Related Threat Clusters
-
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
Critical Vulnerabilities in Tenable Security Center Prompt Urgent Patch Release
Tenable has released Security Center Patch SC202607.1 to address multiple vulnerabilities in third-party components, including Apache, OpenSSL, PostgreSQL, PHP, and Redis. The patch resolves critical issues such as SQL…
2 articles · Updated July 21, 2026 -
Ubiquiti Patches Three Critical Vulnerabilities in UniFi Products
Ubiquiti has disclosed three critical vulnerabilities affecting its UniFi ecosystem, all published on 2026-08-26. These vulnerabilities, tracked as CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, allow…
17 articles · Updated August 26, 2026 -
Critical RCE Vulnerability in OpenEMR Exposes Servers to Attacks
A critical remote code execution vulnerability, CVE-2026-39932, affects OpenEMR versions up to 8.2.0. The flaw arises from an unsafe eval() call in the document category tree component, allowing attackers to execute…
2 articles · Updated August 4, 2026 -
Critical Vulnerabilities in Gogs and Jinjava Require Immediate Patching
Multiple critical vulnerabilities affecting Gogs and Jinjava have been disclosed, with severe impacts including remote code execution (RCE) and unauthorized file access. Gogs vulnerabilities include CVE-2025-64111…
2 articles · Updated June 25, 2026 -
Critical CVE-2026-16117 Vulnerability in @fastify/http-proxy Exposes Internal Endpoints
CVE-2026-16117 was published on July 18, 2026, detailing a critical vulnerability in @fastify/http-proxy versions up to 11.5.0. The flaw allows attackers to bypass request prefix rewrites when the prefix is URL-encoded,…
2 articles · Updated July 19, 2026 -
Critical SearchLeak Vulnerability in Microsoft 365 Copilot Exposes Sensitive Data
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat…
34 articles · Updated June 15, 2026 -
Seiko SkyBridge IoT Routers Face Permanent OS Injection Vulnerability
Seiko Solutions' SkyBridge MB-A100 and MB-A110 routers are affected by a high-severity OS command injection vulnerability (CVE-2026-50043) disclosed on July 1, 2026. The flaw allows authenticated attackers to execute…
2 articles · Updated July 4, 2026 -
Critical Remote Command Execution Vulnerabilities in SUSE Cockpit
SUSE has released a security update addressing multiple vulnerabilities in Cockpit, impacting SUSE Linux Enterprise and openSUSE systems. Notably, CVE-2026-4802 allows remote command execution via unsanitized…
4 articles · Updated May 23, 2026 -
AI-Driven Command Injection Vulnerability Exposes Snowflake Jira Credentials
A critical command injection vulnerability was discovered in Snowflake's GitHub Actions workflow, allowing unauthenticated attackers to execute arbitrary commands. The flaw was introduced by an AI coding assistant,…
12 articles · Updated August 17, 2026
Recent Intelligence Reports
- vulncheck.com: VulnCheck Advisory: LibreNMS before 26.5.0 Remote Code Execution via AboutController external site — www.vulncheck.com · September 1, 2026
- CC-4837 — Digital.Nhs.Uk · August 27, 2026
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection — Thehackernews · August 17, 2026
- CWE-20: Improper Input Validation — cwe.mitre.org · August 11, 2026
- Unclassified News Aug 2, 2026 The eval() That Nobody Was Supposed to Find: SQL Import Chains to OS Command Execution in OpenEMR 8.0.0.3 - Jiva Security jivasecurity.com Open source — jivasecurity.com · August 4, 2026
- CVE-2026-64880 | Tenable® — Tenable · July 21, 2026
- JVN#40604023 prior disclosure — jvn.jp · July 5, 2026
- Warning: Multiple Vulnerabilities in Gogs Allow Remote Code Execution, Patch Immediately! — Ccb.Belgium.Be · June 25, 2026