PROBABLYPWNED
VD

Vulnerability Desk

Vulnerabilities

The Vulnerability Desk tracks CVE disclosures, zero-days, exploited-in-the-wild flaws, and vendor patches, translating technical advisories into actionable guidance for defenders.

CVE analysiszero-daysCISA KEV trackingpatch guidance

Articles from the Vulnerability Desk(309)

Agentjacking Hijacks AI Coding Agents via Sentry MCP Injection
Vulnerabilities4 min read

Agentjacking Hijacks AI Coding Agents via Sentry MCP Injection

Researchers at Tenet Security discovered Agentjacking, an attack that tricks AI coding assistants like Claude Code and Cursor into executing arbitrary code through malicious Sentry error events.

Vulnerability DeskJun 14, 2026
Check Point VPN PoC Drops as Exploitation Intensifies
Vulnerabilities4 min read

Check Point VPN PoC Drops as Exploitation Intensifies

WatchTowr Labs published technical details and exploit code for CVE-2026-50751, the auth bypass flaw already used by Qilin ransomware. TCP 443 bypass works too.

Vulnerability DeskJun 13, 2026
Arista Refuses to Patch Exploited Flaw Added to CISA KEV
Vulnerabilities3 min read

Arista Refuses to Patch Exploited Flaw Added to CISA KEV

CVE-2026-7473 lets attackers bypass tunnel security controls on Arista network devices. CISA added it to KEV—but Arista says patching would 'break existing configurations.'

Vulnerability DeskJun 11, 2026
ShinyHunters Breaches 100+ Orgs via Oracle PeopleSoft RCE
Vulnerabilities3 min read

ShinyHunters Breaches 100+ Orgs via Oracle PeopleSoft RCE

Oracle issues emergency patch for CVE-2026-35273 (CVSS 9.8) as ShinyHunters claims to have stolen data from 300 PeopleSoft instances. Nottingham University among confirmed victims.

Vulnerability DeskJun 11, 2026
RoguePlanet Zero-Day Bypasses Fully-Patched Windows Defender
Vulnerabilities3 min read

RoguePlanet Zero-Day Bypasses Fully-Patched Windows Defender

Security researcher Nightmare Eclipse releases fourth Microsoft Defender zero-day in months, granting SYSTEM privileges on patched Windows 10 and 11 systems. Here's what defenders need to know.

Vulnerability DeskJun 11, 2026
Microsoft Patches 206 Flaws Including Wormable Kernel RCE
Vulnerabilities4 min read

Microsoft Patches 206 Flaws Including Wormable Kernel RCE

Microsoft's record-breaking June 2026 Patch Tuesday fixes 206 vulnerabilities including CVE-2026-45657, a CVSS 9.8 wormable kernel flaw allowing remote code execution without authentication.

Vulnerability DeskJun 10, 2026
WordPress Plugin RCE Under Mass Exploitation — 29K Attacks
Vulnerabilities4 min read

WordPress Plugin RCE Under Mass Exploitation — 29K Attacks

CVE-2026-3300 in Everest Forms Pro allows unauthenticated attackers to execute PHP code via eval() injection. Over 29,300 exploit attempts blocked since April despite patch availability.

Vulnerability DeskJun 6, 2026
VS Code Flaw Enabled One-Click GitHub Token Theft
Vulnerabilities4 min read

VS Code Flaw Enabled One-Click GitHub Token Theft

A vulnerability in GitHub.dev allowed attackers to steal GitHub OAuth tokens with full repo access via a single malicious link. Microsoft patched the flaw within 24 hours.

Vulnerability DeskJun 5, 2026
CIFSwitch: 19-Year Linux Kernel Flaw Grants Root Access
Vulnerabilities3 min read

CIFSwitch: 19-Year Linux Kernel Flaw Grants Root Access

A SpaceX security engineer discovered a privilege escalation bug hidden in the Linux kernel since 2007. Proof-of-concept exploit published—major distributions now patching.

