Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)
CVE-2026-52887 is a critical SQL injection vulnerability affecting NocoBase, an AI-powered no-code/low-code platform. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries via the…
2 articles · Updated July 16, 2026 -
SAP Releases January 2026 Security Patches for Critical Vulnerabilities
On January 13, 2026, SAP issued 17 new security notes during its monthly Security Patch Day, addressing critical injection flaws and remote code execution vulnerabilities in key products. Organizations are urged to…
6 articles · Updated January 13, 2026 -
Critical SQL Injection Vulnerability in Drupal Core Actively Exploited
A critical SQL injection vulnerability (CVE-2026-9082) in Drupal Core has been identified, affecting multiple supported versions. The vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to execute…
6 articles · Updated May 25, 2026 -
Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
A critical unauthenticated SQL injection vulnerability (CVE-2026-49776) has been identified in the GPTranslate plugin for WordPress, affecting versions 2.32.6 and earlier. This flaw allows attackers to execute arbitrary…
3 articles · Updated June 16, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Critical SQL Injection Vulnerability Discovered in ReadyEcommerce (CVE-2026-63106)
A critical unauthenticated SQL injection vulnerability, CVE-2026-63106, has been identified in ReadyEcommerce versions prior to 4.5.2. The flaw exists in the product listing API, where the rating parameter is…
2 articles · Updated August 11, 2026 -
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
A sophisticated cyber campaign has exploited a critical cPanel vulnerability (CVE-2026-41940) to breach government and military servers in Southeast Asia, particularly targeting Indonesia. The attackers utilized a…
3 articles · Updated May 4, 2026 -
Critical SQL Injection Vulnerability in UMAI Vision Traffic Analysis System (CVE-2026-4978)
A critical SQL injection vulnerability, CVE-2026-4978, has been identified in the UMAI Vision Traffic Analysis System, affecting versions 30 to 33. This flaw allows unauthenticated attackers to execute arbitrary SQL…
3 articles · Updated July 30, 2026 -
Critical Vulnerabilities in Veeam Software Expose Systems to Remote Attacks
On August 5, 2026, Veeam disclosed multiple critical vulnerabilities affecting Veeam ONE and Veeam Service Provider Console. The vulnerabilities include remote unauthenticated code execution, file read access, and SQL…
3 articles · Updated August 5, 2026
Recent Intelligence Reports
- CWE-285: Improper Authorization — cwe.mitre.org · August 31, 2026
- ServiceNow patches three maximum severity flaws inside its AI agent platform — Startupfortune · August 30, 2026
- High-Severity MongoDB Driver and BI Connector Flaws Require Immediate Patching Mallory Threat Intelligence Stories / 7h CVE-2026-81532 was published as a high-severity improper-bounds-checking vulnerability in the BI Connector ODBC driver. MongoDB Connector for BI's CVE-2026-77586 was published as a high-severity flaw in which unescaped collection, field, or index names can inject SQL into generated SHOW CREATE output that is later replayed. — mallory.ai · August 29, 2026
- ServiceNow Patches Max-Severity AI Platform Flaws; Urgent Enterprise Action Needed — Techgig · August 29, 2026
- ServiceNow patches three maximum severity flaws that could put enterprise data at risk — Csoonline · August 28, 2026
- PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns — Technadu · August 25, 2026
- 89 — cwe.mitre.org · August 25, 2026
- The OWASP LLM Top 10: What Application Security Teams Need to Know About LLM Vulnerabilities — Scworld · August 24, 2026