PROBABLYPWNED
MC

Marcus Chen

Vulnerability Reporter

Covers CVE disclosures, zero-day vulnerabilities, and security patches across enterprise software for ProbablyPwned. Marcus brings eight years of experience in vulnerability research and penetration testing, having previously worked on red teams at two Fortune 500 companies. He translates technical advisories into actionable intelligence for defenders and maintains a particular focus on critical infrastructure vulnerabilities and vendor patch analysis. Marcus holds OSCP and GPEN certifications and regularly monitors CISA KEV additions and NVD disclosures.

vulnerability researchCVE analysispenetration testingpatch managementCISA KEV tracking

Articles by Marcus(106)

CISA Orders Feds to Patch Dell Flaw Within 3 Days
Vulnerabilities4 min read

CISA Orders Feds to Patch Dell Flaw Within 3 Days

Federal agencies must patch CVE-2026-22769 by Saturday after CISA confirms Chinese hackers exploited the Dell RecoverPoint vulnerability since 2024.

Marcus ChenFeb 19, 2026
BeyondTrust Pre-Auth RCE Exposes 11,000 Systems
Vulnerabilities3 min read

BeyondTrust Pre-Auth RCE Exposes 11,000 Systems

CVE-2026-1731 allows unauthenticated remote code execution on BeyondTrust Remote Support and Privileged Remote Access products. CVSS 9.9 vulnerability affects 11,000+ exposed instances.

Marcus ChenFeb 12, 2026
Microsoft Patches Six Zero-Days in February Patch Tuesday
Vulnerabilities4 min read

Microsoft Patches Six Zero-Days in February Patch Tuesday

Microsoft's February 2026 Patch Tuesday fixes 59 flaws including six actively exploited zero-days. CrowdStrike confirmed CVE-2026-21533 was used in attacks targeting US and Canada since December.

Marcus ChenFeb 12, 2026
SmarterMail Flaw Exploited in Ransomware Attacks
Vulnerabilities3 min read

SmarterMail Flaw Exploited in Ransomware Attacks

CVE-2026-24423 lets unauthenticated attackers execute OS commands on SmarterMail servers. CISA confirms active ransomware exploitation and sets a February 26 patch deadline.

Marcus ChenFeb 6, 2026
CISA Adds SolarWinds, Sangoma, GitLab Flaws to KEV
Vulnerabilities3 min read

CISA Adds SolarWinds, Sangoma, GitLab Flaws to KEV

Four actively exploited vulnerabilities added to CISA's catalog including SolarWinds Web Help Desk deserialization flaw with CVSS 9.8. Federal agencies have until February 6 to patch.

Marcus ChenFeb 4, 2026
Google Looker Flaws Let Attackers Hijack BI Servers
Vulnerabilities4 min read

Google Looker Flaws Let Attackers Hijack BI Servers

Tenable discloses 'LookOut' vulnerabilities in Google Looker enabling remote code execution and full database theft. Self-hosted deployments at 60,000+ organizations exposed.

Marcus ChenFeb 4, 2026
Redis RCE Exploit More Severe Than Initially Rated
Vulnerabilities3 min read

Redis RCE Exploit More Severe Than Initially Rated

JFrog researchers develop working remote code execution exploit for CVE-2025-62507, a stack buffer overflow in Redis discovered by Google's AI security agent.

Marcus ChenFeb 1, 2026
Iconics SCADA Flaw Allows System File Corruption
Vulnerabilities4 min read

Iconics SCADA Flaw Allows System File Corruption

CVE-2025-0921 enables privileged file system operations that can disrupt industrial control systems in automotive, energy, and manufacturing environments.

Marcus ChenFeb 1, 2026
Cisco ISE XXE Flaw Has Public PoC, Patch Now
Vulnerabilities3 min read

Cisco ISE XXE Flaw Has Public PoC, Patch Now

Cisco patches CVE-2026-20029, an XML external entity vulnerability in Identity Services Engine with proof-of-concept exploit code already publicly available.

Marcus ChenJan 31, 2026
OpenSSL Stack Overflow Enables Remote Code Execution
Vulnerabilities5 min read

OpenSSL Stack Overflow Enables Remote Code Execution

CVE-2025-15467 allows attackers to crash or compromise systems by sending malicious CMS messages. All AI-discovered in OpenSSL's largest coordinated security release.

Marcus ChenJan 29, 2026
Curl Ends Bug Bounty Program After AI Slop Floods Queue
Announcements3 min read

Curl Ends Bug Bounty Program After AI Slop Floods Queue

The ubiquitous command-line tool will stop accepting HackerOne submissions January 31. After $86K paid across 78 vulnerabilities, AI-generated noise made the program unsustainable.

Marcus ChenJan 25, 2026
SAP Patches CVSS 9.9 SQL Injection in January Update
Vulnerabilities4 min read

SAP Patches CVSS 9.9 SQL Injection in January Update

January 2026 Patch Day addresses 17 flaws including four HotNews vulnerabilities. CVE-2026-0501 allows authenticated attackers to compromise S/4HANA financial systems.

Marcus ChenJan 13, 2026
Coolify Command Injection Flaws Grant Root Access
Vulnerabilities4 min read

Coolify Command Injection Flaws Grant Root Access

Five critical vulnerabilities in the self-hosting platform allow authenticated users to execute arbitrary commands as root. Over 52,000 instances are exposed globally.

Marcus ChenJan 10, 2026
Cisco Snort 3 Flaws Enable DoS and Data Leaks
Vulnerabilities3 min read

Cisco Snort 3 Flaws Enable DoS and Data Leaks

CVE-2026-20026 and CVE-2026-20027 allow remote attackers to crash Snort or extract sensitive data. No workarounds exist—patches are the only fix.

Marcus ChenJan 10, 2026
jsPDF Flaw Lets Attackers Embed Local Files in PDFs
Vulnerabilities4 min read

jsPDF Flaw Lets Attackers Embed Local Files in PDFs

CVE-2025-68428 enables path traversal in the popular JavaScript PDF library, allowing attackers to read arbitrary files from Node.js servers and exfiltrate them via generated documents.

Marcus ChenJan 9, 2026
Chrome Patches High-Severity WebView Policy Bypass
Vulnerabilities4 min read

Chrome Patches High-Severity WebView Policy Bypass

CVE-2026-0628 allowed malicious extensions to inject scripts into privileged pages through insufficient policy enforcement. Update to Chrome 143.0.7499.192.

Marcus ChenJan 7, 2026
IBM API Connect Auth Bypass Rated CVSS 9.8
Vulnerabilities4 min read

IBM API Connect Auth Bypass Rated CVSS 9.8

CVE-2025-13915 allows remote attackers to bypass authentication without credentials. Affects versions 10.0.8.0 through 10.0.8.5 and 10.0.11.0 used by major banks and airlines.

Marcus ChenJan 1, 2026
CVSS 10.0 Zero-Day Hits 70,000 XSpeeder Devices
Vulnerabilities4 min read

CVSS 10.0 Zero-Day Hits 70,000 XSpeeder Devices

CVE-2025-54322 enables unauthenticated root RCE on SD-WAN appliances and edge routers. Vendor has ignored seven months of disclosure attempts. No patch available.

Marcus ChenJan 1, 2026