PROBABLYPWNED
Home/Vulnerabilities

Vulnerabilities

182 articles

GPUBreach Exploits GDDR6 Rowhammer for Full System Takeover
Vulnerabilities3 min read

GPUBreach Exploits GDDR6 Rowhammer for Full System Takeover

University of Toronto researchers demonstrate GPUBreach, a GPU rowhammer attack that bypasses IOMMU protections to achieve root access on systems with NVIDIA GPUs. Consumer GPUs remain unmitigated.

Marcus ChenApr 7, 2026
PraisonAI Sandbox Bypass Scores Perfect CVSS 10
Vulnerabilities3 min read

PraisonAI Sandbox Bypass Scores Perfect CVSS 10

CVE-2026-34938 lets attackers escape PraisonAI's three-layer Python sandbox to execute arbitrary OS commands. CVSS 10 — patch to version 1.5.90 immediately.

Marcus ChenApr 4, 2026
Azure Kubernetes CVE-2026-33105 Hits CVSS 10.0
Vulnerabilities4 min read

Azure Kubernetes CVE-2026-33105 Hits CVSS 10.0

Microsoft Azure Kubernetes Service has a critical auth bypass (CVE-2026-33105) with a perfect CVSS 10.0 score. Unauthenticated attackers can escalate to cluster admin—patch now.

Marcus ChenApr 3, 2026
Google Patches Fourth Chrome Zero-Day of 2026
Vulnerabilities4 min read

Google Patches Fourth Chrome Zero-Day of 2026

CVE-2026-5281 exploited in the wild targets Dawn WebGPU implementation. Google rushes emergency patch as Chrome zero-days accelerate in 2026.

Marcus ChenApr 1, 2026
n8n Merge Node Flaw Exposes 615K Instances to RCE
Vulnerabilities4 min read

n8n Merge Node Flaw Exposes 615K Instances to RCE

CVE-2026-33660 (CVSS 9.4) lets authenticated users escape n8n's AlaSQL sandbox via the Merge node. Over 615,000 public instances potentially vulnerable.

Marcus ChenMar 31, 2026
800K Sites at Risk from Smart Slider 3 File Read Flaw
Vulnerabilities4 min read

800K Sites at Risk from Smart Slider 3 File Read Flaw

CVE-2026-3098 lets subscribers read wp-config.php and any server file. Amelia Booking Pro also patched for admin password reset bug. Update these WordPress plugins now.

Marcus ChenMar 29, 2026
LangChain Flaws Expose Files, Secrets, and Databases
Vulnerabilities3 min read

LangChain Flaws Expose Files, Secrets, and Databases

Three vulnerabilities in LangChain and LangGraph expose filesystems, environment secrets, and conversation histories. CVE-2026-34070 enables path traversal. Patches available now.

Marcus ChenMar 28, 2026
Four Critical n8n Flaws Enable Unauthenticated RCE
Vulnerabilities3 min read

Four Critical n8n Flaws Enable Unauthenticated RCE

n8n patches CVE-2026-27577, CVE-2026-27493, and two more sandbox escapes. One flaw allows unauthenticated attackers to execute commands via public form endpoints.

Marcus ChenMar 24, 2026
Citrix NetScaler Memory Leak Exposes SAML SSO Secrets
Vulnerabilities3 min read

Citrix NetScaler Memory Leak Exposes SAML SSO Secrets

CVE-2026-3055 (CVSS 9.3) lets unauthenticated attackers read sensitive data from NetScaler memory. Affects appliances configured as SAML Identity Providers—patch now.

Marcus ChenMar 24, 2026
Quest KACE SMA CVSS 10.0 Flaw Exploited in the Wild
Vulnerabilities3 min read

Quest KACE SMA CVSS 10.0 Flaw Exploited in the Wild

Attackers exploiting CVE-2025-32975 authentication bypass in Quest KACE to hijack admin accounts and deploy credential harvesters. Patched in May 2025—many remain exposed.

Marcus ChenMar 24, 2026
AVideo RCE Chain Gives Attackers Full Server Access Without Auth
Vulnerabilities3 min read

AVideo RCE Chain Gives Attackers Full Server Access Without Auth

Three vulnerabilities in AVideo's CloneSite plugin chain together for unauthenticated remote code execution. CVE-2026-33478 has no patch available as attackers can extract admin credentials and inject OS commands.

Marcus ChenMar 23, 2026
Ubuntu Desktop Flaw Lets Local Users Escalate to Root
Vulnerabilities3 min read

Ubuntu Desktop Flaw Lets Local Users Escalate to Root

CVE-2026-3888 exploits timing race between snap-confine and systemd-tmpfiles to grant root access on Ubuntu Desktop 24.04+. Qualys researchers demonstrate full privilege escalation.

Marcus ChenMar 23, 2026
PolyShell Flaw Exposes All Magento Stores to RCE Attacks
Vulnerabilities4 min read

PolyShell Flaw Exposes All Magento Stores to RCE Attacks

Unrestricted file upload in Magento and Adobe Commerce REST API allows unauthenticated attackers to upload executable files. No isolated patch available for production versions.

Marcus ChenMar 21, 2026
CISA Adds Apple, Craft CMS, Laravel Bugs to KEV Catalog
Vulnerabilities4 min read

CISA Adds Apple, Craft CMS, Laravel Bugs to KEV Catalog

Five vulnerabilities under active exploitation added to CISA's KEV catalog. Federal agencies must patch by April 3, 2026. Includes three Apple kernel flaws and Laravel RCE.

Marcus ChenMar 21, 2026
Langflow RCE Exploited Within 20 Hours of Disclosure
Vulnerabilities4 min read

Langflow RCE Exploited Within 20 Hours of Disclosure

CVE-2026-33017 (CVSS 9.3) lets attackers execute arbitrary Python code on Langflow AI pipelines without authentication. Exploitation began before any PoC existed.

Marcus ChenMar 21, 2026