PROBABLYPWNED
Home/Vulnerabilities

Vulnerabilities

127 articles

Atop EHG2408 Industrial Switch RCE Hits CVSS 9.3
Vulnerabilities3 min read

Atop EHG2408 Industrial Switch RCE Hits CVSS 9.3

CVE-2026-3823 allows unauthenticated attackers to execute code on Atop Technologies industrial switches. Firmware 3.36 patches the critical buffer overflow.

Marcus ChenMar 9, 2026
Delta Electronics COMMGR2 Flaws Score CVSS 9.8
Vulnerabilities3 min read

Delta Electronics COMMGR2 Flaws Score CVSS 9.8

Two critical vulnerabilities in Delta Electronics COMMGR2 enable remote code execution without authentication. ICS operators should patch to v2.11.1 immediately.

Marcus ChenMar 9, 2026
Caddy Server Flaw Lets Users Impersonate Admins
Vulnerabilities4 min read

Caddy Server Flaw Lets Users Impersonate Admins

CVE-2026-30851 in Caddy's forward_auth module enables identity injection and privilege escalation. Any valid user can impersonate administrators. Update to 2.11.2.

Marcus ChenMar 8, 2026
CISA Orders Feds to Patch Dell Flaw Within 3 Days
Vulnerabilities4 min read

CISA Orders Feds to Patch Dell Flaw Within 3 Days

Federal agencies must patch CVE-2026-22769 by Saturday after CISA confirms Chinese hackers exploited the Dell RecoverPoint vulnerability since 2024.

Marcus ChenFeb 19, 2026
BeyondTrust Pre-Auth RCE Exposes 11,000 Systems
Vulnerabilities3 min read

BeyondTrust Pre-Auth RCE Exposes 11,000 Systems

CVE-2026-1731 allows unauthenticated remote code execution on BeyondTrust Remote Support and Privileged Remote Access products. CVSS 9.9 vulnerability affects 11,000+ exposed instances.

Marcus ChenFeb 12, 2026
Microsoft Patches Six Zero-Days in February Patch Tuesday
Vulnerabilities4 min read

Microsoft Patches Six Zero-Days in February Patch Tuesday

Microsoft's February 2026 Patch Tuesday fixes 59 flaws including six actively exploited zero-days. CrowdStrike confirmed CVE-2026-21533 was used in attacks targeting US and Canada since December.

Marcus ChenFeb 12, 2026
SmarterMail Flaw Exploited in Ransomware Attacks
Vulnerabilities3 min read

SmarterMail Flaw Exploited in Ransomware Attacks

CVE-2026-24423 lets unauthenticated attackers execute OS commands on SmarterMail servers. CISA confirms active ransomware exploitation and sets a February 26 patch deadline.

Marcus ChenFeb 6, 2026