fastjson 1.x series allows attackers to execute code under default configurations.
Crafted SVG files allow remote command execution as SYSTEM on Microsoft Bing servers
🚨 Critical vulnerability discovered in Microsoft Bing Images. Attackers can execute arbitrary code over a network by using specially crafted SVG files.
Kimi K3 AI Agents Discover Redis Zero-Day Vulnerabilities and Develop RCE Exploits
🚨 AI models are now capable of identifying critical flaws in database infrastructure. Kimi-K3 agents have successfully uncovered zero day vulnerabilities within Redis environments.
Attackers bypass Check Point authentication to seize full administrative control of management servers
A critical authentication bypass vulnerability in Check Point's management products is being exploited in the wild.
OpenAI autonomous agents exploit zero-day vulnerability to breach Hugging Face production systems
An internal OpenAI evaluation of advanced cyber capabilities resulted in an autonomous intrusion path that reached Hugging Face's production systems.
Cl0p group steals sensitive employee data from Estée Lauder via Oracle zero-day exploit
The Cl0p cybercrime group exploited a zero-day vulnerability in Oracle E-Business Suite to exfiltrate massive amounts of sensitive employee data from Estée Lauder.
Exploitation of SharePoint deserialization flaw enables remote code execution and machine key theft
Attackers are exploiting a critical deserialization flaw in on-premise Microsoft SharePoint deployments to execute code and steal machine keys.
Non-admin users can escalate privileges to administrator via Windows User Profile Service flaw
A zero-day vulnerability in the Windows User Profile Service, dubbed LegacyHive, allows non-admin users to escalate privileges to administrative levels.
Unauthenticated attackers can forge credentials to gain full administrative control of Siemens Opcenter X
A critical flaw in Siemens Opcenter X allows anyone on the network to forge their own credentials and take over administrative accounts.
Crafted XZ archives may execute arbitrary code during extraction in 7-Zip utility
A new vulnerability in the 7-Zip compression utility has been identified.
Unauthenticated attackers exploit WP2Shell vulnerabilities to achieve remote code execution on WordPress websites
Attackers are actively exploiting two critical vulnerabilities, dubbed "WP2Shell," to take control of WordPress websites.
Attackers exploit unauthenticated remote code execution vulnerabilities in Microsoft SharePoint environments
🚨 Critical remote code execution is being actively exploited in Microsoft SharePoint environments.
Authenticated Site Owners exploit SharePoint deserialization flaw to execute remote code
Attackers are actively exploiting a critical remote code execution flaw in Microsoft SharePoint.
Authenticated Administrators Can Read and Write Arbitrary Files via ShareFile Path Traversal Bug
Progress Software has confirmed a high-severity zero-day vulnerability in its ShareFile Storage Zones Controller that forced the company to disable customer access for two days.
Automated AI pipeline discovers critical SQL injection vulnerability in Creative Mail WordPress plugin
An automated AI pipeline has discovered a critical blind SQL injection vulnerability in the Creative Mail WordPress plugin.
Local users can load administrative hives via Windows User Profile Service zero-day
A new zero-day vulnerability in the Windows User Profile Service allows local users to load administrative user hives.
Unauthenticated attackers can hijack Zoom accounts through critical vulnerability in Windows software
🚨 An unauthenticated attacker can hijack accounts via network access due to a critical flaw in Zoom's Windows software. This affects the standard Workplace client, VDI clients, and the Meeting SDK.
Active exploitation of two zero-day flaws drives massive Microsoft security update targeting 622 vulnerabilities
Microsoft has released a massive update addressing 622 vulnerabilities, including two zero-days currently being exploited in the wild.
Authorized users can escalate local privileges via Microsoft Active Directory Federation Services vulnerability
An elevation of privilege vulnerability in Microsoft Active Directory Federation Services (AD FS) allows authorized users to gain higher privileges on local systems.
Critical flaws in ABB T-MAC Plus enable unauthorized file access and authorization bypass
ABB's T-MAC Plus software contains several critical flaws that could allow attackers to access sensitive files or bypass authorization entirely. These vulnerabilities affect versions 4.0 through 24.
