Related Threat Clusters
-
HPE OneView Software Vulnerability Enables Remote Code Execution
Hewlett Packard Enterprise (HPE) has addressed a critical vulnerability in its OneView software, identified as CVE-2025-37164, which allows attackers to execute arbitrary code remotely without authentication. This flaw…
15 articles · Updated December 18, 2025 -
Critical Oracle WebLogic Flaw Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-21962, a critical vulnerability affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities…
17 articles · Updated August 25, 2026 -
Critical Apache HTTP Server Vulnerability Poses Remote Code Execution Risk
The Apache Software Foundation has issued an urgent security update for the Apache HTTP Server to address a severe vulnerability tracked as CVE-2026-23918, published on 2026-05-04. This flaw allows attackers to execute…
21 articles · Updated May 5, 2026 -
Critical RCE Vulnerability in Windchill and FlexPLM Triggers Urgent Alerts
PTC Inc. has disclosed a critical vulnerability, CVE-2026-4681, in its Windchill and FlexPLM software that allows for remote code execution through the deserialization of trusted data. The vulnerability has been…
4 articles · Updated March 24, 2026 -
Oracle Linux 9 Vulnerabilities Lead to Critical Security Advisories
Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows…
4 articles · Updated June 25, 2026 -
Critical BadHost Vulnerability Exposes AI Applications to Authentication Bypass
A severe vulnerability known as BadHost (CVE-2026-48710) has been identified in the Starlette framework, affecting millions of AI applications, including those built on FastAPI. This flaw allows unauthenticated…
16 articles · Updated May 26, 2026 -
New HTTP/2 Bomb DoS Attack Crashes Major Web Servers
The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack,…
11 articles · Updated June 3, 2026 -
Multiple CVEs Disclosed for Apache HTTP Server Vulnerabilities
Four vulnerabilities affecting the Apache HTTP Server have been disclosed, including source code disclosures and denial-of-service (DoS) issues. The vulnerabilities, identified as CVE-2024-39884, CVE-2024-40725,…
9 articles · Updated February 18, 2026 -
Fedora Releases Critical Update for Apache HTTP Server to Fix Security Flaws
Fedora has issued a critical security update for the Apache HTTP Server, addressing severe vulnerabilities identified as CVE-2025-58098. The update, version 2.4.66, was released on December 9, 2025, and affects users of…
2 articles · Updated December 25, 2025 -
Oracle Linux 10 mod_http2 DoS Vulnerabilities Disclosed
Oracle has released advisories for multiple denial-of-service (DoS) vulnerabilities affecting mod_http2 in Oracle Linux 10. The vulnerabilities include CVE-2026-43951, CVE-2026-48913, and CVE-2026-49975, all published…
3 articles · Updated July 20, 2026
Recent Intelligence Reports
- CVE-2026-21962 — nvd.nist.gov · August 25, 2026
- Oracle Linux 10 mod_http2 Important DoS Vulnerability ELSA-2026 — Linuxsecurity · July 20, 2026
- Oracle Linux 10 mod_http2 Moderate DoS Advisory ELSA-2026 — Linuxsecurity · July 20, 2026
- Oracle Linux 9 mod_http2 Important Remote DoS Advisory ELSA-2026 — Linuxsecurity · June 25, 2026
- Oracle Linux 9 httpd Important Buffer Overflow Advisory ELSA-2026 — Linuxsecurity · June 25, 2026
- Tracker — www.globenewswire.com · June 11, 2026
- New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute — Bleepingcomputer · June 3, 2026
- FastAPI — Csoonline · May 27, 2026