Related Threat Clusters
-
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical RCE Vulnerability in Zimbra Exploited by Attackers
A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers…
35 articles · Updated August 19, 2026 -
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
The inaugural July 2026 InfraTrust Pulse report reveals critical vulnerabilities affecting infrastructure devices, particularly SonicWall's SMA1000 and Fortinet's FortiSandbox. SonicWall's CVE-2026-15409 and…
6 articles · Updated July 22, 2026 -
Critical OS Command Injection Vulnerability in wg-easy 15.3.0 Disclosed
A severe OS command injection vulnerability (CVE-2026-72603) has been identified in wg-easy version 15.3.0. This flaw allows authenticated users with clients.create permission to inject newline-delimited WireGuard…
4 articles · Updated August 11, 2026 -
Critical FortiSIEM Vulnerability CVE-2025-64155 Under Active Exploitation
A critical vulnerability (CVE-2025-64155) in Fortinet's FortiSIEM platform allows unauthenticated remote code execution via crafted TCP requests. This OS command injection flaw affects the phMonitor service, which is…
3 articles · Updated January 15, 2026 -
Critical Command Injection Vulnerability in D-Link DWR-M961 Devices
A critical command injection vulnerability, CVE-2026-71954, has been identified in D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108. This vulnerability allows…
2 articles · Updated August 9, 2026 -
CISA Adds Seven Exploited Vulnerabilities; IBM Warns of Langflow OSS Flaws
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including CVE-2026-9586, a SQL injection vulnerability in Sangoma Switchvox, and several others affecting SonicWall and JFrog…
2 articles · Updated September 2, 2026 -
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
38 articles · Updated June 10, 2026 -
Critical RCE Vulnerabilities Discovered in Fortinet Products
Fortinet has identified multiple critical vulnerabilities in its FortiSandbox and FortiAuthenticator products, which could allow unauthenticated attackers to execute arbitrary code remotely. The vulnerabilities are…
107 articles · Updated May 12, 2026 -
FortiWeb Vulnerabilities Exploited: Path Traversal and OS Command Injection
Two vulnerabilities in FortiWeb have been identified, both exploited in the wild. The first, a relative path traversal vulnerability (CWE-23), allows unauthenticated attackers to execute administrative commands via…
2 articles · Updated June 17, 2026
Recent Intelligence Reports
- vulncheck.com: VulnCheck Advisory: n8n before 1.123.73 Remote Code Execution via Git Node external site — www.vulncheck.com · September 3, 2026
- SUSE yast2-users Important OS Command Injection Vuln 2026-3948 — Linuxsecurity · September 3, 2026
- SUSE yast2-users Important OS Command Injection Vuln 2026-3949 — Linuxsecurity · September 3, 2026
- CISA Adds Seven Known Exploited Vulnerabilities to Catalog — Cisa · September 2, 2026
- SUSE Yast2-Samba-Client Important OS Command Injection Fix 2026-3886 — Linuxsecurity · September 1, 2026
- openSUSE yast2-samba-client Important Command Injection Issue 2026-3887 — Linuxsecurity · September 1, 2026
- SUSE Important yast2-auth-client OS Command Injection Fix 2026-3901 — Linuxsecurity · September 1, 2026
- CVE-2026-75121 - Exploits & Severity — Feedly · August 29, 2026