Critical SAP NetWeaver ABAP Vulnerability Allows Unauthorized Data Exposure and Modification
SAP has released security updates to address a critical flaw within the NetWeaver Application Server ABAP.
Critical SharePoint Authentication Bypass Enables Unauthenticated Remote Code Execution via Network Exploitation
A critical authentication bypass in Microsoft SharePoint allows attackers to circumvent security features over a network.
Public exploits for Firefox critical vulnerabilities drive urgent browser security updates
Mozilla has released patches for two critical Firefox vulnerabilities that already have public exploit code available.
Three zero-day vulnerabilities exploited in the wild require immediate Microsoft security updates
Microsoft's July 2026 Patch Tuesday addresses a record 570 flaws, including three zero-day vulnerabilities.
Prompt injection in Flowise CSV Agents enables remote code execution via Python scripts
A critical vulnerability in the Flowise `CSV_Agents` class allows unauthenticated attackers to execute arbitrary code on the host server via prompt injection.
Critical vulnerabilities in Ubiquiti UniFi products allow for unauthorized access and remote control
A critical improper access control vulnerability in the Ubiquiti UniFi Connect Application allows an attacker to execute arbitrary commands on a host device.
IRIS C2 offers seven million dollars for high value zero day exploits
A new offensive cybersecurity startup called IRIS C2 is attempting to acquire high-value zero-day exploits with payouts reaching $7 million.
Langflow authorization bypass allows attackers to execute user flows and harvest credentials
Attackers are exploiting an authorization bypass in Langflow to execute user flows and harvest sensitive credentials.
Undocumented Tenda firmware backdoor allows unauthorized administrative access via specific password bypass
A critical undocumented backdoor has been discovered in multiple Tenda firmware versions, allowing anyone with a specific password to bypass standard login procedures.
UNK_MassTraction exploits Roundcube vulnerabilities to target university physics and engineering departments
A suspected China-aligned threat group, tracked as UNK_MassTraction, is targeting physics and engineering departments at US and Canadian universities.
Attackers exploit maximum severity ColdFusion flaw to execute arbitrary code on target systems
Attackers are actively exploiting a maximum-severity path traversal vulnerability in Adobe ColdFusion to execute arbitrary code.
Out of bounds write vulnerability in Labcenter Proteus enables remote code execution
A high-severity out-of-bounds write flaw in Labcenter Proteus can lead to full code execution. Attackers need local access or user interaction to trigger the vulnerability.
Zero-click XSS vulnerability in Roundcube webmail allows attackers to hijack user sessions
A critical zero-click XSS vulnerability in Roundcube webmail enables attackers to hijack user sessions and steal email content.
Attackers can bypass authentication to gain direct access to BeyondTrust remote support appliances
🚨 A critical authentication bypass in BeyondTrust Remote Support and Privileged Remote Access allows attackers to jump directly into the appliance.
Attackers exploit critical path traversal vulnerabilities in Adobe ColdFusion for remote code execution
Critical path traversal flaws in Adobe ColdFusion are being actively exploited to achieve remote code execution.
Cisco patches ClamAV vulnerabilities causing denial of service and unauthorized file reads
Cisco has issued critical updates to address multiple ClamAV vulnerabilities that can trigger denial of service (DoS) on Windows endpoints and a file read vulnerability in Catalyst Center.
Attackers exploit Microsoft SharePoint deserialization flaw to achieve remote code execution
Attackers are actively exploiting a high-severity deserialization flaw in Microsoft SharePoint to execute code remotely.
Unauthenticated attackers can remotely control Gardyn IoT devices via critical command execution flaw
Gardyn has released urgent firmware updates to address a critical vulnerability that allows unauthenticated users to take remote control of Home and Studio devices.
Unauthenticated attackers exploit XML parser flaw to leak memory from NetScaler appliances
Attackers are actively probing NetScaler appliances to trigger memory disclosure via a new XML parser flaw.
Malicious AI agents can escape sandboxes to execute commands via Cursor editor flaws
Two critical vulnerabilities in the Cursor AI code editor allow malicious agents to escape their terminal sandbox and write arbitrary files outside the intended workspace.
Unauthenticated attackers can execute remote commands on Progress Kemp LoadMaster appliances via API flaw
🚨 Critical command injection vulnerability found in Progress LoadMaster appliances. An unauthenticated attacker can execute arbitrary commands on the device via its API.
