Related Threat Clusters
-
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical Command Injection and DoS Vulnerabilities in openSUSE pcp
Recent updates for openSUSE's pcp software have addressed multiple critical vulnerabilities, including command injection and denial-of-service (DoS) issues. The vulnerabilities, identified as CVE-2026-16524,…
11 articles · Updated August 6, 2026 -
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to…
10 articles · Updated August 20, 2026 -
Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the…
2 articles · Updated June 4, 2026 -
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
3 articles · Updated July 14, 2026 -
Critical Auth Bypass Vulnerability in SUSE Elemental Systems (CVE-2026-33186)
A significant authorization bypass vulnerability (CVE-2026-33186) has been identified in multiple SUSE Elemental systems, including the elemental-system-agent, elemental-toolkit, and elemental-register. This flaw arises…
73 articles · Updated June 9, 2026 -
Critical Ubuntu Snap Flaw Allows Local Privilege Escalation
A local privilege escalation vulnerability, tracked as CVE-2026-3888, has been identified in default installations of Ubuntu Desktop 24.04 and later. Discovered by Qualys, the flaw arises from an unintended interaction…
11 articles · Updated March 18, 2026 -
Apache Syncope Vulnerabilities Enable Remote Code Execution and Privilege Escalation
Apache Syncope has released critical updates to address six vulnerabilities, including remote code execution (RCE) and SQL injection flaws. The vulnerabilities affect versions 4.1, 4.0, and 3.0 of the Syncope identity…
2 articles · Updated July 24, 2026 -
Microsoft March 2026 Patch Tuesday Addresses 79 Vulnerabilities, Including Zero-Days
On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively…
51 articles · Updated March 10, 2026 -
Linux Kernel CVE-2026-23111 Enables Local Privilege Escalation via nftables
A use-after-free vulnerability in the Linux kernel's nftables subsystem, tracked as CVE-2026-23111, allows local attackers to escalate privileges to root. Discovered in early 2025, the flaw was patched on February 5,…
4 articles · Updated June 8, 2026
Recent Intelligence Reports
- Ubuntu 26.04 UDisks Significant Local Privilege Escalation Issue USN-8701 — Linuxsecurity · August 31, 2026
- CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability — Api.Msrc.Microsoft · August 31, 2026
- ServiceNow Patches Max-Severity AI Platform Flaws; Urgent Enterprise Action Needed — Techgig · August 29, 2026
- CC-4837 — Digital.Nhs.Uk · August 27, 2026
- CVE-2015-5287 — nvd.nist.gov · August 20, 2026
- Gentoo Bubblewrap Critical Root Access Risk GLSA-202608-09 CVE-2026 — Linuxsecurity · August 14, 2026
- According to a post — security.paloaltonetworks.com · August 13, 2026
- A severe ASUS Armoury Crate vulnerability affects laptops, handhelds, and desktop PCs — Inkl · August 12, 2026