Vulnerabilities — Page 16

Vulnerabilities

CISA Adds Two-Year-Old Oracle WebLogic Flaw to KEV, Gives Feds Four Days to Patch

CVE-2024-21182 sat quietly at CVSS 7.3 for two years before threat actors noticed the unpatched stragglers. Now federal agencies have until Thursday.

2 min read
Vulnerabilities

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed

A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root — and a front-row seat to every executive call.

2 min read
Vulnerabilities

Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited

CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

2 min read
Vulnerabilities

CISA Flags Oracle WebLogic Bug CVE-2024-21182 as Actively Exploited

A two-year-old T3/IIOP flaw in WebLogic Server is back in the spotlight after CISA added it to the KEV catalog. Federal agencies have three weeks to patch.

2 min read
Vulnerabilities

A Dev Flag Left Microsoft Account Tokens Exposed Across Billions of Android Installs

A single misconfigured development setting bypassed token-protection controls in Microsoft's Android apps. The blast radius was massive.

2 min read
Vulnerabilities

Miasma Campaign Infects Red Hat npm Packages

Latest supply chain attack reveals persistent threat of credential theft

2 min read
Vulnerabilities

CVE-2026-0257: Palo Alto GlobalProtect Authentication Bypass Hit in the Wild Within Days of Disclosure

A credential-less VPN session forgery flaw in PAN-OS moved from 'medium severity, no known exploitation' to CISA's KEV catalog in sixteen days. Federal agencies had 72 hours to patch.

2 min read
Vulnerabilities

Miasma Attack Targets Red Hat Packages

Supply chain breach deploys credential-stealing worm through compromised npm packages.

2 min read
Vulnerabilities

Unauthenticated Admin-Account Bug in WP Maps Pro Draws Active Exploitation

CVE-2026-8732 lets attackers create administrator accounts without credentials — and exploitation is already underway against live WordPress installations.

2 min read
Vulnerabilities

Oracle Launches Monthly Patch Cycle With 35-Flaw Drop, Four CVEs Under Active PoC Threat

A CVSS 10 hole in REST Data Services leads the list. Four older bugs with public exploit code deserve faster attention than their scores suggest.

2 min read
Vulnerabilities

PoC Drops for 19-Year-Old Linux Kernel Privilege-Escalation Bug in CIFSwitch

A flaw that's been sitting in the kernel since the mid-2000s now has working exploit code. Low-privileged users can reach root.

2 min read
Vulnerabilities

Attackers Hammer WP Maps Pro Flaw to Mint Admin Accounts on WordPress Sites

A critical bug in the 15,000-install Envato plugin is being weaponized in the wild to seed rogue administrators.

3 min read
Vulnerabilities

Exploit Code Goes Public for Critical Flowise One-Click RCE Flaw

A published proof-of-concept puts every self-hosted Flowise deployment at risk of full remote code execution — no authentication required from the attacker, just a malicious chatflow import.

2 min read
Vulnerabilities

CIFSwitch: Linux Kernel Key-Handling Bug Hands Out Root Across Major Distros

A local privilege escalation in the kernel's CIFS authentication path lets an unprivileged user forge key descriptions and walk away with root.

3 min read
Vulnerabilities

One Bad Character in a Host Header Breaks Auth for Thousands of FastAPI Apps

A parsing gap in Starlette lets unauthenticated requests reach protected routes — and the blast radius runs deep into the AI inference stack.

3 min read
© 2026 Threat Vectr