Tag: Exploit

WP Maps Pro CVE-2026-8732

WP Maps Pro CVE-2026-8732 lets unauthenticated attackers create WordPress administrator accounts. Update…

Brendan Smith

Flowise Chatflow RCE

Flowise CVE-2026-40933 can turn a malicious chatflow import into server-side command execution.…

Brendan Smith

EMS Patch Trap

FortiClient EMS CVE-2026-35616 was abused to push EKZ Infostealer as a fake…

Brendan Smith

PAN-OS CVE-2026-0257 Patch

CISA added PAN-OS CVE-2026-0257 to KEV after exploitation. Check GlobalProtect portals and…

Stephanie Adlam

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited for Root Scripts

LiteSpeed says CVE-2026-48172 is being actively exploited in its user-end cPanel plugin.…

Stephanie Adlam

Langflow CVE-2025-34291: Token Hijack and RCE Added to CISA KEV

Langflow CVE-2025-34291 can turn a malicious webpage into account takeover and RCE…

Stephanie Adlam

Trend Micro Apex One CVE-2026-34926 Exploited in the Wild

Trend Micro patched an Apex One on-prem directory traversal flaw after observing…

Stephanie Adlam

Microsoft Defender CVE-2026-41091 and CVE-2026-45498 Exploited

Microsoft says two Defender flaws have been exploited. CISA added both to…

Stephanie Adlam

Drupal Core CVE-2026-9082: PostgreSQL SQL Injection Patch

Drupal core CVE-2026-9082 is a highly critical PostgreSQL SQL injection flaw. Check…

Stephanie Adlam

ChromaDB CVE-2026-45829 Allows Pre-Auth Server Takeover

HiddenLayer disclosed ChromaToast, a pre-auth RCE in ChromaDB Python FastAPI server deployments…

Stephanie Adlam

MiniPlasma Windows Zero-Day PoC Gives Local Users SYSTEM Access

A public MiniPlasma proof-of-concept shows local privilege escalation to SYSTEM on fully…

Stephanie Adlam

Anthropic Mythos Helped Build a macOS M5 Kernel Exploit

Calif says researchers used Anthropic’s Mythos Preview to build a local macOS…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?