Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated August 19, 2026 — 188 published advisories, with new analysis most weekdays. Recent coverage includes a flaw in the Ray AI framework that a botnet exploited before it was even public, which CISA has now ordered federal agencies to fix by August 20 (CVE-2025-62593), a SAP Commerce Cloud flaw attackers began exploiting within days of the patch, giving them a way to run their own code on your storefront (CVE-2026-58231), a Cisco firewall flaw attackers are using to knock remote-access VPNs offline, cutting staff off from the network (CVE-2026-20349), an Adobe ColdFusion flaw rated the maximum 10.0 severity that lets an attacker run commands on your server without ever logging in (CVE-2026-48362), and a SharePoint flaw attackers are using to walk past the login screen entirely, now that working exploit code is public (CVE-2026-55040). If one of these touches a system you run and you are not sure what to do next, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
113 articles found
critical
CVE AdvisoryVulnerabilityJul 21, 2026

CRITICAL: ServiceNow AI Platform Pre-Auth RCE (CVE-2026-6875) Under Active Attack

A critical unauthenticated remote code execution flaw in the ServiceNow AI Platform, CVE-2026-6875, is under active attack after threat actors weaponized a sandbox escape against the /assessment_thanks.do endpoint. Scored 9.5 on CVSS 4.0, it lets attackers run code with no credentials. Patches reached hosted instances in April and self hosted customers in June, and every unpatched instance is now a live target.

Read more
critical
CVE AdvisoryVulnerabilityJul 20, 2026

CRITICAL: SonicWall SMA 1000 Zero-Days Chained for Root, Exploited a Month Before Disclosure

A previously unknown threat actor tracked as UTA0533 chained two SonicWall SMA 1000 zero-days, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410, to gain root on internet-facing VPN appliances starting June 22, 2026, weeks before disclosure. Root access let attackers steal credentials, session databases, and MFA seed configurations, then pivot into corporate networks. There are no workarounds. Patch to 12.4.3-03453 or 12.5.0-02835 immediately.

Read more
CVE-2026-58644
critical
CVE AdvisoryVulnerabilityCVE-2026-58644 Jul 17, 2026

CRITICAL: Microsoft SharePoint Server Zero-Day CVE-2026-58644 Under Active Attack, CISA Sets Three-Day Clock

Microsoft confirmed CVE-2026-58644, a critical CVSS 9.8 deserialization flaw in on-premises SharePoint Server, was exploited as a zero-day before patches shipped. CISA added it to the KEV catalog with a July 19, 2026 federal deadline. It affects SharePoint Subscription Edition, 2019, and 2016, and attackers are stealing IIS machine keys for persistence.

Read more
critical
CVE AdvisoryVulnerabilityJul 15, 2026

CRITICAL: SonicWall SMA 1000 Zero-Days Under Active Attack, One Scoring a Perfect 10.0

SonicWall confirmed active exploitation of two SMA 1000 zero-days. CVE-2026-15409 is a maximum severity 10.0 unauthenticated SSRF that chains with CVE-2026-15410, a post-auth code injection, to hand attackers unauthenticated remote command execution as administrator. CISA added both to its KEV catalog with a July 17 federal patch deadline. Patch to 12.4.3-03453 or 12.5.0-02835 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJul 14, 2026

CRITICAL: iCagenda and Balbooa Forms Joomla Zero-Days Exploited for Unauthenticated RCE

Two Joomla extensions, iCagenda and Balbooa Forms, contain maximum severity CVSS 10.0 arbitrary file upload flaws (CVE-2026-48939 and CVE-2026-56291) that allow unauthenticated remote code execution. Both were exploited as zero-days before patches shipped and now sit in CISA's KEV catalog. Update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1 immediately and hunt for planted web shells.

Read more
critical
CVE AdvisoryVulnerabilityJul 13, 2026

CRITICAL: Progress Orders ShareFile Customers to Shut Down Storage Zone Controllers Over Credible Threat

Progress ordered ShareFile customers to shut down the Windows servers running their Storage Zone Controllers on July 10, 2026, over a credible but undisclosed threat. The move follows April's chainable pre-authentication flaws CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1), which allow unauthenticated remote code execution on internet-facing controllers.

Read more
critical
CVE AdvisoryVulnerabilityJul 12, 2026

CRITICAL: Progress Orders ShareFile Customers to Pull Storage Zone Controllers Offline Over Credible Threat

Progress Software has ordered ShareFile customers to manually power down the Windows servers running Storage Zone Controllers over a credible external security threat, with no patch available and no CVE disclosed. The emergency shutdown targets the same internet facing component that had a pre authentication RCE chain, CVE-2026-2699 and CVE-2026-2701, disclosed in April 2026.