Vulnerability DeskJun 2, 2026
Flowise One-Click RCE — Import a Chatflow, Lose Your Server
Vulnerabilities3 min read

Flowise One-Click RCE — Import a Chatflow, Lose Your Server

CVE-2026-40933 (CVSS 9.9) allows attackers to compromise self-hosted Flowise AI agent builders by tricking users into importing a malicious chatflow. The payload executes during import without user action.

Vulnerability DeskMay 31, 2026
ChatGPhish Turns ChatGPT Web Summaries Into Phishing Delivery
Vulnerabilities4 min read

ChatGPhish Turns ChatGPT Web Summaries Into Phishing Delivery

Researchers discover ChatGPT's Markdown rendering trusts attacker-controlled content from summarized pages, enabling phishing URLs, IP exfiltration, and fake security alerts inside the AI interface.

Vulnerability DeskMay 31, 2026
Gitea Flaw Exposed Private Container Images for 4 Years
Vulnerabilities3 min read

Gitea Flaw Exposed Private Container Images for 4 Years

CVE-2026-27771 let attackers pull private container images without authentication. Over 30,000 Gitea deployments affected across healthcare, aerospace, and retail. Update to 1.26.2 now.

Vulnerability DeskMay 28, 2026
Trend Micro Apex One Zero-Day Added to CISA KEV
Vulnerabilities3 min read

Trend Micro Apex One Zero-Day Added to CISA KEV

CVE-2026-34926 lets attackers inject malicious code into Apex One servers and deploy it to all connected endpoint agents. CISA confirms active exploitation with June 4 federal deadline.

Vulnerability DeskMay 24, 2026
MuddyWater Exploits Langflow Flaw for Initial Access
Vulnerabilities3 min read

MuddyWater Exploits Langflow Flaw for Initial Access

CISA adds CVE-2025-34291 to KEV after Iranian APT MuddyWater weaponizes the CORS/CSRF chain for account takeover and RCE. CVSS 9.4 flaw requires only a malicious link click.

Vulnerability DeskMay 24, 2026
Apache HTTP/2 Double-Free Enables DoS and RCE
Vulnerabilities4 min read

Apache HTTP/2 Double-Free Enables DoS and RCE

CVE-2026-23918 in Apache HTTP Server 2.4.66 lets attackers crash workers trivially or achieve remote code execution through a double-free in mod_http2. Upgrade to 2.4.67 immediately.

Vulnerability DeskMay 23, 2026
Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS
Vulnerabilities4 min read

Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS

Ubiquiti releases emergency patches for three maximum-severity vulnerabilities in UniFi OS that allow unauthenticated remote attackers to take full control of network appliances. 100,000 devices exposed.

Vulnerability DeskMay 23, 2026
CISA KEV Adds 7 Flaws Including Exploited Defender Bugs
Vulnerabilities4 min read

CISA KEV Adds 7 Flaws Including Exploited Defender Bugs

CISA's May 20 KEV update includes two actively exploited Microsoft Defender vulnerabilities and five legacy flaws from 2008-2010. Federal agencies have until June 3 to patch.

Vulnerability DeskMay 21, 2026
Drupal Warns of Highly Critical Flaw — Patches Due Today
Vulnerabilities3 min read

Drupal Warns of Highly Critical Flaw — Patches Due Today

Drupal releases patches for a highly critical vulnerability (severity 20/25) affecting all supported versions. Exploits may emerge within hours—administrators should update between 5-9pm UTC today.

Vulnerability DeskMay 20, 2026
SEPPMail Gateway Flaws Enable Complete Mail System Takeover
Vulnerabilities4 min read

SEPPMail Gateway Flaws Enable Complete Mail System Takeover

Seven vulnerabilities including CVE-2026-2743 (CVSS 10.0) allow unauthenticated attackers to compromise SEPPMail secure email gateways, read all traffic, and establish persistent access. Patch to 15.0.4 immediately.

Vulnerability DeskMay 20, 2026
24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026
Vulnerabilities4 min read

24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026

Security researchers exploited Windows 11, Microsoft Edge, Red Hat Linux, and multiple AI platforms on the first day of Pwn2Own Berlin 2026, earning $523,000 for 24 unique zero-day vulnerabilities.

