vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
vulnerability Digi International PortServer TS, Digi One SP IA Digi International has issued a security advisory regarding critical vulnerabilities (CVE-2026-12948) in its PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices. These vulnerabilities allow an unauthentic… CISA Advisories · Jul 7, 2026 High CVE-2026-12352CVE-2026-12948xsscveweb-management
threat-intel AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network A new malware family, dubbed AryStinger, is exploiting vulnerabilities in older Realtek RTL819X routers to create a reconnaissance network. Approximately 4,300 routers, primarily D-Link models, have been infected, scanni… The Hacker News · Jun 22, 2026 Medium CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSEreconnaissanceproxyiot
vulnerability Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT This CISA advisory details a vulnerability in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT, specifically version 0x0110_v1.1.0. The device is susceptible to unauthorized interception of sensitive health… CISA Advisories · Jun 18, 2026 High CVE-2026-50034CVE-2026-52866INbluetoothbleglucose
vulnerability Multiples vulnérabilités dans Mattermost Desktop App (18 juin 2026) Multiple vulnerabilities have been discovered in the Mattermost Desktop App, potentially allowing for remote denial-of-service attacks and an unspecified security issue. These vulnerabilities affect older versions of the… CERT-FR · Jun 18, 2026 Medium CVE-2026-8075CVE-2026-9602vulnerabilitymattermostdesktop app
vulnerability Rockwell Automation FactoryTalk Analytics PavilionX This advisory from CISA details a critical vulnerability in Rockwell Automation’s FactoryTalk Analytics PavilionX software, specifically versions below 7.01. The flaw, stemming from improper authorization enforcement in… CISA Advisories · Jun 16, 2026 Critical CVE-2025-14272UScveauthorizationapi
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
vulnerability Multiples vulnérabilités dans les produits Mattermost (15 juin 2026) Multiple vulnerabilities have been discovered in Mattermost Server, potentially allowing an attacker to cause a security issue not specified by the vendor. These vulnerabilities could lead to data integrity and confident… CERT-FR · Jun 15, 2026 Medium CVE-2026-10085CVE-2026-10103CVE-2026-10106vulnerabilitymattermostsecurity
vulnerability Vulnérabilité dans Traefik (11 juin 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This issue affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to p… CERT-FR · Jun 11, 2026 Medium CVE-2026-54761traefikvulnerabilitysecurity
vulnerability CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation CISA has added three newly exploited vulnerabilities to its KEV catalog, impacting Cisco, Google Chrome, and Arista Networks. These vulnerabilities – one in Cisco SD-WAN Manager, another in Chrome’s V8 engine, and a thir… The Hacker News · Jun 10, 2026 High CVE-2026-20245CVE-2026-11645CVE-2026-7473cvesd-wanchrome
vulnerability Schneider Electric Modicon Network Managed Switches Schneider Electric has identified a vulnerability (CVE-2024-3596) in its Modicon Network Managed Switches due to a misconfigured RADIUS protocol. Specifically, disabling the RADIUS Server Message Authenticator option mak… CISA Advisories · Jun 9, 2026 High CVE-2024-3596WOradiuscvesecurity
vulnerability Critical Everest Forms Pro flaw exploited to take over WordPress sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution,… BleepingComputer · Jun 6, 2026 Critical CVE-2026-3300wordpresspluginvulnerability
vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execu… The Hacker News · Jun 6, 2026 Critical CVE-2026-20245CVE-2026-20182CVE-2026-20127sd-wancvezero-day
vulnerability Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 Cisco has issued a security advisory regarding a newly discovered zero-day vulnerability (CVE-2026-20245) within its SD-WAN Manager product. This vulnerability, exploitable via command injection, has been actively used b… SecurityWeek · Jun 5, 2026 High CVE-2026-20245CVE-2026-20182CVE-2026-20127zero-daycommand injectionsd-wan
vulnerability NAVTOR NavBox A critical vulnerability (CVE-2026-21404) has been identified in NAVTOR NavBox versions 4.16.1.20, allowing local attackers to gain unauthorized access due to hard-coded credentials within the Windows Communication Found… CISA Advisories · Jun 4, 2026 Critical CVE-2026-21404NOsoapcredentialswcf
vulnerability Multiples vulnérabilités dans les produits Mattermost (29 mai 2026) Multiple vulnerabilities have been discovered in Mattermost Server, allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities, detailed in Mattermost security bulletins, re… CERT-FR · May 29, 2026 Medium CVE-2026-3472CVE-2026-4339vulnerabilitymattermostsecurity
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
vulnerability Multiples vulnérabilités dans les produits Mattermost (22 mai 2026) Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions… CERT-FR · May 22, 2026 Medium CVE-2026-5139CVE-2026-6062CVE-2026-6517vulnerabilitysecuritypatch
vulnerability Siemens Ruggedcom Rox This CISA advisory details a vulnerability affecting Siemens Ruggedcom Rox devices. The devices, specifically versions prior to 2.17.1, contain multiple third-party vulnerabilities, including those listed in CVEs from 20… CISA Advisories · May 14, 2026 Medium CVE-2019-13103CVE-2019-13104CVE-2019-13106vulnerabilitypatchingcve