Related Threat Clusters
-
Critical RCE Vulnerability in N-able N-central Requires Immediate Patching
N-able has released Hotfix 4 for its N-central platform to address CVE-2026-86218, a critical remote code execution (RCE) vulnerability rated CVSS 10.0. This flaw allows unauthenticated attackers to execute arbitrary…
43 articles · Updated September 7, 2026 -
Critical RCE Vulnerabilities Under Active Exploitation
Multiple critical vulnerabilities are currently being exploited, including remote code execution (RCE) flaws in HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and…
2 articles · Updated September 6, 2026 -
Multiple CVEs Exploited in Cybersecurity Threats: September 2026
In September 2026, several critical vulnerabilities were disclosed, notably CVE-2026-81963 and CVE-2026-85880, both of which are actively exploited. CVE-2026-81963, affecting Windows Update Stack, allows local privilege…
8 articles · Updated September 8, 2026 -
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
3 articles · Updated July 14, 2026 -
Active Exploitation of Magento Zero-Day and Chromium Backdoors
A sophisticated backdoor toolkit named PEEP has been discovered, exploiting browser extensions in Chrome and Edge for command execution post-compromise. Additionally, a zero-day vulnerability in Magento and Adobe…
2 articles · Updated September 8, 2026 -
Active Exploitation of Magento Zero-Day Vulnerability 'StyleSmuggler'
A new unpatched vulnerability, named StyleSmuggler, has been discovered in Magento Open Source and Adobe Commerce, allowing unauthenticated attackers to execute remote code. The attacks began on September 4, 2026, and…
30 articles · Updated September 5, 2026 -
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These…
57 articles · Updated September 8, 2026 -
Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks
A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication,…
5 articles · Updated May 15, 2026 -
Critical PHP Object Injection Vulnerability in Mirasvit Cache Warmer
A critical vulnerability, CVE-2026-45247, has been identified in the Mirasvit Full Page Cache Warmer for Magento 2, allowing unauthenticated remote code execution via a crafted CacheWarmer cookie. The flaw, rated 9.8 on…
8 articles · Updated June 4, 2026 -
Critical Adobe Commerce Flaw Allows Account Takeover
A critical vulnerability (CVE-2026-71362) in Adobe Commerce and Magento platforms has been exploited, allowing unauthenticated attackers to hijack customer accounts. The flaw, rated 9.1 on the CVSS scale, enables…
6 articles · Updated August 12, 2026
Recent Intelligence Reports
- September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows — Csoonline · September 9, 2026
- Microsoft breaks Patch Tuesday record with 974-CVE deluge — Theregister · September 9, 2026
- Microsoft Patch Tuesday September 2026 Security Update Review — blog.qualys.com · September 8, 2026
- Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited — Therecord.Media · September 8, 2026
- CVE Alert: CVE-2026-75650 – Adobe — Redpacketsecurity · September 8, 2026
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days — Bleepingcomputer · September 8, 2026
- Chrome/Edge backdoors, Magento zero-day, Microsoft 365 phishing at scale — Defendwork · September 8, 2026
- N-able Pre-Auth RCE, Magento StyleSmuggler Zero-Day, and MikroTik MikroTrick Router Takeovers — Rodtrent.Substack · September 7, 2026