threat-intel CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six previously exploited vulnerabilities to its KEV catalog, including flaws in Citrix NetScaler, Linux, and Microsoft SQL Server. These vulnerabilities are actively being exploited, with telemetry showing attacks originating from various countr… The Hacker News · 3d ago High CVE-2019-1068CVE-2026-8452CVE-2022-0995SWGEHOkevexploitationvulnerability
vulnerability Recent Citrix NetScaler Vulnerability Exploited in the Wild A critical Citrix NetScaler vulnerability (CVE-2026-8452) is currently being actively exploited in the wild, prompting CISA to urge immediate action from government agencies. The vulnerability allows for unauthenticated… SecurityWeek · 3d ago High CVE-2026-8452CVE-2026-8451vulnerabilityremote code executionunpatched
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
vulnerability Exploited Zimbra Flaw Highlights Shrinking Window to Patch A critical vulnerability in Zimbra Unified Communications Suite (ZCS) is being aggressively exploited, prompting CISA to issue a three-day deadline for federal agencies to patch. The flaw, CVE-2026-73570, allows unauthen… Dark Reading · 6d ago High CVE-2026-73570CVE-2026-73750CVE-2025-66376PORULIpatchingvulnerabilityremote code execution
threat-intel NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology The NSA and FBI have issued an urgent warning about a growing threat where hackers are utilizing AI-generated exploit scripts to target critical infrastructure organizations, specifically focusing on Siemens S7 Series PL… The Record · Aug 19, 2026 High IRplccybersecurityai
vulnerability Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure A critical vulnerability in SAP Commerce Cloud was rapidly exploited by hackers just days after its public announcement. The flaw, tracked as CVE-2026-58231, allows for arbitrary code execution and poses a significant ri… SecurityWeek · Aug 17, 2026 Critical CVE-2026-58231CVE-2019-0344sapcommercevulnerability
vulnerability SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch A critical security vulnerability (CVE-2026-58231) in SAP Commerce Cloud is being actively exploited, despite a patch being available for days. The flaw stems from inadequate input validation, potentially leading to code… The Hacker News · Aug 15, 2026 Critical CVE-2026-58231CVE-2025-31324USsapvulnerabilitypatch
vulnerability Hackers Exploiting Unpatched GeoServer Zero-Day A zero-day vulnerability in GeoServer is being actively exploited by threat actors shortly after its public disclosure. The flaw, a SQL injection, allows remote code execution and has prompted immediate action from secur… SecurityWeek · Aug 14, 2026 High sql injectionzero-dayremote code execution
vulnerability SharePoint Vulnerability Exploited Shortly After PoC Release A SharePoint vulnerability, patched last month, is now being actively exploited in the wild, with attackers leveraging a publicly released proof-of-concept. This follows a series of similar vulnerabilities discovered thi… SecurityWeek · Aug 12, 2026 High CVE-2026-55040CVE-2026-63520CVE-2026-50522sharepointvulnerabilityexploitation
threat-intel CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited The U.S. CISA has added three vulnerabilities to its KEV catalog, including a critical code injection flaw in Langflow, a Tomcat encryption bypass, and an authentication bypass in N-able N-central. These flaws are curren… The Hacker News · Aug 5, 2026 Critical CVE-2026-9198CVE-2026-34486CVE-2026-18556CNvulnerabilitythreat-actorai
vulnerability Attackers Exploit N-able Patch Bypass Flaw on RMM Servers N-able disclosed a patch bypass vulnerability (CVE-2026-18577) that allowed attackers to gain administrative access to N-central servers, its remote monitoring and management (RMM) platform. Threat actors exploited this… Dark Reading · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556patch-bypassremote-managementrmm
vulnerability Cisco Secure FMC Zero-Day Exploited in the Wild A zero-day vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC) is being actively exploited in the wild. Attackers are leveraging default credentials to gain access to sensitive data, and Cisco… SecurityWeek · Jul 30, 2026 High CVE-2026-20316CVE-2026-20079zero-dayvulnerabilitycisco
vulnerability Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data A zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) software is actively being exploited, allowing unauthenticated remote attackers to gain access to sensitive data. The vulnerability stems from sta… The Hacker News · Jul 30, 2026 High CVE-2026-20316CVE-2026-20079zero-dayauthenticationremote
vulnerability Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw A maximum-severity command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator (VCO) has been actively exploited in the wild, allowing remote code execution and potential access to VeloCloud Edge de… The Hacker News · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2026-16723command injectionvcocisa
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026) Multiple vulnerabilities have been discovered in the Red Hat Linux kernel. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service attack. These vulne… CERT-FR · Jul 24, 2026 High CVE-2024-46738CVE-2024-50076CVE-2025-39982linuxkernelvulnerability
threat-intel Is Patching Dead? Vulnerability Management in the Post-Mythos Era The U.S. government is deploying a new AI-powered system, Gold Eagle, to proactively identify and remediate software vulnerabilities across federal agencies and critical infrastructure. This initiative is driven by the i… SecurityWeek · Jul 23, 2026 High USvulnerabilityaicybersecurity
threat-intel OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy OVH, a cloud infrastructure provider, is addressing a critical bug in its Januscape hypervisor through a planned system-wide reboot. This follows reports of exploitation attempts targeting the vulnerability, highlighting… The Register · Jul 21, 2026 High CVE-2026-53359hypervisorcloud securityvulnerability
threat-intel WP2Shell WordPress Vulnerabilities Exploited in the Wild Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress site… SecurityWeek · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina