Related Threat Clusters
-
Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)
CVE-2026-52887 is a critical SQL injection vulnerability affecting NocoBase, an AI-powered no-code/low-code platform. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries via the…
2 articles · Updated July 16, 2026 -
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
Critical SQL Injection Vulnerability in Drupal Core Actively Exploited
A critical SQL injection vulnerability (CVE-2026-9082) in Drupal Core has been identified, affecting multiple supported versions. The vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to execute…
6 articles · Updated May 25, 2026 -
Critical Exploitation of Sangoma Switchvox Vulnerabilities Underway
Sangoma Switchvox SMB Edition 8.3 is facing active exploitation of multiple vulnerabilities, particularly CVE-2026-9586, which allows unauthenticated SQL injection leading to remote code execution. The flaw can be…
11 articles · Updated September 2, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Veeam Discloses Critical RCE Vulnerability in Backup Software
Veeam reported a critical Remote Code Execution (RCE) vulnerability in its backup and replication software, identified as CVE-2025-59470, with a CVSS score of 9.0. The vulnerability highlights risks associated with…
1 article · Updated January 29, 2026 -
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
A sophisticated cyber campaign has exploited a critical cPanel vulnerability (CVE-2026-41940) to breach government and military servers in Southeast Asia, particularly targeting Indonesia. The attackers utilized a…
3 articles · Updated May 4, 2026 -
Critical RCE Vulnerabilities Under Active Exploitation
Multiple critical vulnerabilities are currently being exploited, including remote code execution (RCE) flaws in HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and…
2 articles · Updated September 6, 2026 -
Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
pgAdmin 4 version 9.16 was released to patch seven vulnerabilities, including critical issues tracked as CVE-2026-12044 to CVE-2026-12050. These vulnerabilities could allow attackers to execute arbitrary commands, gain…
9 articles · Updated June 22, 2026 -
Critical SQL Injection Vulnerability in Kestra (CVE-2026-34612)
A critical SQL Injection vulnerability, identified as CVE-2026-34612, affects Kestra versions prior to 1.3.7. This vulnerability exists in the GET /api/v1/main/flows/ endpoint of the default Docker Compose deployment,…
2 articles · Updated April 4, 2026
Recent Intelligence Reports
- CVE 2026 6471 — www.postgresql.org · September 9, 2026
- CVE-2023-27524-Apache-Superset-Auth-Bypass-and — Sploitus · September 7, 2026
- [SecurityIntel] 05 Sep | Critical RCEs Actively Exploited — Buttondown · September 5, 2026
- Postgreshell The Database Powering Much Of The Internet Had An Open Door For 12 Years — www.cyera.com · September 4, 2026
- Postgreshell The Database Powering Much Of The Internet Had An Open Door For 12 Years — www.cyera.com · September 4, 2026
- OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders — Securityweek · September 4, 2026
- 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover — Feeds.Feedburner · September 4, 2026
- SUSE PostgreSQL 15 Key Buffer Overflow and SQL Injection Issues Addressed — Linuxsecurity · September 3, 2026