Known Exploited Vulnerabilities

Entity category: PRODUCT

AI & Tech

CISA Warns of Exploited Flaws in SharePoint, WSO2, Adobe

CISA has added critical vulnerabilities in WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities catalog, mandating that federal…

Read More »
AI & Tech

Patch Citrix NetScaler now: New critical flaws confirmed

Citrix disclosed two new NetScaler vulnerabilities: CVE-2026-19490, an unauthenticated authentication bypass (critical, when configured as AAA or Gateway with SAML…

Read More »
AI & Tech

US Launches Gold Eagle for AI-Driven Vulnerability Management

The U.S. federal government launched "Gold Eagle," a program using AI to accelerate cyber threat detection and remediation, uniting CISA,…

Read More »
BigTech Companies

Microsoft Patches 622 Flaws, Including Two Actively Attacked Zero-Days

Microsoft's July 2026 Patch Tuesday is the largest on record, addressing 622 vulnerabilities, including two actively exploited zero-days in SharePoint…

Read More »
AI & Tech

CISA warns of active exploits targeting Android, Linux flaws

CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-48595, an Android Framework integer overflow affecting…

Read More »
BigTech Companies

CISA Warns of Actively Exploited Trend Micro Apex One Bug

A critical zero-day vulnerability (CVE-2026-34926) in Trend Micro's Apex One on-premise platform is being actively exploited, with at least one…

Read More »
Cybersecurity

Active Exploit of Palo Alto PAN-OS Flaw Allows Remote Code Execution

A critical buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks PAN-OS software allows unauthenticated remote code execution with root privileges…

Read More »
BigTech Companies

CISA Adds Actively Exploited Linux Root Bug to KEV List

CISA added Linux kernel vulnerability CVE-2026-31431 ("Copy Fail") to its Known Exploited Vulnerabilities catalog due to active exploitation, with a…

Read More »
BigTech Companies

Massive cPanel Bug Exploited by Hackers to Hijack Thousands of Sites

Hackers are actively exploiting a critical vulnerability (CVE-2026-41940) in cPanel and WebHost Manager, with over 550,000 servers potentially vulnerable and…

Read More »
BigTech Companies

CISA orders federal agencies to patch exploited BlueHammer flaw

CISA has mandated that U.S. federal agencies patch a Microsoft Defender privilege escalation vulnerability (CVE-2026-33825, dubbed "BlueHammer") within two weeks,…

Read More »
Artificial Intelligence

CISA KEV Data Reveals Human-Scale Security Gaps

The cybersecurity operational model is fundamentally broken, with defenders closing more tickets but the percentage of critical vulnerabilities open after…

Read More »
BigTech Companies

Chrome Zero-Day CVE-2026-5281 Exploited, Patch Available

Google has released a critical Chrome update patching 21 vulnerabilities, including a high-severity zero-day flaw (CVE-2026-5281) that is already being…

Read More »
Business

Patch Critical F5 BIG-IP Bug, NCSC Warns

The UK's NCSC warns of active attacks exploiting a critical RCE vulnerability (CVE-2025-53521) in F5's BIG-IP APM, urging immediate patching.…

Read More »
BigTech Companies

Patch Critical Cisco Flaw by Sunday, CISA Orders

Federal agencies must patch a critical vulnerability (CVE-2026-20131) in Cisco's firewall management software by March 22, as it allows unauthenticated…

Read More »
BigTech Companies

Urgent CISA Alert: Active Microsoft SharePoint Exploit

A critical, actively exploited security flaw (CVE-2026-20963) in Microsoft SharePoint has been added to CISA's Known Exploited Vulnerabilities catalog, requiring…

Read More »
AI & Tech

AI Adversaries Accelerate Cyberattack Timelines

AI and automation have dramatically accelerated cyberattack timelines, compressing the window for organizations to patch vulnerabilities from weeks to days…

Read More »
Artificial Intelligence

CISA Mandates Patch for Actively Exploited n8n RCE Vulnerability

CISA has mandated federal agencies to patch a critical remote code execution vulnerability (CVE-2025-68613) in the n8n automation platform by…

Read More »
BigTech Companies

CISA Warns of Active VMware RCE Attacks

A critical command injection vulnerability (CVE-2026-22719) in VMware Aria Operations is under active exploitation, allowing unauthenticated attackers to execute arbitrary…

Read More »
Business

Patch Now: CISA Warns of Active FileZen Exploit (CVE-2026-25108)

A critical vulnerability (CVE-2026-25108) in Soliton Systems' FileZen appliance is under active exploitation, allowing attackers to run arbitrary commands, prompting…

Read More »
Business

CISA Warns: BeyondTrust RCE Flaw Actively Exploited by Ransomware

A critical, unauthenticated remote code execution flaw (CVE-2026-1731) in BeyondTrust's remote support software is being actively exploited by ransomware groups,…

Read More »