Vulnerability DeskMay 14, 2026
Microsoft Fixes 120 Flaws in May Patch Tuesday, 17 Critical
Vulnerabilities3 min read

Microsoft Fixes 120 Flaws in May Patch Tuesday, 17 Critical

Microsoft's May 2026 Patch Tuesday addresses 120 vulnerabilities including 17 critical RCE flaws. No zero-days, but Word preview pane attacks and Netlogon bugs demand immediate attention.

Vulnerability DeskMay 13, 2026
cPanel Ships Second Emergency Patch in 10 Days: Three New CVEs
Vulnerabilities3 min read

cPanel Ships Second Emergency Patch in 10 Days: Three New CVEs

cPanel releases emergency fixes for CVE-2026-29201, 29202, and 29203—including file read, code execution, and privilege escalation flaws. Comes days after 44,000 servers were hit by ransomware.

Vulnerability DeskMay 10, 2026
12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover
Vulnerabilities4 min read

12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover

Security researchers disclosed 12 sandbox escape vulnerabilities in vm2, including three with CVSS 10.0 scores. The popular JavaScript isolation library can no longer be trusted to contain untrusted code.

Vulnerability DeskMay 8, 2026
APT28 Exploiting Windows Shell Flaw to Steal NTLM Credentials
Vulnerabilities5 min read

APT28 Exploiting Windows Shell Flaw to Steal NTLM Credentials

Russian state hackers weaponize CVE-2026-32202, an incomplete patch for Windows Shell that enables zero-click NTLM hash theft. Microsoft confirms active exploitation after Akamai discovers the bypass.

Vulnerability DeskApr 28, 2026
PhantomRPC: Unpatched Windows Flaw Enables SYSTEM Escalation
Vulnerabilities5 min read

PhantomRPC: Unpatched Windows Flaw Enables SYSTEM Escalation

Kaspersky discloses PhantomRPC, an architectural Windows RPC vulnerability enabling SYSTEM-level privilege escalation across all Windows versions. Microsoft declined to patch despite five exploitation paths.

Vulnerability DeskApr 27, 2026
One Researcher, Four Critical RCE Bugs in AI Frameworks
Vulnerabilities5 min read

One Researcher, Four Critical RCE Bugs in AI Frameworks

Security researcher Valentin Lobstein discovers CVSS 9.8 pickle deserialization vulnerabilities in LeRobot, ktransformers, and LightLLM. ML frameworks using pickle for network serialization create widespread attack surface.

Vulnerability DeskApr 26, 2026
LMDeploy SSRF Exploited 12 Hours After Disclosure
Vulnerabilities4 min read

LMDeploy SSRF Exploited 12 Hours After Disclosure

CVE-2026-33626 in LMDeploy AI toolkit was weaponized within 12 hours of publication, targeting AWS credentials and internal services. Patch to v0.12.3 immediately.

Vulnerability DeskApr 24, 2026
Defender Zero-Days Hit Live Attacks - Two Still Unpatched
Vulnerabilities4 min read

Defender Zero-Days Hit Live Attacks - Two Still Unpatched

Huntress confirms hands-on-keyboard exploitation of all three Windows Defender zero-days. Microsoft patched BlueHammer, but RedSun and UnDefend remain unpatched as attackers chain them for SYSTEM access.

Vulnerability DeskApr 23, 2026
Cisco Webex SSO Flaw Let Attackers Impersonate Any User
Vulnerabilities4 min read

Cisco Webex SSO Flaw Let Attackers Impersonate Any User

CVE-2026-20184 (CVSS 9.8) in Cisco Webex Services allowed unauthenticated attackers to impersonate any user through SSO certificate validation bypass. Cloud service already patched.

Vulnerability DeskApr 22, 2026
FortiSandbox Auth Bypass and RCE Flaws Score CVSS 9.1
Vulnerabilities3 min read

FortiSandbox Auth Bypass and RCE Flaws Score CVSS 9.1

Fortinet patches two critical FortiSandbox vulnerabilities allowing unauthenticated attackers to bypass authentication and execute code. Upgrade to 4.4.9 or 5.0.6 immediately.

