Cwe-122 - Heap-based Buffer Overflow is a cwe tracked across 50 threat clusters and 170 intelligence report mentions on ThreatCluster. First observed April 17, 2026; most recent activity July 21, 2026.
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
Silex Technology, Inc. has reported a critical heap-based buffer overflow vulnerability in its SD-330AC devices and AMC Manager software, identified as CVE-2026-32956. This vulnerability allows unauthenticated remote…
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
On May 7, 2026, Ubuntu published USN-8251-1, addressing several critical vulnerabilities in libpng, affecting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The vulnerabilities include improper memory handling when processing…
Multiple critical vulnerabilities have been identified in the freerdp component of openSUSE, affecting versions 15.4 and 15.6. The vulnerabilities include CVE-2026-25941, CVE-2026-25942, CVE-2026-25952, CVE-2026-25953,…