Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated October 3, 2026 — all 220 published advisories are browsable here. The four drawing the most attention right now: a FortiMail email-gateway flaw being exploited before any fix exists (CVE-2026-104286, rated 9 out of 10 for severity) — there is no patch yet, so every affected 8.0, 7.6, 7.4 and 7.2 system is relying on Fortinet’s workaround, starting with switching off the Identity Based Encryption portal if you do not use it; two Citrix NetScaler flaws exploited for weeks before the September 27 fix (CVE-2026-88771 and CVE-2026-88772) — a patched box can still be hosting a webshell (a hidden back door left behind in the software itself), so update to 14.1-73.37 or 13.1-64.23 and then go looking for what was left behind; a Roundcube webmail flaw that lets an attacker tamper with the mail database before anyone logs in (CVE-2026-48842), patched in May 2026 and still being exploited because it ships inside hosting control panels most firms forget they run; and a Microsoft SharePoint Server flaw under active attack that lets an intruder run their own code on the server holding your internal documents (CVE-2026-65660), whose CISA federal patch deadline passed on September 28, so an unpatched server is now overdue rather than pending. Two of the four are email systems, and one has no fix at all, which is why what decides the cost is how fast someone notices. If you are not sure who is reading the alerts at 2 a.m., our 24/7 staffed security operations center handles the detection and the response.

Severity: All Critical High Medium Low
138 articles found
Featured Story
critical
Sep 3, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: JFrog Artifactory CVE-2026-82329 Exploited to Mint Admin Tokens

JFrog Artifactory instances running default configurations hand unauthenticated attackers a path to full administrator access through what researchers call a phantom join key. CISA added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog after watchTowr observed attackers minting admin tokens in the wild, four days after the patch shipped.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerability•Sep 1, 2026

CRITICAL: Ruby on Rails CVE-2026-66066 Exploited in the Wild

Attackers are actively exploiting CVE-2026-66066, the CVSS 9.5 Active Storage flaw in Ruby on Rails nicknamed KindaRails2Shell, with VulnCheck detections jumping from 50 to 360 in under two days. A crafted image upload gives an unauthenticated attacker arbitrary file read and a path to remote code execution. Patched in Active Storage 7.2.3.2, 8.0.5.1, and 8.1.3.1, and the fix also requires libvips 8.13 or newer.

Read more
critical
CVE AdvisoryVulnerability•Aug 19, 2026

CRITICAL: Windows IKE Flaw CVE-2026-33824 Under Active Exploitation

CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on August 18 after Unit 42 observed hands on keyboard attacks against Windows IKE VPN endpoints. The CVSS 9.8 double free in the Windows IKE Service Extensions gives unauthenticated attackers SYSTEM level code execution over UDP 500 and 4500. Microsoft patched it in April 2026 and federal agencies must remediate by August 21.

Read more
critical
CVE AdvisoryVulnerability•Aug 18, 2026

CRITICAL: Ray CVE-2025-62593 Added to CISA KEV After Active Exploitation

CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026, giving federal civilian agencies until August 20 to remediate. The critical 9.4 flaw in the Ray distributed AI framework lets a malicious web page reach an otherwise unexposed Ray dashboard through DNS rebinding and execute arbitrary code. The RondoDox botnet weaponized it two days before public disclosure, and every version before Ray 2.52.0 is affected.

Read more
critical
CVE AdvisoryVulnerability•Aug 14, 2026

CRITICAL: SharePoint CVE-2026-55040 Exploited After Public PoC Release

Microsoft patched CVE-2026-55040 in July 2026, a CVSS 9.1 authentication bypass in on-premises SharePoint Server that chains four JWT validation failures to let an unauthenticated attacker forge tokens and impersonate any user, including administrators. Rapid7 published a working proof of concept on August 11 and honeypots recorded exploitation attempts roughly one day later. SharePoint Server 2016, 2019, and Subscription Edition are all affected.

Read more
critical
CVE AdvisoryVulnerability•Aug 11, 2026

CRITICAL: Gunra Ransomware Exploits Fortinet FortiOS Auth Bypass Flaws

CISA, the FBI, and South Korea's National Police Agency issued joint advisory AA26-222A on the Gunra ransomware group, which is breaching networks through the Fortinet FortiOS and FortiProxy authentication bypass flaws CVE-2024-55591 and CVE-2025-24472. Gunra has claimed fifty-one victims across healthcare, finance, government, and manufacturing, and tampers with VDI authentication files to create a persistent MFA bypass before destroying backups and encrypting with ChaCha20.

Read more
critical
CVE AdvisoryVulnerability•Aug 7, 2026

CRITICAL: Cisco Patches Three CVSS 9.9 Catalyst SD-WAN Flaws and Seven IOS XE Bugs

Cisco shipped security hardening releases for Catalyst SD-WAN and IOS XE on August 5, 2026, fixing 12 flaws including three rated CVSS 9.9 and a 9.8 command injection. There are no workarounds and no configuration mitigations, only fixed images, and the low privileges required rating means any authenticated account on SD-WAN Manager is now a critical severity foothold.

Read more
critical
CVE AdvisoryVulnerability•Aug 6, 2026

CRITICAL: Veeam Service Provider Console CVE-2026-58073 Allows Unauthenticated Credential Theft

Veeam patched four flaws in Service Provider Console, the multi-tenant console that MSPs and hosting providers use to manage customer backups. The most severe, CVE-2026-58073 at CVSS 9.5, lets an unauthenticated attacker impersonate a managed agent and steal that agent's credentials. Every version 9 build through 9.2.1.33875 is affected, and build 9.3.0.35057 is the fix.

Read more
critical
CVE AdvisoryVulnerability•Aug 5, 2026

CRITICAL: Langflow CVE-2026-9198 Hits CISA KEV as Exploit Code Spreads

IBM Langflow carries a CVSS 9.8 unauthenticated remote code execution flaw, CVE-2026-9198, that chains a token minting auto-login endpoint with a code validation endpoint running exec(). CISA added it to the Known Exploited Vulnerabilities catalog with an August 7 federal deadline, public exploit code is circulating, and roughly 7,000 instances are reachable online. Upgrade to 1.10.1 or later and rotate every secret the instance could read.

Read more
critical
CVE AdvisoryVulnerability•Aug 2, 2026

CRITICAL: Coldcard Seed Flaw Linked to $70 Million Bitcoin Theft

A firmware integration error shipped in March 2021 routed Coldcard seed generation to a deterministic software PRNG instead of the STM32 hardware RNG, cutting effective entropy to as low as 40 bits. An attacker drained 1,196 Bitcoin addresses of 1,082.65 BTC worth roughly $70.2 million in 41 minutes on July 30, 2026, without ever touching a device. Coinkite shipped emergency firmware on July 31, but updating does not repair a seed that was already generated.

Read more
critical
CVE AdvisoryVulnerability•Jul 31, 2026

CRITICAL: Azure Cosmos DB CVE-2026-66803 Exposed a Platform-Wide Master Key

Microsoft has disclosed CVE-2026-66803, a CVSS 10.0 improper access control flaw in Azure Cosmos DB that let researchers escape the Gremlin query sandbox and reach a platform wide signing key capable of retrieving the primary key for any Cosmos DB account on the service. Microsoft says no customer data was accessed and no customer action is required, but the finding is a hard lesson in cloud key hygiene and blast radius.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 2 of 7Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.