Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated July 31, 2026 — 169 published advisories, with new analysis most weekdays. Recent coverage includes a Cisco Secure Firewall Management Center zero-day already under active exploitation (CVE-2026-20316), an OpenWrt DHCPv6 flaw that hands over root without any authentication (CVE-2026-53921), a pre-authentication remote code execution bug affecting every on-premises JetBrains TeamCity build server (CVE-2026-63077), a CVSS 10.0 Arista VeloCloud Orchestrator flaw already exploited in the wild (CVE-2026-16812), and the fastjson deserialization remote code execution bug still shipping without a patch (CVE-2026-16723). If one of these touches a system you run and you are not sure what to do next, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
100 articles found
Featured Story
CVE-2026-48282
critical
Jul 8, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Adobe ColdFusion Bug (CVE-2026-48282) Weaponized Within Hours as CISA Starts the Patch Clock

Adobe ColdFusion is under active attack through CVE-2026-48282, a CVSS 10.0 path traversal flaw in the Remote Development Services component that hands unauthenticated attackers remote code execution. Exploitation began within about two hours of disclosure, and CISA has added it to its Known Exploited Vulnerabilities catalog with a July 10 federal patch deadline. Patch to ColdFusion 2025 update 10 or 2023 update 21 now.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityJul 7, 2026

CRITICAL: BeyondTrust Auth Bypass Flaws Hand Attackers the Keys to Remote Support and PRA

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two unauthenticated CVSS 9.2 auth bypass bugs (CVE-2026-40138 and CVE-2026-40139) that let network-positioned attackers reach elevated accounts. All versions at or below 25.3.2 are vulnerable, with fixes in the 25.3.3 line. Cloud customers were patched April 21 2026, so self-hosted admins are the ones who need to move now.

Read more
CVE-2026-46242
high
CVE AdvisoryVulnerabilityCVE-2026-46242 Jul 5, 2026

HIGH: Bad Epoll Linux Kernel Flaw Hands Any User Root on Servers and Android (CVE-2026-46242)

A use-after-free race condition in the Linux kernel epoll subsystem lets an unprivileged local user escalate to root with roughly 99 percent reliability. It affects kernel 6.4 and newer across servers, desktops, and Android, can be triggered from a Chrome renderer sandbox, and has no workaround. Only a patched kernel fixes it.

Read more
critical
CVE AdvisoryVulnerabilityJun 19, 2026

CRITICAL: F5 Patches Two NGINX Flaws Handing Unauthenticated RCE to Remote Attackers

F5 disclosed two critical NGINX vulnerabilities on June 17, 2026, both scoring CVSS 4.0 9.2. CVE-2026-42530 is a use-after-free in the HTTP/3 QPACK encoder and CVE-2026-42055 is a heap-based buffer overflow in the HTTP/2 proxy and gRPC modules. Both are remotely exploitable by unauthenticated attackers and affect a huge swath of the NGINX Open Source and NGINX Plus install base.

Read more
high
CVE AdvisoryVulnerabilityJun 18, 2026

HIGH: Microsoft Defender RoguePlanet Zero-Day Hits SYSTEM Without a Patch in Sight (CVE-2026-50656)

Researcher Nightmare Eclipse dropped a public PoC for CVE-2026-50656 (RoguePlanet), a TOCTOU race condition in the Microsoft Defender Malware Protection Engine that yields NT AUTHORITY\SYSTEM on fully patched Windows 10 and Windows 11. Microsoft has confirmed the flaw, rated it CVSS 7.8, and is still working on a patch. The PoC works whether real-time protection is enabled or not, leaving defenders with detection and containment as the only options for now.

Read more
critical
CVE AdvisoryVulnerabilityJun 17, 2026

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Attackers Chain Auth Bypass and Command Injection

Three critical FortiSandbox vulnerabilities are under active exploitation, led by CVE-2026-39813, a path traversal flaw in the JRPC API that lets unauthenticated attackers bypass authentication via crafted HTTP requests. Paired with two OS command injection bugs, the chain gives remote code execution on appliances running FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. Upgrade to 5.0.6 or 4.4.9 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJun 16, 2026

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Defenders Race to Patch

Defused Cyber reported active exploitation of three CVSS 9.1 FortiSandbox vulnerabilities inside a 24-hour window. CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 allow unauthenticated remote code execution and authentication bypass on the appliance that other Fortinet products trust to verdict malware. Patches are available, but the 4.2 branch requires migration to a supported release.

Read more
CVE-2026-5027
high
CVE AdvisoryVulnerabilityCVE-2026-5027 Jun 11, 2026

HIGH: Langflow Path Traversal CVE-2026-5027 Lets Unauthenticated Attackers Plant Code on Roughly 7,000 Exposed AI Servers

A path traversal flaw in Langflow's POST /api/v2/files endpoint allows unauthenticated attackers to write files anywhere the platform process can reach, opening a clean route to remote code execution on the roughly seven thousand exposed instances Censys is currently tracking. Tenable disclosed CVE-2026-5027 in late March, the maintainers shipped a fix in version 1.10.0 on June 10, and VulnCheck honeypots are catching exploitation right now. Patch immediately or pull the instance off the public internet.

