Vulnerabilities — Page 16

CISA Adds Two-Year-Old Oracle WebLogic Flaw to KEV, Gives Feds Four Days to Patch
CVE-2024-21182 sat quietly at CVSS 7.3 for two years before threat actors noticed the unpatched stragglers. Now federal agencies have until Thursday.

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed
A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root — and a front-row seat to every executive call.

Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited
CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

CISA Flags Oracle WebLogic Bug CVE-2024-21182 as Actively Exploited
A two-year-old T3/IIOP flaw in WebLogic Server is back in the spotlight after CISA added it to the KEV catalog. Federal agencies have three weeks to patch.

A Dev Flag Left Microsoft Account Tokens Exposed Across Billions of Android Installs
A single misconfigured development setting bypassed token-protection controls in Microsoft's Android apps. The blast radius was massive.

Miasma Campaign Infects Red Hat npm Packages
Latest supply chain attack reveals persistent threat of credential theft

CVE-2026-0257: Palo Alto GlobalProtect Authentication Bypass Hit in the Wild Within Days of Disclosure
A credential-less VPN session forgery flaw in PAN-OS moved from 'medium severity, no known exploitation' to CISA's KEV catalog in sixteen days. Federal agencies had 72 hours to patch.

Miasma Attack Targets Red Hat Packages
Supply chain breach deploys credential-stealing worm through compromised npm packages.

Unauthenticated Admin-Account Bug in WP Maps Pro Draws Active Exploitation
CVE-2026-8732 lets attackers create administrator accounts without credentials — and exploitation is already underway against live WordPress installations.

Oracle Launches Monthly Patch Cycle With 35-Flaw Drop, Four CVEs Under Active PoC Threat
A CVSS 10 hole in REST Data Services leads the list. Four older bugs with public exploit code deserve faster attention than their scores suggest.

PoC Drops for 19-Year-Old Linux Kernel Privilege-Escalation Bug in CIFSwitch
A flaw that's been sitting in the kernel since the mid-2000s now has working exploit code. Low-privileged users can reach root.

Attackers Hammer WP Maps Pro Flaw to Mint Admin Accounts on WordPress Sites
A critical bug in the 15,000-install Envato plugin is being weaponized in the wild to seed rogue administrators.

Exploit Code Goes Public for Critical Flowise One-Click RCE Flaw
A published proof-of-concept puts every self-hosted Flowise deployment at risk of full remote code execution — no authentication required from the attacker, just a malicious chatflow import.

CIFSwitch: Linux Kernel Key-Handling Bug Hands Out Root Across Major Distros
A local privilege escalation in the kernel's CIFS authentication path lets an unprivileged user forge key descriptions and walk away with root.

One Bad Character in a Host Header Breaks Auth for Thousands of FastAPI Apps
A parsing gap in Starlette lets unauthenticated requests reach protected routes — and the blast radius runs deep into the AI inference stack.