PROBABLYPWNED
Home/Vulnerabilities

Vulnerabilities

105 articles

CISA Orders Feds to Patch Dell Flaw Within 3 Days
Vulnerabilities4 min read

CISA Orders Feds to Patch Dell Flaw Within 3 Days

Federal agencies must patch CVE-2026-22769 by Saturday after CISA confirms Chinese hackers exploited the Dell RecoverPoint vulnerability since 2024.

Marcus ChenFeb 19, 2026
BeyondTrust Pre-Auth RCE Exposes 11,000 Systems
Vulnerabilities3 min read

BeyondTrust Pre-Auth RCE Exposes 11,000 Systems

CVE-2026-1731 allows unauthenticated remote code execution on BeyondTrust Remote Support and Privileged Remote Access products. CVSS 9.9 vulnerability affects 11,000+ exposed instances.

Marcus ChenFeb 12, 2026
Microsoft Patches Six Zero-Days in February Patch Tuesday
Vulnerabilities4 min read

Microsoft Patches Six Zero-Days in February Patch Tuesday

Microsoft's February 2026 Patch Tuesday fixes 59 flaws including six actively exploited zero-days. CrowdStrike confirmed CVE-2026-21533 was used in attacks targeting US and Canada since December.

Marcus ChenFeb 12, 2026
SmarterMail Flaw Exploited in Ransomware Attacks
Vulnerabilities3 min read

SmarterMail Flaw Exploited in Ransomware Attacks

CVE-2026-24423 lets unauthenticated attackers execute OS commands on SmarterMail servers. CISA confirms active ransomware exploitation and sets a February 26 patch deadline.

Marcus ChenFeb 6, 2026
CISA Adds SolarWinds, Sangoma, GitLab Flaws to KEV
Vulnerabilities3 min read

CISA Adds SolarWinds, Sangoma, GitLab Flaws to KEV

Four actively exploited vulnerabilities added to CISA's catalog including SolarWinds Web Help Desk deserialization flaw with CVSS 9.8. Federal agencies have until February 6 to patch.

Marcus ChenFeb 4, 2026
Google Looker Flaws Let Attackers Hijack BI Servers
Vulnerabilities4 min read

Google Looker Flaws Let Attackers Hijack BI Servers

Tenable discloses 'LookOut' vulnerabilities in Google Looker enabling remote code execution and full database theft. Self-hosted deployments at 60,000+ organizations exposed.

Marcus ChenFeb 4, 2026
Redis RCE Exploit More Severe Than Initially Rated
Vulnerabilities3 min read

Redis RCE Exploit More Severe Than Initially Rated

JFrog researchers develop working remote code execution exploit for CVE-2025-62507, a stack buffer overflow in Redis discovered by Google's AI security agent.

Marcus ChenFeb 1, 2026
Iconics SCADA Flaw Allows System File Corruption
Vulnerabilities4 min read

Iconics SCADA Flaw Allows System File Corruption

CVE-2025-0921 enables privileged file system operations that can disrupt industrial control systems in automotive, energy, and manufacturing environments.

Marcus ChenFeb 1, 2026
Cisco ISE XXE Flaw Has Public PoC, Patch Now
Vulnerabilities3 min read

Cisco ISE XXE Flaw Has Public PoC, Patch Now

Cisco patches CVE-2026-20029, an XML external entity vulnerability in Identity Services Engine with proof-of-concept exploit code already publicly available.

Marcus ChenJan 31, 2026
OpenSSL Stack Overflow Enables Remote Code Execution
Vulnerabilities5 min read

OpenSSL Stack Overflow Enables Remote Code Execution

CVE-2025-15467 allows attackers to crash or compromise systems by sending malicious CMS messages. All AI-discovered in OpenSSL's largest coordinated security release.

Marcus ChenJan 29, 2026