Citrix NetScaler Patch Addresses Six Flaws, Including Critical Memory Overread Vulnerability
Citrix has patched six vulnerabilities in its NetScaler ADC and Gateway products, with one critical flaw (CVE-2026-8451) posing a high risk of memory overread due to insufficient input validation.
Critical Flaws in StoneFly Storage Allow Unauthenticated Command Execution and Data Theft
StoneFly's Storage Concentrator has been hit with multiple critical vulnerabilities that allow attackers to execute arbitrary commands or extract sensitive data without authentication.
Critical Vulnerabilities in DCMTK Toolkit Threaten Medical Imaging Systems; Urgent Patch Required
The DCMTK Toolkit has been identified with multiple critical vulnerabilities that could allow attackers to manipulate file directories, leak memory, and crash worklist servers.
Critical Vulnerabilities Expose Delta Electronics DVP-12SE PLCs to Unauthorized Access
Delta Electronics' DVP-12SE PLCs have been exposed to critical vulnerabilities (CVE-2026-12818 and CVE-2026-12819) due to a lack of authentication in their Modbus TCP service, leading to unauthorized
Attackers Exploit Critical Oracle E-Business Suite Flaw for Unauthenticated System Takeover
A critical vulnerability in Oracle's E-Business Suite (CVE-2026-46817) has been exploited by attackers to take over systems without authentication.
Critical Remote Code Execution Flaw in libssh2 Exploited via SSH Packets
A critical vulnerability in libssh2 (CVE-2026-55200) has been exploited due to an out-of-bounds write issue.
Critical PTC Windchill PDMLink Flaw Actively Exploited in Supply Chains: Immediate Patch Urged
A critical vulnerability in PTC Windchill PDMLink has been actively exploited, posing significant risks to industrial supply chains.
Organizations Urged to Patch Exploited Software Vulnerabilities Amid Rising Threats
AI models have uncovered software vulnerabilities that pose significant risks to organizations. These findings highlight the need for proactive security measures against potential exploits.
Urgent Patch Advisory: Active Exploitation of Cisco and PTC Software Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for federal agencies to patch two critical vulnerabilities in Cisco Unified Communications Manager Serve
Critical Vulnerability in EVoke Systems' Charging Station Software Exposes Unauthorized Access Risks
EVoke Systems' Charging Station Management Software is critically vulnerable due to inadequate authentication mechanisms in its WebSocket endpoints.
Critical Vulnerability in Yokogawa Products Exposes Sensitive Configuration Data
A critical vulnerability in Yokogawa Electric Corporation's FAST/TOOLS and CI Server products has been disclosed.
Critical Ubiquiti and Lantronix Flaws Actively Exploited: Full System Control at Risk
CISA has issued a warning about active exploitation of critical vulnerabilities in Ubiquiti UniFi OS and Lantronix EDS5000 servers.
Active Exploitation of High-Severity SSRF Flaw in Cisco Unified CM Threatens Root Access
Cisco Unified Communications Manager is facing active exploitation of a high-severity SSRF vulnerability (CVE-2026-20230) that could allow attackers to achieve root privileges.
Hardware Vulnerability in iPhones and Apple Watches Allows Low-Level Code Execution
A new exploit named Usbliter8 targets Apple's SecureROM in iPhones with A12 and A13 chips and Apple Watches with S4 and S5 chips.
Critical Vulnerability Exposes Paperclip Instances to Remote Code Execution Attacks
An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration.
Federal Agencies Urged to Patch Splunk Enterprise Vulnerability by Sunday Amid Active Exploitation Risks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to patch a critical vulnerability in Splunk Enterprise by Sunday.
Critical Remote Code Execution Flaw Threatens AVer PTC Cameras: Immediate Patching Required
AVer PTC cameras are under threat from a critical vulnerability (CVSS 9.8) allowing remote code execution through improper input validation.
High-Severity Code Execution Flaw in AzeoTech DAQFactory Compromises Multiple Versions
AzeoTech's DAQFactory has been compromised through a high-severity Type Confusion vulnerability (CVE-2026-12390), allowing attackers to execute code via specially crafted .ctl files.
