Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Slackware 15.0 released urgent updates for two significant vulnerabilities on June 3, 2026. The first addresses a stack-based buffer overflow in the net-tools package (CVE-2026-154) affecting network interface handling. The second update resolves a denial-of-service vulnerability (CVE-2026-49975) in...
Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows arbitrary code execution via a heap-based buffer overflow. Other vulnerabilities includ...
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as remote code execution (RCE) vulnerabilities. The update included CVE-2026-47291,...
A vulnerability in nginx was discovered that allows remote attackers to cause excessive resource consumption through specially crafted HTTP/2 cookie headers, leading to denial of service (CVE-2026-49975). The initial fix for this vulnerability introduced a regression causing nginx to crash when used...