PROBABLYPWNED
Home/Vulnerabilities

Vulnerabilities

262 articles

Trend Micro Apex One Zero-Day Added to CISA KEV
Vulnerabilities3 min read

Trend Micro Apex One Zero-Day Added to CISA KEV

CVE-2026-34926 lets attackers inject malicious code into Apex One servers and deploy it to all connected endpoint agents. CISA confirms active exploitation with June 4 federal deadline.

Marcus ChenMay 24, 2026
MuddyWater Exploits Langflow Flaw for Initial Access
Vulnerabilities3 min read

MuddyWater Exploits Langflow Flaw for Initial Access

CISA adds CVE-2025-34291 to KEV after Iranian APT MuddyWater weaponizes the CORS/CSRF chain for account takeover and RCE. CVSS 9.4 flaw requires only a malicious link click.

Marcus ChenMay 24, 2026
Apache HTTP/2 Double-Free Enables DoS and RCE
Vulnerabilities4 min read

Apache HTTP/2 Double-Free Enables DoS and RCE

CVE-2026-23918 in Apache HTTP Server 2.4.66 lets attackers crash workers trivially or achieve remote code execution through a double-free in mod_http2. Upgrade to 2.4.67 immediately.

Marcus ChenMay 23, 2026
Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS
Vulnerabilities4 min read

Ubiquiti Patches Three CVSS 10.0 Flaws in UniFi OS

Ubiquiti releases emergency patches for three maximum-severity vulnerabilities in UniFi OS that allow unauthenticated remote attackers to take full control of network appliances. 100,000 devices exposed.

Marcus ChenMay 23, 2026
CISA KEV Adds 7 Flaws Including Exploited Defender Bugs
Vulnerabilities4 min read

CISA KEV Adds 7 Flaws Including Exploited Defender Bugs

CISA's May 20 KEV update includes two actively exploited Microsoft Defender vulnerabilities and five legacy flaws from 2008-2010. Federal agencies have until June 3 to patch.

Marcus ChenMay 21, 2026
Drupal Warns of Highly Critical Flaw — Patches Due Today
Vulnerabilities3 min read

Drupal Warns of Highly Critical Flaw — Patches Due Today

Drupal releases patches for a highly critical vulnerability (severity 20/25) affecting all supported versions. Exploits may emerge within hours—administrators should update between 5-9pm UTC today.

Marcus ChenMay 20, 2026
SEPPMail Gateway Flaws Enable Complete Mail System Takeover
Vulnerabilities4 min read

SEPPMail Gateway Flaws Enable Complete Mail System Takeover

Seven vulnerabilities including CVE-2026-2743 (CVSS 10.0) allow unauthenticated attackers to compromise SEPPMail secure email gateways, read all traffic, and establish persistent access. Patch to 15.0.4 immediately.

Marcus ChenMay 20, 2026
24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026
Vulnerabilities4 min read

24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026

Security researchers exploited Windows 11, Microsoft Edge, Red Hat Linux, and multiple AI platforms on the first day of Pwn2Own Berlin 2026, earning $523,000 for 24 unique zero-day vulnerabilities.

Marcus ChenMay 14, 2026
12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover
Vulnerabilities4 min read

12 Critical Flaws in vm2 Node.js Sandbox Enable Host Takeover

Security researchers disclosed 12 sandbox escape vulnerabilities in vm2, including three with CVSS 10.0 scores. The popular JavaScript isolation library can no longer be trusted to contain untrusted code.

Marcus ChenMay 8, 2026