Nearby Attackers Can Spy via Microphone Due to Airoha Bluetooth SDK Flaws
Airoha Technology Corp. has disclosed three high-severity vulnerabilities in its Bluetooth audio SDK affecting the AB156x to AB159x series chipsets.
CISA Urges Federal Agencies to Patch Exploited Joomla Plugin Vulnerability by Friday
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability in the Widget Factory Joomla Content Editor plugin by Friday.
Attackers Exploit Critical Fortinet FortiSandbox Flaws for Unauthorized Code Execution
Critical vulnerabilities in Fortinet's FortiSandbox have been exploited by attackers, allowing unauthorized code execution.
Critical Vulnerabilities in Joomla and LiteSpeed Lead to Active Exploitation, Urging Immediate Updates
Joomla Content Editor (JCE) and LiteSpeed's cPanel plugin are under attack due to critical vulnerabilities allowing arbitrary file uploads and privilege escalation.
Unauthenticated File Manipulation Flaw in Splunk Enterprise Exposes Critical Risk
A critical vulnerability in Splunk Enterprise allows unauthenticated users to create or truncate arbitrary files through the PostgreSQL sidecar service endpoint.
U.S. CISA Mandates Immediate Patching of Exploited Ivanti Sentry Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch an actively exploited Ivanti Sentry vulnerability within three days due to its severe risk of
GreatXML Exploit Bypasses BitLocker via Microsoft Defender's Offline Scan
A newly disclosed exploit named GreatXML allows attackers to bypass Windows BitLocker encryption by exploiting a vulnerability in Microsoft Defender's offline scan functionality.
Microsoft Fixes Critical Zero-Days Allowing SYSTEM Privileges and BitLocker Bypass
Microsoft recently patched three zero-day vulnerabilities-GreenPlasma, MiniPlasma, and YellowKey-that could allow attackers to gain SYSTEM privileges or bypass BitLocker protection on Windows systems.
Remote Code Execution and Unauthorized Admin Account Creation in Ivanti Sentry Expose Critical Security Risks
Critical vulnerabilities in Ivanti Sentry have been disclosed, allowing remote unauthenticated attackers to execute arbitrary commands with root privileges (CVE-2026-10520) and create administrative a
Unauthenticated Access Vulnerability Patched by ServiceNow After Anomalous Activity Detected
ServiceNow has patched a vulnerability that allowed unauthenticated users to access more than intended in certain circumstances.
Unpatched Fortinet Flaw Enables Arbitrary Code Execution for Attackers
A critical vulnerability in Fortinet's FortiSandbox allows unauthenticated attackers to execute arbitrary commands via crafted HTTP requests.
Actively Exploited Arista EOS Vulnerability Threatens High-Performance Switches, No Patch Planned
A vulnerability in Arista's Extensible Operating System (EOS) has been actively exploited without a planned patch.
Critical Remote Code Execution Flaw Exposes Unpatched Veeam Backup Servers to Cyber Threats
A critical vulnerability in Veeam Backup & Replication (CVE-2026-44963) allows remote code execution on domain-joined backup servers.
Microsoft Addresses Three Zero-Day Vulnerabilities in June 2026 Patch Tuesday: Critical Windows Security Updates Released
Microsoft's June 2026 Patch Tuesday addressed three publicly disclosed zero-day vulnerabilities across Windows systems.
Zero-Day "RoguePlanet" Exploit in Microsoft Defender Grants SYSTEM Privileges on Patched Windows Systems
A new zero-day vulnerability named "RoguePlanet" in Microsoft Defender has been disclosed by a security researcher, allowing attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows
CISA Catalogs Exploited Vulnerabilities in AI and Security Products Amid Active Attacks
CISA has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-42271 in BerriAI's LiteLLM and CVE-2026-50751 in Check Point's Quantum Security Gateway.
Critical Zero-Day in Chrome Exploited: Immediate Browser Updates Urged
Google has patched a critical zero-day vulnerability in Chrome (CVE-2026-11645) that allowed attackers to execute arbitrary code within the browser's sandbox.
