Cwe-295 - Improper Certificate Validation is a cwe tracked across 9 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed April 16, 2026; most recent activity June 8, 2026.
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
Recent updates for strongSwan, affecting SUSE and Ubuntu systems, have addressed several critical vulnerabilities. The issues include CVE-2026-35328, which can cause an infinite loop in TLS processing, and…
Ivanti has disclosed a zero-day vulnerability (CVE-2026-6973) in its Endpoint Manager Mobile (EPMM) product, which has been actively exploited by attackers. This flaw allows authenticated users with administrative…
Two critical vulnerabilities (CVE-2026-5787 and CVE-2026-5788) were disclosed in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. CVE-2026-5787 allows attackers to impersonate Sentry hosts and obtain…
Two critical vulnerabilities have been identified in Spring Boot's auto-configuration for Elasticsearch and RabbitMQ. CVE-2026-40970 affects Elasticsearch, while CVE-2026-40971 impacts RabbitMQ. Both vulnerabilities…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
Palo Alto Networks disclosed two critical vulnerabilities in their GlobalProtect app. CVE-2026-0251, published on 2026-05-13, allows local privilege escalation on Windows, macOS, and Linux, enabling non-administrative…
Fedora has released updates for docker-buildx and docker-buildkit to address CVE-2026-39984, which involves improper certificate validation. The vulnerabilities affect multiple Fedora versions, including 42, 43, and 44,…
On May 29, 2026, Ubuntu announced a regression in pip due to patches for CVE-2025-66471, which were initially intended to fix vulnerabilities in pip on Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. The regression caused…