CISA has added critical vulnerabilities in WSO2 products and Adobe Commerce to its Known Exploited Vulnerabilities catalog, mandating that federal…
Read More »Known Exploited Vulnerabilities
Entity category: PRODUCT
Citrix disclosed two new NetScaler vulnerabilities: CVE-2026-19490, an unauthenticated authentication bypass (critical, when configured as AAA or Gateway with SAML…
Read More »The U.S. federal government launched "Gold Eagle," a program using AI to accelerate cyber threat detection and remediation, uniting CISA,…
Read More »Microsoft's July 2026 Patch Tuesday is the largest on record, addressing 622 vulnerabilities, including two actively exploited zero-days in SharePoint…
Read More »CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-48595, an Android Framework integer overflow affecting…
Read More »A critical zero-day vulnerability (CVE-2026-34926) in Trend Micro's Apex One on-premise platform is being actively exploited, with at least one…
Read More »A critical buffer overflow vulnerability (CVE-2026-0300) in Palo Alto Networks PAN-OS software allows unauthenticated remote code execution with root privileges…
Read More »CISA added Linux kernel vulnerability CVE-2026-31431 ("Copy Fail") to its Known Exploited Vulnerabilities catalog due to active exploitation, with a…
Read More »Hackers are actively exploiting a critical vulnerability (CVE-2026-41940) in cPanel and WebHost Manager, with over 550,000 servers potentially vulnerable and…
Read More »CISA has mandated that U.S. federal agencies patch a Microsoft Defender privilege escalation vulnerability (CVE-2026-33825, dubbed "BlueHammer") within two weeks,…
Read More »The cybersecurity operational model is fundamentally broken, with defenders closing more tickets but the percentage of critical vulnerabilities open after…
Read More »Google has released a critical Chrome update patching 21 vulnerabilities, including a high-severity zero-day flaw (CVE-2026-5281) that is already being…
Read More »The UK's NCSC warns of active attacks exploiting a critical RCE vulnerability (CVE-2025-53521) in F5's BIG-IP APM, urging immediate patching.…
Read More »Federal agencies must patch a critical vulnerability (CVE-2026-20131) in Cisco's firewall management software by March 22, as it allows unauthenticated…
Read More »A critical, actively exploited security flaw (CVE-2026-20963) in Microsoft SharePoint has been added to CISA's Known Exploited Vulnerabilities catalog, requiring…
Read More »AI and automation have dramatically accelerated cyberattack timelines, compressing the window for organizations to patch vulnerabilities from weeks to days…
Read More »CISA has mandated federal agencies to patch a critical remote code execution vulnerability (CVE-2025-68613) in the n8n automation platform by…
Read More »A critical command injection vulnerability (CVE-2026-22719) in VMware Aria Operations is under active exploitation, allowing unauthenticated attackers to execute arbitrary…
Read More »A critical vulnerability (CVE-2026-25108) in Soliton Systems' FileZen appliance is under active exploitation, allowing attackers to run arbitrary commands, prompting…
Read More »A critical, unauthenticated remote code execution flaw (CVE-2026-1731) in BeyondTrust's remote support software is being actively exploited by ransomware groups,…
Read More »


