Vulnerability DeskApr 18, 2026
RedSun: Second Windows Defender Zero-Day Drops in Two Weeks
Vulnerabilities4 min read

RedSun: Second Windows Defender Zero-Day Drops in Two Weeks

Frustrated researcher 'Chaotic Eclipse' releases RedSun, another Windows Defender privilege escalation exploit granting SYSTEM access. Microsoft has not yet patched this second zero-day.

Vulnerability DeskApr 17, 2026
13-Year-Old ActiveMQ Bug Found by Claude AI Enables RCE
Vulnerabilities4 min read

13-Year-Old ActiveMQ Bug Found by Claude AI Enables RCE

CVE-2026-34197 exposes Apache ActiveMQ to remote code execution via the Jolokia API. Horizon3 researcher used Claude to uncover the flaw in under 10 minutes. Patch now.

Vulnerability DeskApr 8, 2026
GPUBreach Exploits GDDR6 Rowhammer for Full System Takeover
Vulnerabilities3 min read

GPUBreach Exploits GDDR6 Rowhammer for Full System Takeover

University of Toronto researchers demonstrate GPUBreach, a GPU rowhammer attack that bypasses IOMMU protections to achieve root access on systems with NVIDIA GPUs. Consumer GPUs remain unmitigated.

Vulnerability DeskApr 7, 2026
PraisonAI Sandbox Bypass Scores Perfect CVSS 10
Vulnerabilities3 min read

PraisonAI Sandbox Bypass Scores Perfect CVSS 10

CVE-2026-34938 lets attackers escape PraisonAI's three-layer Python sandbox to execute arbitrary OS commands. CVSS 10 — patch to version 1.5.90 immediately.

Vulnerability DeskApr 4, 2026
Azure Kubernetes CVE-2026-33105 Hits CVSS 10.0
Vulnerabilities4 min read

Azure Kubernetes CVE-2026-33105 Hits CVSS 10.0

Microsoft Azure Kubernetes Service has a critical auth bypass (CVE-2026-33105) with a perfect CVSS 10.0 score. Unauthenticated attackers can escalate to cluster admin—patch now.

Vulnerability DeskApr 3, 2026
Google Patches Fourth Chrome Zero-Day of 2026
Vulnerabilities4 min read

Google Patches Fourth Chrome Zero-Day of 2026

CVE-2026-5281 exploited in the wild targets Dawn WebGPU implementation. Google rushes emergency patch as Chrome zero-days accelerate in 2026.

Vulnerability DeskApr 1, 2026
n8n Merge Node Flaw Exposes 615K Instances to RCE
Vulnerabilities4 min read

n8n Merge Node Flaw Exposes 615K Instances to RCE

CVE-2026-33660 (CVSS 9.4) lets authenticated users escape n8n's AlaSQL sandbox via the Merge node. Over 615,000 public instances potentially vulnerable.

Vulnerability DeskMar 31, 2026
800K Sites at Risk from Smart Slider 3 File Read Flaw
Vulnerabilities4 min read

800K Sites at Risk from Smart Slider 3 File Read Flaw

CVE-2026-3098 lets subscribers read wp-config.php and any server file. Amelia Booking Pro also patched for admin password reset bug. Update these WordPress plugins now.

Vulnerability DeskMar 29, 2026
LangChain Flaws Expose Files, Secrets, and Databases
Vulnerabilities3 min read

LangChain Flaws Expose Files, Secrets, and Databases

Three vulnerabilities in LangChain and LangGraph expose filesystems, environment secrets, and conversation histories. CVE-2026-34070 enables path traversal. Patches available now.

Vulnerability DeskMar 28, 2026
Four Critical n8n Flaws Enable Unauthenticated RCE
Vulnerabilities3 min read

Four Critical n8n Flaws Enable Unauthenticated RCE

n8n patches CVE-2026-27577, CVE-2026-27493, and two more sandbox escapes. One flaw allows unauthenticated attackers to execute commands via public form endpoints.

Vulnerability DeskMar 24, 2026
Citrix NetScaler Memory Leak Exposes SAML SSO Secrets
Vulnerabilities3 min read

Citrix NetScaler Memory Leak Exposes SAML SSO Secrets

CVE-2026-3055 (CVSS 9.3) lets unauthenticated attackers read sensitive data from NetScaler memory. Affects appliances configured as SAML Identity Providers—patch now.

