Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical FreeIPA Vulnerabilities Allow Unauthenticated Admin Access
A critical flaw in FreeIPA, tracked as CVE-2026-76578, allows unauthenticated clients to create Kerberos identities and gain administrative privileges. This vulnerability arises from a misconfigured access control rule…
3 articles · Updated September 8, 2026 -
Critical Vulnerabilities in Yarbo Robot Firmware Expose Devices to Remote Attacks
AHA! disclosed three critical vulnerabilities in Yarbo robot firmware v2.3.9, identified as CVE-2026-7413, CVE-2026-7414, and CVE-2026-7415. The vulnerabilities include a hidden backdoor, hardcoded credentials, and an…
3 articles · Updated May 7, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts
Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62%…
5 articles · Updated August 18, 2026 -
Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain…
9 articles · Updated June 22, 2026 -
Critical Vulnerabilities Disclosed in Palo Alto Networks PAN-OS Software
On November 18, 2024, Palo Alto Networks disclosed two critical vulnerabilities in PAN-OS: CVE-2024-0012 and CVE-2024-9474. CVE-2024-0012 is an authentication bypass vulnerability that allows unauthenticated attackers…
114 articles · Updated April 24, 2026 -
Critical RCE Vulnerability in WebErpMesv2 Affects Self-Registered Users
CVE-2026-49827, published on August 13, 2026, reveals a critical vulnerability in WebErpMesv2 versions 1.19 and prior. This flaw allows unauthenticated remote code execution through arbitrary PHP file uploads via the HR…
2 articles · Updated August 14, 2026 -
Critical Vulnerability in Aqara IAM/SSO Gateway Exposes Signing Key
The Aqara IAM/SSO gateway (gw-builder.aqara.com) has a critical vulnerability (CVE-2026-50086) that allows unauthorized access to cryptographic operations involving the platform's signing key. This flaw enables…
2 articles · Updated June 13, 2026 -
Oracle CSPU May 2026: 35 Critical Vulnerabilities Addressed
Oracle released its first Critical Security Patch Update (CSPU) on May 28, 2026, addressing 35 vulnerabilities across multiple product families, including Oracle Database, Oracle REST Data Services, and Oracle…
68 articles · Updated May 29, 2026
Recent Intelligence Reports
- CVE-2026-76578 — access.redhat.com · September 8, 2026
- 1 — github.com · September 7, 2026
- Calix GigaSpire Flaw Lets Strangers Control Your Home Firewall: No Patch — Techtimes · August 25, 2026
- New Report from Rapid7 Labs: Why Q2 2026 signals the end of traditional patch cycles — Rapid7 · August 18, 2026
- CVE-2026-49827 - WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) Latest High/Critical Vulnerabilitiy Feed / 10h CVE ID : CVE-2026-49827 Published : Aug. 13, 2026, 1:19 p.m. 16 minutes ago Description : WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execu — cvefeed.io · August 14, 2026
- CVE 2026 0283 — security.paloaltonetworks.com · July 10, 2026
- JVN#40604023 prior disclosure — jvn.jp · July 5, 2026
- JetBrains Patches Critical Hub Authentication Bypass and Account Takeover Vulnerabilities — Gbhackers · July 2, 2026