Vulnerabilities — Page 15

Vulnerabilities

Cisco SD-WAN Manager Bug Under Active Exploit, No Fix Yet

CVE-2026-20245 affects on-prem and FedRAMP deployments. Cisco confirms exploitation in the wild while customers wait on a patch.

2 min read
Vulnerabilities

RubyGems Adds Installation Cooldown to Bundler as Supply Chain Defense

A configurable delay before newly published gems install gives the community time to spot malicious code before it reaches developer machines.

2 min read
Vulnerabilities

OWASP's CVE Lite CLI Puts Dependency Scanning in the Terminal

A new OWASP Incubator project lets developers scan project dependencies for known vulnerabilities from the command line — no dashboard, no subscription, no delay.

2 min read
Vulnerabilities

Fuel, Chemicals, Food: CISA Warns ATG Attacks Can Drain Tanks Silently

Hardcoded credentials and unauthenticated command execution leave automated tank gauges wide open. The fix list is embarrassingly short.

2 min read
Vulnerabilities

900+ Fuel Tank Gauges Still Hanging Off the Public Internet

ATG systems in gas stations, hospitals, and military sites are exposed to known CVEs — and nobody owns the patch cycle.

2 min read
Vulnerabilities

Everest Forms Pro RCE Under Active Exploitation on WordPress Sites

CVE-2026-3300 carries a 9.8 CVSS. Attackers are using it to take over sites running unpatched versions of the premium form-builder plugin.

3 min read
Vulnerabilities

Public PoC Lands for Cisco Unified CM Root-Write Bug CVE-2026-20230

An unauthenticated SSRF in Cisco Unified Communications Manager opens a path to root. Cisco's PSIRT hasn't observed in-the-wild use — yet.

2 min read
Vulnerabilities

HTTP/2 Bomb: A Decade-Old Compression Trick Finally Gets a CVE

A chained HPACK attack lets small packets force runaway memory allocation on nginx, Apache, IIS, Envoy, and Cloudflare's Pingora. Patches are partial. Exposure is wide.

2 min read
Vulnerabilities

CISA Flags Magento Cache Extension Bug as Actively Exploited

CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

2 min read
Vulnerabilities

GitHub's Browser VSCode Handed Attackers a Skeleton Key to Your Private Repos

An unscoped OAuth token, a Jupyter notebook, and a skipped publisher trust check. That's all it took.

3 min read
Vulnerabilities

Redis Patches Two-Year-Old Use-After-Free Surfaced by Autonomous AI Bug Hunter

CVE-2026-23479 sat in the blocking-client code from Redis 7.2.0 until the May 5 fixes. An authenticated user could parlay it into arbitrary OS command execution.

2 min read
Vulnerabilities

Privilege Escalation Attacks Hit Kirki and Burst Statistics WordPress Plugins

Threat actors are actively exploiting flaws in two widely-used WordPress plugins to grab admin access and seize site control.

2 min read
Vulnerabilities

HTTP/2 Default Configs Leave Web Servers Open to Compression-Bomb, Slowloris Combo Attack

A chained exploit targeting HTTP/2's default settings can take servers offline in seconds — no patch issued yet for the underlying configuration exposure.

2 min read
Vulnerabilities

Second Windows URI Handler Bug Leaks NTLMv2 Hashes — Still Unpatched

Researchers flag a search: URI handler flaw that mirrors the recently patched ms-screensketch issue. Microsoft hasn't shipped a fix.

2 min read
Vulnerabilities

Microsoft Threatened a Bug Hunter With Legal Action. Now It's Walking That Back.

A researcher dropped unpatched zero-days with working exploits. Microsoft's first response was to reach for the lawyers. That went poorly.

2 min read
© 2026 Threat Vectr