Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical RCE Vulnerability in Oracle PeopleSoft Exploited by SHADOW-AETHER-015
A pre-authentication remote code execution (RCE) vulnerability, CVE-2026-35273, was discovered in Oracle PeopleSoft PeopleTools, affecting versions 8.61 and 8.62. The vulnerability allows unauthenticated attackers to…
5 articles · Updated June 18, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the…
2 articles · Updated June 4, 2026 -
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
3 articles · Updated July 14, 2026 -
Apache Syncope Vulnerabilities Enable Remote Code Execution and Privilege Escalation
Apache Syncope has released critical updates to address six vulnerabilities, including remote code execution (RCE) and SQL injection flaws. The vulnerabilities affect versions 4.1, 4.0, and 3.0 of the Syncope identity…
2 articles · Updated July 24, 2026 -
Critical Vulnerabilities in Fluentd Enable Remote Code Execution and SSRF
Fluentd v1.19.3 addresses multiple vulnerabilities, including a critical RCE flaw tracked as CVE-2026-44024. These vulnerabilities can allow unauthenticated remote attackers to execute arbitrary code, access sensitive…
5 articles · Updated July 1, 2026 -
Cisco Confirms Active Exploitation of Unified CM Vulnerability CVE-2026-20230
Cisco has confirmed that attackers are exploiting a vulnerability in its Unified Communications Manager (Unified CM), tracked as CVE-2026-20230, which was patched on June 3, 2026. This vulnerability allows for…
2 articles · Updated July 2, 2026 -
Vibe Coding Tools Found to Generate Critical Security Flaws
A study by security startup Tenzai revealed that popular vibe coding platforms produce insecure code, including critical vulnerabilities, when responding to common programming prompts. The assessment, conducted in…
3 articles · Updated January 14, 2026 -
CVE-2026: SSRF Vulnerabilities in Azure Services
Two critical server-side request forgery (SSRF) vulnerabilities have been identified in Azure services. The first allows authorized attackers to elevate privileges in Azure MCP Server, while the second enables…
2 articles · Updated March 10, 2026
Recent Intelligence Reports
- Ubuntu 26.04 LTS Axios High Server-Side Request Forgery Issues USN-8638 — Linuxsecurity · August 13, 2026
- USN-8638-1: Axios vulnerabilities — Ubuntu · August 13, 2026
- Daily Threat Brief: July 27, 2026 — Buttondown · July 28, 2026
- 918 — cwe.mitre.org · July 25, 2026
- Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code — Gbhackers · July 24, 2026
- Ubuntu 26.04 Wget Important Server-Side Request Forgery Vuln USN-8572 — Linuxsecurity · July 20, 2026
- Weekly Security Roundup: June 29 to July 12, 2026 — Sherlockforensics · July 13, 2026
- USN-8509-1: Python vulnerabilities — Ubuntu · July 6, 2026