Vulnerability DeskMar 24, 2026
Quest KACE SMA CVSS 10.0 Flaw Exploited in the Wild
Vulnerabilities3 min read

Quest KACE SMA CVSS 10.0 Flaw Exploited in the Wild

Attackers exploiting CVE-2025-32975 authentication bypass in Quest KACE to hijack admin accounts and deploy credential harvesters. Patched in May 2025—many remain exposed.

Vulnerability DeskMar 24, 2026
AVideo RCE Chain Gives Attackers Full Server Access Without Auth
Vulnerabilities3 min read

AVideo RCE Chain Gives Attackers Full Server Access Without Auth

Three vulnerabilities in AVideo's CloneSite plugin chain together for unauthenticated remote code execution. CVE-2026-33478 has no patch available as attackers can extract admin credentials and inject OS commands.

Vulnerability DeskMar 23, 2026
Ubuntu Desktop Flaw Lets Local Users Escalate to Root
Vulnerabilities3 min read

Ubuntu Desktop Flaw Lets Local Users Escalate to Root

CVE-2026-3888 exploits timing race between snap-confine and systemd-tmpfiles to grant root access on Ubuntu Desktop 24.04+. Qualys researchers demonstrate full privilege escalation.

Vulnerability DeskMar 23, 2026
PolyShell Flaw Exposes All Magento Stores to RCE Attacks
Vulnerabilities4 min read

PolyShell Flaw Exposes All Magento Stores to RCE Attacks

Unrestricted file upload in Magento and Adobe Commerce REST API allows unauthenticated attackers to upload executable files. No isolated patch available for production versions.

Vulnerability DeskMar 21, 2026
CISA Adds Apple, Craft CMS, Laravel Bugs to KEV Catalog
Vulnerabilities4 min read

CISA Adds Apple, Craft CMS, Laravel Bugs to KEV Catalog

Five vulnerabilities under active exploitation added to CISA's KEV catalog. Federal agencies must patch by April 3, 2026. Includes three Apple kernel flaws and Laravel RCE.

Vulnerability DeskMar 21, 2026
Langflow RCE Exploited Within 20 Hours of Disclosure
Vulnerabilities4 min read

Langflow RCE Exploited Within 20 Hours of Disclosure

CVE-2026-33017 (CVSS 9.3) lets attackers execute arbitrary Python code on Langflow AI pipelines without authentication. Exploitation began before any PoC existed.

Vulnerability DeskMar 21, 2026
Atop EHG2408 Industrial Switch RCE Hits CVSS 9.3
Vulnerabilities3 min read

Atop EHG2408 Industrial Switch RCE Hits CVSS 9.3

CVE-2026-3823 allows unauthenticated attackers to execute code on Atop Technologies industrial switches. Firmware 3.36 patches the critical buffer overflow.

Vulnerability DeskMar 9, 2026
Delta Electronics COMMGR2 Flaws Score CVSS 9.8
Vulnerabilities3 min read

Delta Electronics COMMGR2 Flaws Score CVSS 9.8

Two critical vulnerabilities in Delta Electronics COMMGR2 enable remote code execution without authentication. ICS operators should patch to v2.11.1 immediately.

Vulnerability DeskMar 9, 2026
Caddy Server Flaw Lets Users Impersonate Admins
Vulnerabilities4 min read

Caddy Server Flaw Lets Users Impersonate Admins

CVE-2026-30851 in Caddy's forward_auth module enables identity injection and privilege escalation. Any valid user can impersonate administrators. Update to 2.11.2.

Vulnerability DeskMar 8, 2026
WeKnora AI Framework Hit with Twin CVSS 9.9 RCE Flaws
Vulnerabilities4 min read

WeKnora AI Framework Hit with Twin CVSS 9.9 RCE Flaws

Critical command injection and SQL bypass vulnerabilities in Tencent's WeKnora LLM framework allow unauthenticated RCE. Patch to versions 0.2.10 and 0.2.12 now.