Read more
critical
CVE AdvisoryVulnerabilityJul 11, 2026

CRITICAL: Zimbra Classic Web Client Flaw Lets a Single Crafted Email Hijack Your Inbox

Zimbra shipped an emergency fix for a critical stored cross-site scripting flaw in its Classic Web Client that lets a crafted email run malicious code inside a victim's authenticated session the moment they open it. Google's Threat Analysis Group reported it, no CVE is assigned yet, and administrators should upgrade to Collaboration Suite 10.1.19 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJul 9, 2026

CRITICAL: Ubiquiti Ships Emergency UniFi Fixes for CVSS 10.0 Unauthenticated Command Injection

Ubiquiti disclosed 25 vulnerabilities across the UniFi ecosystem on July 8, 2026, including seven critical flaws. The worst, CVE-2026-50746, is a CVSS 10.0 unauthenticated command injection in UniFi Connect that lets any network-adjacent attacker run commands as the host. With roughly 100,000 UniFi OS endpoints exposed to the internet, patching to the fixed releases is urgent.

Read more
CVE-2026-48282
critical
CVE AdvisoryVulnerabilityCVE-2026-48282 Jul 8, 2026

CRITICAL: Adobe ColdFusion Bug (CVE-2026-48282) Weaponized Within Hours as CISA Starts the Patch Clock

Adobe ColdFusion is under active attack through CVE-2026-48282, a CVSS 10.0 path traversal flaw in the Remote Development Services component that hands unauthenticated attackers remote code execution. Exploitation began within about two hours of disclosure, and CISA has added it to its Known Exploited Vulnerabilities catalog with a July 10 federal patch deadline. Patch to ColdFusion 2025 update 10 or 2023 update 21 now.

Read more
critical
CVE AdvisoryVulnerabilityJul 7, 2026

CRITICAL: BeyondTrust Auth Bypass Flaws Hand Attackers the Keys to Remote Support and PRA

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two unauthenticated CVSS 9.2 auth bypass bugs (CVE-2026-40138 and CVE-2026-40139) that let network-positioned attackers reach elevated accounts. All versions at or below 25.3.2 are vulnerable, with fixes in the 25.3.3 line. Cloud customers were patched April 21 2026, so self-hosted admins are the ones who need to move now.

Read more
critical
CVE AdvisoryVulnerabilityJun 19, 2026

CRITICAL: F5 Patches Two NGINX Flaws Handing Unauthenticated RCE to Remote Attackers

F5 disclosed two critical NGINX vulnerabilities on June 17, 2026, both scoring CVSS 4.0 9.2. CVE-2026-42530 is a use-after-free in the HTTP/3 QPACK encoder and CVE-2026-42055 is a heap-based buffer overflow in the HTTP/2 proxy and gRPC modules. Both are remotely exploitable by unauthenticated attackers and affect a huge swath of the NGINX Open Source and NGINX Plus install base.

Read more
critical
CVE AdvisoryVulnerabilityJun 17, 2026

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Attackers Chain Auth Bypass and Command Injection

Three critical FortiSandbox vulnerabilities are under active exploitation, led by CVE-2026-39813, a path traversal flaw in the JRPC API that lets unauthenticated attackers bypass authentication via crafted HTTP requests. Paired with two OS command injection bugs, the chain gives remote code execution on appliances running FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. Upgrade to 5.0.6 or 4.4.9 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJun 16, 2026

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Defenders Race to Patch

Defused Cyber reported active exploitation of three CVSS 9.1 FortiSandbox vulnerabilities inside a 24-hour window. CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 allow unauthenticated remote code execution and authentication bypass on the appliance that other Fortinet products trust to verdict malware. Patches are available, but the 4.2 branch requires migration to a supported release.

Read more
CVE-2026-42271
critical
CVE AdvisoryVulnerabilityCVE-2026-42271 Jun 9, 2026

CRITICAL: LiteLLM RCE Chain Hits CISA KEV as Attackers Hammer Exposed AI Gateways

LiteLLM CVE-2026-42271 chained with Starlette CVE-2026-48710 (BadHost) creates an unauthenticated RCE path scoring CVSS 10.0 against AI gateways. CISA added the flaw to the KEV catalog after confirming active exploitation. Patch LiteLLM 1.83.7 and Starlette 1.0.1 immediately or block the vulnerable MCP test endpoints at your reverse proxy.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 2 of 6Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.