Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
A critical argument injection vulnerability (CWE-88) has been discovered in Gogs, a widely used self-hosted Git service, allowing authenticated users to execute arbitrary code on the server. The flaw, identified by…
A critical vulnerability, CVE-2026-2329, has been identified in the Grandstream GXP1600 series VoIP phones, allowing unauthenticated remote code execution with root privileges. This flaw affects small and midsized…
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
Zafran has introduced a threat exposure management platform on AWS, emphasizing the need for continuous threat exposure management (CTEM) in vulnerability management. This platform leverages AI-powered approaches and…
SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability…
On March 17, 2026, Mondoo announced the launch of its Agentic Managed Vulnerability Service, designed to shift organizations from traditional scanning and reporting to effective vulnerability remediation. The service…