vulnerability Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL ServiceNow has released security patches for four critical vulnerabilities in its AI Platform, including three rated at 10.0 CVSS, that could allow unauthenticated attackers to execute code, create or modify instance data, and potentially gain access to underlying databases. While ServiceNow states it’s not currently a… The Hacker News · 2d ago Critical CVE-2026-18885CVE-2026-18886CVE-2026-74820cvssvulnerabilitycode injection
threat-intel China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access A Chinese-made router manufacturer, Zhibotong Electronics (ZBT) through its brand Zbtlink, ships routers with two factory-installed implants – SPEAKINGSTONE and DARKLANTERN – that provide unauthenticated remote access to… The Hacker News · 2d ago High CVE-2026-74232CVE-2026-74233CVE-2026-66747CHc2routerfirmware
vulnerability Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patch… The Hacker News · 6d ago Critical CVE-2026-18963CVE-2026-15571password-resetauthenticationkeycloak
vulnerability GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure A critical vulnerability (CVE-2026-19478) in GitLab, allowing unauthenticated code injection and data manipulation, has been actively exploited shortly after its disclosure. This poses a significant risk to organizations… The Hacker News · Aug 21, 2026 Critical CVE-2026-19478vulnerabilitycode-injectiongraphql
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
vulnerability Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A critical vulnerability in Windmill, a popular open-source developer platform, is being actively exploited to allow attackers to read arbitrary server files without needing any credentials. This unauthenticated path tra… The Hacker News · Jul 22, 2026 High CVE-2026-29059path traversalunauthenticatedserver files
threat-intel Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters An unpatched vulnerability in Argo CD's repo-server component allows unauthenticated attackers to take over Kubernetes clusters by exploiting a lack of authentication and network policies. Synacktiv discovered the flaw i… The Hacker News · Jul 1, 2026 Critical CVE-2024-31989CVE-2025-55190CVE-2026-42880kubernetesargo cdnetwork policy
vulnerability Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A critical vulnerability, CVE-2026-5027, in the Langflow low-code platform has been actively exploited, allowing for remote code execution due to a lack of input sanitization. This flaw, combined with unauthenticated aut… The Hacker News · Jun 10, 2026 Critical CVE-2026-5027CVE-2026-0770CVE-2026-33017USCAlow-codeairemote code execution
ransomware LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE A critical command injection vulnerability (CVE-2026-42271) in BerriAI’s LiteLLM has been actively exploited in the wild. The flaw, combined with a separate Starlette vulnerability (CVE-2026-48710), allows for unauthenti… The Hacker News · Jun 9, 2026 Critical CVE-2026-42271CVE-2026-48710CVE-2026-42208command injectionremote code executionunauthenticated
vulnerability KMW CCTV Security Cameras This advisory details a critical vulnerability in KMW CCTV Security Cameras, specifically versions KM-IP521 (V4.04.91.230307) and KM-IP421 (V4.04.53.210416), allowing unauthorized access to camera feeds and settings via… CISA Advisories · May 28, 2026 Critical CVE-2026-5386WOcctvpasswordunauthenticated