Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall appliances, allowing unauthenticated attackers to execute commands as root. Addi...
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a CVSS 9.9 vulnerability. Microsoft reported a staggering 621 new CVEs, marking a reco...
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that could steal GitHub tokens. The updates are crucial for protecting a wide range of Mi...
Microsoft has confirmed the active exploitation of CVE-2026-56155, an elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows authenticated local attackers with low privileges to gain administrator-level access. The vulnerability was published on 2026-0...