PROBABLYPWNED
Home/Vulnerabilities

Vulnerabilities

247 articles

24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026
Vulnerabilities4 min read

24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026

Security researchers exploited Windows 11, Microsoft Edge, Red Hat Linux, and multiple AI platforms on the first day of Pwn2Own Berlin 2026, earning $523,000 for 24 unique zero-day vulnerabilities.

Marcus ChenMay 14, 2026
12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover
Vulnerabilities4 min read

12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover

Security researchers disclosed 12 sandbox escape vulnerabilities in vm2, including three with CVSS 10.0 scores. The popular JavaScript isolation library can no longer be trusted to contain untrusted code.

Marcus ChenMay 8, 2026
APT28 Exploiting Windows Shell Flaw to Steal NTLM Credentials
Vulnerabilities5 min read

APT28 Exploiting Windows Shell Flaw to Steal NTLM Credentials

Russian state hackers weaponize CVE-2026-32202, an incomplete patch for Windows Shell that enables zero-click NTLM hash theft. Microsoft confirms active exploitation after Akamai discovers the bypass.

Marcus ChenApr 28, 2026
PhantomRPC: Unpatched Windows Flaw Enables SYSTEM Escalation
Vulnerabilities5 min read

PhantomRPC: Unpatched Windows Flaw Enables SYSTEM Escalation

Kaspersky discloses PhantomRPC, an architectural Windows RPC vulnerability enabling SYSTEM-level privilege escalation across all Windows versions. Microsoft declined to patch despite five exploitation paths.

Marcus ChenApr 27, 2026
One Researcher, Four Critical RCE Bugs in AI Frameworks
Vulnerabilities5 min read

One Researcher, Four Critical RCE Bugs in AI Frameworks

Security researcher Valentin Lobstein discovers CVSS 9.8 pickle deserialization vulnerabilities in LeRobot, ktransformers, and LightLLM. ML frameworks using pickle for network serialization create widespread attack surface.

Marcus ChenApr 26, 2026
LMDeploy SSRF Exploited 12 Hours After Disclosure
Vulnerabilities4 min read

LMDeploy SSRF Exploited 12 Hours After Disclosure

CVE-2026-33626 in LMDeploy AI toolkit was weaponized within 12 hours of publication, targeting AWS credentials and internal services. Patch to v0.12.3 immediately.

Marcus ChenApr 24, 2026
Defender Zero-Days Hit Live Attacks - Two Still Unpatched
Vulnerabilities4 min read

Defender Zero-Days Hit Live Attacks - Two Still Unpatched

Huntress confirms hands-on-keyboard exploitation of all three Windows Defender zero-days. Microsoft patched BlueHammer, but RedSun and UnDefend remain unpatched as attackers chain them for SYSTEM access.

Marcus ChenApr 23, 2026