Related Threat Clusters
-
Critical Dgraph Database Flaw Allowed Attackers to Bypass Authentication
A critical vulnerability in the Dgraph database system, tracked as CVE-2026-34976, has been discovered, allowing unauthenticated remote attackers to bypass all security controls. This flaw carries a maximum CVSS score…
2 articles · Updated April 6, 2026 -
Active Exploitation of Microsoft SharePoint Flaw CVE-2026-45659 Confirmed
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45659, a remote code execution vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog due to active…
2 articles · Updated July 4, 2026 -
Critical Authentication Bypass Vulnerability in Spring Authorization Server
A critical vulnerability, CVE-2026-22752, has been identified in Spring Authorization Server, affecting versions 1.3.0 to 1.3.10, 1.4.0 to 1.4.9, 1.5.0 to 1.5.6, and 7.0.0 to 7.0.4. The flaw allows attackers with a…
2 articles · Updated July 18, 2026 -
Critical SSRF Vulnerability in Cisco Unified CM Exposes Enterprises to Root Access
Cisco disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (CVE-2026-20230) on June 3, 2026. This flaw allows attackers with network access to write arbitrary files…
8 articles · Updated June 4, 2026 -
Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild
Microsoft disclosed a critical remote code execution vulnerability in Entra ID, tracked as CVE-2026-69836, which has been actively exploited in the wild. This flaw, stemming from unsafe deserialization of untrusted…
42 articles · Updated August 21, 2026 -
AgentForger: New Phishing Attack Creates Autonomous AI Insiders
Zenity Labs has identified a critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents. This flaw allows attackers to create a malicious AI agent within an organization by embedding instructions in a…
11 articles · Updated July 23, 2026 -
Red Hat Kubernetes SSRF Vulnerability Exposes Internal Services to Attackers
Red Hat disclosed CVE-2026-66794, a high-severity SSRF vulnerability in the cluster-proxy-addon of the Multicluster Engine for Kubernetes. This flaw, rated with a CVSS v3.1 score of 9.3, allows unauthenticated remote…
2 articles · Updated August 20, 2026 -
Multiple Vulnerabilities Discovered in Splunk Products Affecting Security Integrity
Splunk has disclosed several vulnerabilities affecting its products, including Splunk Enterprise, SOAR, and AI Toolkit. Key vulnerabilities include CVE-2026-76338, CVE-2026-76352, CVE-2026-76362, CVE-2026-76364, and…
8 articles · Updated August 20, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1438 articles · Updated February 9, 2026 -
Reconnaissance for MCP Servers and AI Credentials Intensifies
A recent analysis of Apache and ModSecurity logs revealed a surge in internet-wide reconnaissance targeting Model Context Protocol (MCP) servers and AI assistant configuration files. Over a 14-day period, approximately…
2 articles · Updated July 13, 2026
Recent Intelligence Reports
- Threataft Blog News Aug 21, 2026 CVE-2026-65801: Microsoft Exchange Online SSRF - CVSS 10 threataft.com Open source — threataft.com · August 21, 2026
- Cvefeed High Severity Advisories Aug 21, 2026 CVE-2026-69502 - Azure SQL Database Elevation of Privilege Vulnerability cvefeed.io Open source — cvefeed.io · August 21, 2026
- CVE-2026-69855 - Exploits & Severity — Feedly · August 21, 2026
- SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026 Splunk Security Announcements / 19h In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer’s archive extraction to write files outside the intended inst — advisory.splunk.com · August 20, 2026
- Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services — Gbhackers · August 20, 2026
- 918 — cwe.mitre.org · July 25, 2026
- labs.zenity.io — cts.businesswire.com · July 23, 2026
- Microsoft open — Feeds.4Sysops · July 20, 2026