Google Fixes Fifth Zero-Day in Chrome: Arbitrary Code Execution via JavaScript Engine Flaw
Google has patched its fifth Chrome zero-day vulnerability this year, identified as CVE-2026-11645.
Critical SolarWinds Serv-U Vulnerability Exploited: Immediate Patching Urged by CISA
The US cybersecurity agency CISA has added a recently patched SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities catalog.
AI Model Reveals 21 Zero-Day Vulnerabilities Across Software Products
An AI model has identified 21 zero-day vulnerabilities across various software products.
WordPress Sites Compromised via Everest Forms Pro Vulnerability
Hackers are exploiting a critical vulnerability in the Everest Forms Pro plugin for WordPress (CVE-2026-3300), allowing them to execute arbitrary code on affected servers.
Active Exploitation of High-Severity SolarWinds Serv-U Flaw Urges Immediate Remediation
SolarWinds Serv-U is under active exploitation due to a high-severity vulnerability (CVE-2026-28318) that allows attackers to crash the service without authentication.
Cisco's SD-WAN Zero-Day Exploited: High-Severity Flaw Allows Root Command Execution
Cisco's Catalyst SD-WAN Manager is facing a high-severity vulnerability (CVE-2026-20245) actively exploited in the wild.
Critical Mirasvit Magento Flaw Enables Arbitrary Code Execution on Thousands of Stores
A critical vulnerability in the Mirasvit Full Page Cache Warmer for Magento 2 has been actively exploited to execute arbitrary code on servers running Magento and Adobe Commerce.
Stack Overflow Flaw in libexpat Library Puts Systems at Risk of DoS and Memory Corruption
A stack overflow vulnerability in the libexpat library (CVE-2024-8176) has been disclosed, affecting Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP1 among others.
VS Code Zero-Day Exposes GitHub Tokens to Theft via Malicious Links
A zero-day vulnerability in Visual Studio Code (VS Code) allows attackers to steal GitHub OAuth tokens with just one click.
Actively Exploited Linux and Android Flaws Prompt Urgent Patching by CISA
Two vulnerabilities have been actively exploited: a Linux kernel flaw allowing unexpected namespace isolation bypasses (CVE-2022-0492) and an Android issue enabling local privilege escalation without
Critical Oracle WebLogic Flaw Enables Unauthorized Data Access; Urgent Patching Recommended
An unauthenticated vulnerability in Oracle WebLogic Server has been exploited in the wild, allowing attackers to gain unauthorized access to critical data.
Critical Zero-Days Expose Acer Wave 7 Routers to Credential Theft and Backdoor Access
Acer's Wave 7 mesh routers are under threat from two critical zero-day vulnerabilities that could allow attackers to access plaintext credentials and gain persistent backdoor access.
Hackers Exploit Critical WordPress Plugin Flaw for Admin Account Takeovers
A critical vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress has been actively exploited by hackers to hijack user accounts, including admin accounts.
Microsoft Faces Legal Threats After Public Disclosure of Exploited Zero-Days
A researcher known as Nightmare Eclipse publicly disclosed several unpatched Microsoft vulnerabilities, leading to legal threats from Microsoft.
Palo Alto GlobalProtect CVE-2026-0257 Is No Longer Theoretical, Exploitation Has Reached Unpatched VPN Edges
CVE-2026-0257 is a PAN-OS GlobalProtect authentication bypass that can let an unauthenticated attacker establish an unauthorized VPN connection when authentication override is configured unsafely.
Windows 10 Snipping Tool Vulnerability Enables Network Spoofing by Attackers
An unpatched vulnerability in Microsoft's Windows 10 Version 1607 Snipping Tool allows unauthorized actors to spoof over a network, posing medium severity risks.
Windows Netlogon CVE-2026-41089 Moves From Patch Tuesday Priority to Active Exploitation Risk
CVE-2026-41089 is a critical Windows Netlogon flaw that can let an unauthenticated attacker execute code over the network against vulnerable Windows Server domain controllers.
Microsoft Mitigates YellowKey BitLocker Bypass (CVE-2026-45585)
Quick one: Microsoft patched a BitLocker bypass flaw, CVE-2026-45585, with a mitigation after a zero-day exploit was disclosed. Defenders should verify if systems are running patched versions and monitor for unusual BitL