Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated October 3, 2026 — all 220 published advisories are browsable here. The four drawing the most attention right now: a FortiMail email-gateway flaw being exploited before any fix exists (CVE-2026-104286, rated 9 out of 10 for severity) — there is no patch yet, so every affected 8.0, 7.6, 7.4 and 7.2 system is relying on Fortinet’s workaround, starting with switching off the Identity Based Encryption portal if you do not use it; two Citrix NetScaler flaws exploited for weeks before the September 27 fix (CVE-2026-88771 and CVE-2026-88772) — a patched box can still be hosting a webshell (a hidden back door left behind in the software itself), so update to 14.1-73.37 or 13.1-64.23 and then go looking for what was left behind; a Roundcube webmail flaw that lets an attacker tamper with the mail database before anyone logs in (CVE-2026-48842), patched in May 2026 and still being exploited because it ships inside hosting control panels most firms forget they run; and a Microsoft SharePoint Server flaw under active attack that lets an intruder run their own code on the server holding your internal documents (CVE-2026-65660), whose CISA federal patch deadline passed on September 28, so an unpatched server is now overdue rather than pending. Two of the four are email systems, and one has no fix at all, which is why what decides the cost is how fast someone notices. If you are not sure who is reading the alerts at 2 a.m., our 24/7 staffed security operations center handles the detection and the response.

Severity: All Critical High Medium Low
138 articles found
Featured Story
CVE-2026-53921
critical
Jul 29, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: OpenWrt DHCPv6 Flaw CVE-2026-53921 Gives Root Without Auth

OpenWrt disclosed CVE-2026-53921, a pair of stack buffer overflows in the odhcpd DHCPv6 daemon that let an unauthenticated attacker reach code execution as root on affected devices. It scores CVSS 9.8 and is fixed in OpenWrt 24.10.8 and 25.12.5. No exploitation has been reported yet, but public proof of concept code already exists.

By Danny MercerRead Full Article
CVE-2026-16812
critical
CVE AdvisoryVulnerabilityCVE-2026-16812 •Jul 28, 2026

CRITICAL: Arista VeloCloud Orchestrator CVSS 10.0 Flaw Exploited in the Wild

Arista has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator that is already under active exploitation. CISA added it to the Known Exploited Vulnerabilities catalog with a July 30, 2026 federal patching deadline, and compromise of the orchestrator can extend to the VeloCloud Edge devices it manages.

Read more
critical
CVE AdvisoryVulnerability•Jul 25, 2026

CRITICAL: Cl0p Is Ransacking PTC Windchill Through a 9.8 Deserialization Bug

Cl0p affiliates are actively exploiting CVE-2026-12569, a CVSS 9.8 unauthenticated RCE in PTC Windchill PDMLink and FlexPLM, chaining it with a FlexPLM WSDL information disclosure to drop JSP web shells and steal engineering data. Exploited as a zero-day since early June 2026 and on the CISA KEV list since June 25. Patch via PTC CS473270 and hunt for compromise now.

Read more
critical
CVE AdvisoryVulnerability•Jul 21, 2026

CRITICAL: ServiceNow AI Platform Pre-Auth RCE (CVE-2026-6875) Under Active Attack

A critical unauthenticated remote code execution flaw in the ServiceNow AI Platform, CVE-2026-6875, is under active attack after threat actors weaponized a sandbox escape against the /assessment_thanks.do endpoint. Scored 9.5 on CVSS 4.0, it lets attackers run code with no credentials. Patches reached hosted instances in April and self hosted customers in June, and every unpatched instance is now a live target.

Read more
critical
CVE AdvisoryVulnerability•Jul 20, 2026

CRITICAL: SonicWall SMA 1000 Zero-Days Chained for Root, Exploited a Month Before Disclosure

A previously unknown threat actor tracked as UTA0533 chained two SonicWall SMA 1000 zero-days, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410, to gain root on internet-facing VPN appliances starting June 22, 2026, weeks before disclosure. Root access let attackers steal credentials, session databases, and MFA seed configurations, then pivot into corporate networks. There are no workarounds. Patch to 12.4.3-03453 or 12.5.0-02835 immediately.

Read more
CVE-2026-58644
critical
CVE AdvisoryVulnerabilityCVE-2026-58644 •Jul 17, 2026

CRITICAL: Microsoft SharePoint Server Zero-Day CVE-2026-58644 Under Active Attack, CISA Sets Three-Day Clock

Microsoft confirmed CVE-2026-58644, a critical CVSS 9.8 deserialization flaw in on-premises SharePoint Server, was exploited as a zero-day before patches shipped. CISA added it to the KEV catalog with a July 19, 2026 federal deadline. It affects SharePoint Subscription Edition, 2019, and 2016, and attackers are stealing IIS machine keys for persistence.

