Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical Zero-Day Vulnerability in Gogs Allows Remote Code Execution
A critical argument injection vulnerability (CWE-88) has been discovered in Gogs, a widely used self-hosted Git service, allowing authenticated users to execute arbitrary code on the server. The flaw, identified by…
10 articles · Updated May 28, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Critical CVE-2026-2329 Vulnerability in Grandstream VoIP Phones
A critical vulnerability, CVE-2026-2329, has been identified in the Grandstream GXP1600 series VoIP phones, allowing unauthenticated remote code execution with root privileges. This flaw affects small and midsized…
18 articles · Updated February 18, 2026 -
Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
74 articles · Updated November 28, 2025 -
Zafran Launches Threat Exposure Management Platform on AWS
Zafran has introduced a threat exposure management platform on AWS, emphasizing the need for continuous threat exposure management (CTEM) in vulnerability management. This platform leverages AI-powered approaches and…
2 articles · Updated February 6, 2026 -
SonicWall SMA1000 Zero-Day Vulnerability Disclosed
SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability…
5 articles · Updated December 17, 2025 -
Mondoo Launches Managed Vulnerability Service to Enhance Remediation Efforts
On March 17, 2026, Mondoo announced the launch of its Agentic Managed Vulnerability Service, designed to shift organizations from traditional scanning and reporting to effective vulnerability remediation. The service…
2 articles · Updated March 17, 2026
Recent Intelligence Reports
- Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) — Rapid7 · August 11, 2026
- Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects — Csoonline · May 29, 2026
- Maximum Severity Cisco SD — Darkreading · May 14, 2026
- Mondoo Launches Agentic Managed Vulnerability Service to Accelerate Remediation and ... — Markets.Businessinsider · March 17, 2026
- Critical flaw in Grandstream GXP1600 VoIP phones could lead to call eavesdropping — Scworld · February 19, 2026
- Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot — Darkreading · February 18, 2026
- CVE-2026-2329: Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 ... — Rapid7 · February 18, 2026
- Transform CTEM with Zafran's threat exposure management platform on AWS — Aws.Amazon · February 6, 2026