Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass a...
On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization....
Google's September 2026 Android Security Bulletin addresses 180 vulnerabilities, including 95 bugs from the 2026-09-01 patch level and 85 from the 2026-09-05 patch level. The most severe vulnerability, CVE-2026-28662, allows remote code execution without user interaction. Samsung's September update...
Threat actors are exploiting CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager, to deploy a Node.js remote access trojan (RAT) known as PivotC2. This vulnerability allows unauthenticated remote code execution, affecting numerous devices, including FortiGate...