Read more
CVE-2026-11645
high
CVE AdvisoryVulnerabilityCVE-2026-11645 Jun 10, 2026

HIGH: Chrome V8 Zero-Day CVE-2026-11645 Under Active Exploitation, Patch Today

Google confirmed active in the wild exploitation of CVE-2026-11645, an out-of-bounds read and write vulnerability in Chrome V8 with a CVSS score of 8.8. The fifth Chrome zero day patched in 2026 lets attackers run code inside the browser sandbox via a crafted HTML page. Update to Chrome 149.0.7827.102 or .103 immediately and force a relaunch across the fleet.

Read more
CVE-2026-42271
critical
CVE AdvisoryVulnerabilityCVE-2026-42271 Jun 9, 2026

CRITICAL: LiteLLM RCE Chain Hits CISA KEV as Attackers Hammer Exposed AI Gateways

LiteLLM CVE-2026-42271 chained with Starlette CVE-2026-48710 (BadHost) creates an unauthenticated RCE path scoring CVSS 10.0 against AI gateways. CISA added the flaw to the KEV catalog after confirming active exploitation. Patch LiteLLM 1.83.7 and Starlette 1.0.1 immediately or block the vulnerable MCP test endpoints at your reverse proxy.

Read more
CVE-2026-20230
high
CVE AdvisoryVulnerabilityCVE-2026-20230 Jun 7, 2026

HIGH: Cisco Unified Communications Manager SSRF Flaw Has a Public PoC and a Root-Level Punchline (CVE-2026-20230)

Cisco's June 3 advisory for CVE-2026-20230 details a critical-rated SSRF in the Unified Communications Manager WebDialer service, with a CVSS 8.6 base score and a public proof-of-concept already in circulation. An unauthenticated attacker on the network can write arbitrary files to the underlying OS and chain that into root. Cisco has released fixes in 14SU6 and an interim COP for the 15 line, with 15SU5 due in September 2026. Disabling WebDialer is the recommended interim mitigation.

Read more
CVE-2026-20245
high
CVE AdvisoryVulnerabilityCVE-2026-20245 Jun 6, 2026

HIGH: Cisco Catalyst SD-WAN Manager Zero-Day Under Active Exploitation, No Patch Available (CVE-2026-20245)

Cisco confirmed active exploitation of CVE-2026-20245, an unpatched command injection flaw in Catalyst SD-WAN Manager that lets authenticated attackers escalate to root and push malicious configurations to edge devices. The CVSS 7.8 bug is the seventh exploited SD-WAN zero-day since 2023 and chains with two prior auth bypass vulnerabilities to enable full remote takeover. No patch is available.

Read more
CVE-2026-20230
critical
CVE AdvisoryVulnerabilityCVE-2026-20230 Jun 5, 2026

CRITICAL: Cisco Unified CM SSRF Flaw CVE-2026-20230 Hands Attackers Root, PoC Already Public

Cisco patched CVE-2026-20230, an unauthenticated SSRF in the Unified Communications Manager WebDialer Web Service that lets remote attackers write arbitrary files and escalate to root. Public proof-of-concept code is already circulating. CVSS 8.6 with a Critical Security Impact Rating from Cisco PSIRT. Version 14SU6 is fixed, but the 15 train waits until September 2026 for 15SU5 with only an interim COP patch available now.

Read more
CVE-2026-45247
critical
CVE AdvisoryVulnerabilityCVE-2026-45247 Jun 4, 2026

CRITICAL: Active Exploitation Hits Magento Stores via Mirasvit Cache Warmer Bug (CVE-2026-45247)

CISA added CVE-2026-45247, a CVSS 9.8 PHP object deserialization flaw in the Mirasvit Full Page Cache Warmer extension for Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog after Imperva confirmed active unauthenticated RCE attacks against gaming and business storefronts in the US, UK, France, and Australia. Patch to version 1.11.12 or disable the extension immediately.

Read more
CVE-2026-49975
high
CVE AdvisoryVulnerabilityCVE-2026-49975 Jun 3, 2026

HIGH: HTTP/2 Bomb Vulnerability Lets a Home Connection Flatten NGINX, Apache, IIS, Envoy, and Cloudflare Pingora

A newly disclosed HTTP/2 vulnerability dubbed HTTP/2 Bomb lets a single client on a residential connection exhaust 32 gigabytes of server memory in under twenty seconds. The flaw, tracked as CVE-2026-49975 for Apache httpd, affects NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. NGINX and Apache shipped fixes. IIS, Envoy, and Pingora remain unpatched as of public disclosure on June 2, 2026.

Read more
CVE-2026-0257
critical
CVE AdvisoryVulnerabilityCVE-2026-0257 Jun 2, 2026

CRITICAL: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation

An authentication bypass flaw in PAN-OS GlobalProtect portal and gateway (CVE-2026-0257, CVSS 9.1) is under active exploitation. Rapid7 confirmed in-the-wild attacks beginning May 17, and the CISA federal remediation deadline expired June 1. Patches and workarounds are available across PAN-OS 10.2, 11.1, 11.2, and 12.1 branches.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 2 of 5Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.