Read more
critical
CVE AdvisoryVulnerability•Jul 15, 2026

CRITICAL: SonicWall SMA 1000 Zero-Days Under Active Attack, One Scoring a Perfect 10.0

SonicWall confirmed active exploitation of two SMA 1000 zero-days. CVE-2026-15409 is a maximum severity 10.0 unauthenticated SSRF that chains with CVE-2026-15410, a post-auth code injection, to hand attackers unauthenticated remote command execution as administrator. CISA added both to its KEV catalog with a July 17 federal patch deadline. Patch to 12.4.3-03453 or 12.5.0-02835 immediately.

Read more
critical
CVE AdvisoryVulnerability•Jul 14, 2026

CRITICAL: iCagenda and Balbooa Forms Joomla Zero-Days Exploited for Unauthenticated RCE

Two Joomla extensions, iCagenda and Balbooa Forms, contain maximum severity CVSS 10.0 arbitrary file upload flaws (CVE-2026-48939 and CVE-2026-56291) that allow unauthenticated remote code execution. Both were exploited as zero-days before patches shipped and now sit in CISA's KEV catalog. Update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1 immediately and hunt for planted web shells.

Read more
critical
CVE AdvisoryVulnerability•Jul 13, 2026

CRITICAL: Progress Orders ShareFile Customers to Shut Down Storage Zone Controllers Over Credible Threat

Progress ordered ShareFile customers to shut down the Windows servers running their Storage Zone Controllers on July 10, 2026, over a credible but undisclosed threat. The move follows April's chainable pre-authentication flaws CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1), which allow unauthenticated remote code execution on internet-facing controllers.

Read more
critical
CVE AdvisoryVulnerability•Jul 12, 2026

CRITICAL: Progress Orders ShareFile Customers to Pull Storage Zone Controllers Offline Over Credible Threat

Progress Software has ordered ShareFile customers to manually power down the Windows servers running Storage Zone Controllers over a credible external security threat, with no patch available and no CVE disclosed. The emergency shutdown targets the same internet facing component that had a pre authentication RCE chain, CVE-2026-2699 and CVE-2026-2701, disclosed in April 2026.

Read more
critical
CVE AdvisoryVulnerability•Jul 11, 2026

CRITICAL: Zimbra Classic Web Client Flaw Lets a Single Crafted Email Hijack Your Inbox

Zimbra shipped an emergency fix for a critical stored cross-site scripting flaw in its Classic Web Client that lets a crafted email run malicious code inside a victim's authenticated session the moment they open it. Google's Threat Analysis Group reported it, no CVE is assigned yet, and administrators should upgrade to Collaboration Suite 10.1.19 immediately.

Read more
critical
CVE AdvisoryVulnerability•Jul 9, 2026

CRITICAL: Ubiquiti Ships Emergency UniFi Fixes for CVSS 10.0 Unauthenticated Command Injection

Ubiquiti disclosed 25 vulnerabilities across the UniFi ecosystem on July 8, 2026, including seven critical flaws. The worst, CVE-2026-50746, is a CVSS 10.0 unauthenticated command injection in UniFi Connect that lets any network-adjacent attacker run commands as the host. With roughly 100,000 UniFi OS endpoints exposed to the internet, patching to the fixed releases is urgent.

Read more
CVE-2026-48282
critical
CVE AdvisoryVulnerabilityCVE-2026-48282 •Jul 8, 2026

CRITICAL: Adobe ColdFusion Bug (CVE-2026-48282) Weaponized Within Hours as CISA Starts the Patch Clock

Adobe ColdFusion is under active attack through CVE-2026-48282, a CVSS 10.0 path traversal flaw in the Remote Development Services component that hands unauthenticated attackers remote code execution. Exploitation began within about two hours of disclosure, and CISA has added it to its Known Exploited Vulnerabilities catalog with a July 10 federal patch deadline. Patch to ColdFusion 2025 update 10 or 2023 update 21 now.

Read more
critical
CVE AdvisoryVulnerability•Jul 7, 2026

CRITICAL: BeyondTrust Auth Bypass Flaws Hand Attackers the Keys to Remote Support and PRA

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two unauthenticated CVSS 9.2 auth bypass bugs (CVE-2026-40138 and CVE-2026-40139) that let network-positioned attackers reach elevated accounts. All versions at or below 25.3.2 are vulnerable, with fixes in the 25.3.3 line. Cloud customers were patched April 21 2026, so self-hosted admins are the ones who need to move now.

Read more
critical
CVE AdvisoryVulnerability•Jun 19, 2026

CRITICAL: F5 Patches Two NGINX Flaws Handing Unauthenticated RCE to Remote Attackers

F5 disclosed two critical NGINX vulnerabilities on June 17, 2026, both scoring CVSS 4.0 9.2. CVE-2026-42530 is a use-after-free in the HTTP/3 QPACK encoder and CVE-2026-42055 is a heap-based buffer overflow in the HTTP/2 proxy and gRPC modules. Both are remotely exploitable by unauthenticated attackers and affect a huge swath of the NGINX Open Source and NGINX Plus install base.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 3 of 7Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.