Vulnerability DeskMar 8, 2026
Cisco FMC RADIUS Flaw Scores CVSS 10 for Pre-Auth RCE
Vulnerabilities4 min read

Cisco FMC RADIUS Flaw Scores CVSS 10 for Pre-Auth RCE

CVE-2025-20265 in Cisco Secure Firewall Management Center allows unauthenticated attackers to execute commands as root via RADIUS authentication. Patch immediately.

Vulnerability DeskMar 4, 2026
Android March Patch Fixes Qualcomm Zero-Day Under Attack
Vulnerabilities5 min read

Android March Patch Fixes Qualcomm Zero-Day Under Attack

Google's March 2026 Android security update patches 129 vulnerabilities including CVE-2026-21385, a Qualcomm graphics flaw affecting 234 chipsets under active exploitation.

Vulnerability DeskMar 3, 2026
U-Office Force CVE-2026-3422 Enables Unauthenticated RCE
Vulnerabilities4 min read

U-Office Force CVE-2026-3422 Enables Unauthenticated RCE

Critical insecure deserialization vulnerability in U-Office Force allows remote attackers to execute arbitrary code without authentication. CVSS 9.8, no patch available yet.

Vulnerability DeskMar 2, 2026
CISA Orders Feds to Patch Dell Flaw Within 3 Days
Vulnerabilities4 min read

CISA Orders Feds to Patch Dell Flaw Within 3 Days

Federal agencies must patch CVE-2026-22769 by Saturday after CISA confirms Chinese hackers exploited the Dell RecoverPoint vulnerability since 2024.

Vulnerability DeskFeb 19, 2026
n8n Sandbox Escape CVE-2026-25049 Bypasses Prior Fix
Vulnerabilities3 min read

n8n Sandbox Escape CVE-2026-25049 Bypasses Prior Fix

New n8n RCE flaw bypasses December patch through type confusion. CVSS 9.4 vulnerability enables unauthenticated command execution via malicious workflows.

Vulnerability DeskFeb 15, 2026
BeyondTrust Pre-Auth RCE Exposes 11,000 Systems
Vulnerabilities3 min read

BeyondTrust Pre-Auth RCE Exposes 11,000 Systems

CVE-2026-1731 allows unauthenticated remote code execution on BeyondTrust Remote Support and Privileged Remote Access products. CVSS 9.9 vulnerability affects 11,000+ exposed instances.

Vulnerability DeskFeb 12, 2026
Microsoft Patches Six Zero-Days in February Patch Tuesday
Vulnerabilities4 min read

Microsoft Patches Six Zero-Days in February Patch Tuesday

Microsoft's February 2026 Patch Tuesday fixes 59 flaws including six actively exploited zero-days. CrowdStrike confirmed CVE-2026-21533 was used in attacks targeting US and Canada since December.

Vulnerability DeskFeb 12, 2026
SmarterMail Flaw Exploited in Ransomware Attacks
Vulnerabilities3 min read

SmarterMail Flaw Exploited in Ransomware Attacks

CVE-2026-24423 lets unauthenticated attackers execute OS commands on SmarterMail servers. CISA confirms active ransomware exploitation and sets a February 26 patch deadline.

Vulnerability DeskFeb 6, 2026
CISA Adds SolarWinds, Sangoma, GitLab Flaws to KEV
Vulnerabilities3 min read

CISA Adds SolarWinds, Sangoma, GitLab Flaws to KEV

Four actively exploited vulnerabilities added to CISA's catalog including SolarWinds Web Help Desk deserialization flaw with CVSS 9.8. Federal agencies have until February 6 to patch.

Vulnerability DeskFeb 4, 2026
Google Looker Flaws Let Attackers Hijack BI Servers
Vulnerabilities4 min read

Google Looker Flaws Let Attackers Hijack BI Servers

Tenable discloses 'LookOut' vulnerabilities in Google Looker enabling remote code execution and full database theft. Self-hosted deployments at 60,000+ organizations exposed.

Vulnerability DeskFeb 4, 2026
Redis RCE Exploit More Severe Than Initially Rated
Vulnerabilities3 min read

Redis RCE Exploit More Severe Than Initially Rated

JFrog researchers develop working remote code execution exploit for CVE-2025-62507, a stack buffer overflow in Redis discovered by Google's AI security agent.

