Tag: vulnerability

Netlogon CVE-2026-41089 RCE

CVE-2026-41089 is now reported as actively exploited. Patch Windows Server domain controllers…

Brendan Smith

WP Maps Pro CVE-2026-8732

WP Maps Pro CVE-2026-8732 lets unauthenticated attackers create WordPress administrator accounts. Update…

Brendan Smith

Flowise Chatflow RCE

Flowise CVE-2026-40933 can turn a malicious chatflow import into server-side command execution.…

Brendan Smith

EMS Patch Trap

FortiClient EMS CVE-2026-35616 was abused to push EKZ Infostealer as a fake…

Brendan Smith

PAN-OS CVE-2026-0257 Patch

CISA added PAN-OS CVE-2026-0257 to KEV after exploitation. Check GlobalProtect portals and…

Stephanie Adlam

Gogs RCE Zero-Day: Check Open Registration

Rapid7 disclosed a critical unpatched Gogs RCE path. Check open registration, repository…

Stephanie Adlam

Ghost CMS Exploit Poisons 700 Sites for ClickFix Malware

Attackers are exploiting Ghost CMS CVE-2026-26980 to inject ClickFix loaders into trusted…

Stephanie Adlam

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited for Root Scripts

LiteSpeed says CVE-2026-48172 is being actively exploited in its user-end cPanel plugin.…

Stephanie Adlam

Langflow CVE-2025-34291: Token Hijack and RCE Added to CISA KEV

Langflow CVE-2025-34291 can turn a malicious webpage into account takeover and RCE…

Stephanie Adlam

Trend Micro Apex One CVE-2026-34926 Exploited in the Wild

Trend Micro patched an Apex One on-prem directory traversal flaw after observing…

Stephanie Adlam

Microsoft Defender CVE-2026-41091 and CVE-2026-45498 Exploited

Microsoft says two Defender flaws have been exploited. CISA added both to…

Stephanie Adlam

Drupal Core CVE-2026-9082: PostgreSQL SQL Injection Patch

Drupal core CVE-2026-9082 is a highly critical PostgreSQL SQL injection flaw. Check…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?