Vulnerability DeskFeb 1, 2026
Iconics SCADA Flaw Allows System File Corruption
Vulnerabilities4 min read

Iconics SCADA Flaw Allows System File Corruption

CVE-2025-0921 enables privileged file system operations that can disrupt industrial control systems in automotive, energy, and manufacturing environments.

Vulnerability DeskFeb 1, 2026
Cisco ISE XXE Flaw Has Public PoC, Patch Now
Vulnerabilities3 min read

Cisco ISE XXE Flaw Has Public PoC, Patch Now

Cisco patches CVE-2026-20029, an XML external entity vulnerability in Identity Services Engine with proof-of-concept exploit code already publicly available.

Vulnerability DeskJan 31, 2026
OpenSSL Stack Overflow Enables Remote Code Execution
Vulnerabilities5 min read

OpenSSL Stack Overflow Enables Remote Code Execution

CVE-2025-15467 allows attackers to crash or compromise systems by sending malicious CMS messages. All AI-discovered in OpenSSL's largest coordinated security release.

Vulnerability DeskJan 29, 2026
SAP Patches CVSS 9.9 SQL Injection in January Update
Vulnerabilities4 min read

SAP Patches CVSS 9.9 SQL Injection in January Update

January 2026 Patch Day addresses 17 flaws including four HotNews vulnerabilities. CVE-2026-0501 allows authenticated attackers to compromise S/4HANA financial systems.

Vulnerability DeskJan 13, 2026
Cisco Patches ISE Flaw After Public PoC Exploit Emerges
Vulnerabilities3 min read

Cisco Patches ISE Flaw After Public PoC Exploit Emerges

CVE-2026-20029 lets authenticated admins read restricted system files through XML parsing weakness. Trend Micro ZDI researcher found the bug; no workarounds available.

Vulnerability DeskJan 11, 2026
Coolify Command Injection Flaws Grant Root Access
Vulnerabilities4 min read

Coolify Command Injection Flaws Grant Root Access

Five critical vulnerabilities in the self-hosting platform allow authenticated users to execute arbitrary commands as root. Over 52,000 instances are exposed globally.

Vulnerability DeskJan 10, 2026
Cisco Snort 3 Flaws Enable DoS and Data Leaks
Vulnerabilities3 min read

Cisco Snort 3 Flaws Enable DoS and Data Leaks

CVE-2026-20026 and CVE-2026-20027 allow remote attackers to crash Snort or extract sensitive data. No workarounds exist—patches are the only fix.

Vulnerability DeskJan 10, 2026
jsPDF Flaw Lets Attackers Embed Local Files in PDFs
Vulnerabilities4 min read

jsPDF Flaw Lets Attackers Embed Local Files in PDFs

CVE-2025-68428 enables path traversal in the popular JavaScript PDF library, allowing attackers to read arbitrary files from Node.js servers and exfiltrate them via generated documents.

Vulnerability DeskJan 9, 2026
Chrome Patches High-Severity WebView Policy Bypass
Vulnerabilities4 min read

Chrome Patches High-Severity WebView Policy Bypass

CVE-2026-0628 allowed malicious extensions to inject scripts into privileged pages through insufficient policy enforcement. Update to Chrome 143.0.7499.192.

Vulnerability DeskJan 7, 2026
IBM API Connect Auth Bypass Rated CVSS 9.8
Vulnerabilities4 min read

IBM API Connect Auth Bypass Rated CVSS 9.8

CVE-2025-13915 allows remote attackers to bypass authentication without credentials. Affects versions 10.0.8.0 through 10.0.8.5 and 10.0.11.0 used by major banks and airlines.

Vulnerability DeskJan 1, 2026
CVSS 10.0 Zero-Day Hits 70,000 XSpeeder Devices
Vulnerabilities4 min read

CVSS 10.0 Zero-Day Hits 70,000 XSpeeder Devices

CVE-2025-54322 enables unauthenticated root RCE on SD-WAN appliances and edge routers. Vendor has ignored seven months of disclosure attempts. No patch available.

Vulnerability DeskJan 1, 2026