Vulnerabilities — Page 18

Vulnerabilities

Unpatched Flaws Now Outpace Stolen Credentials as the Leading Breach Entry Point

Verizon's 2025 DBIR puts vulnerability exploitation at 31% of breach root causes. Median patch time has climbed to 43 days, and only 26% of CISA KEVs were fully remediated — a gap attackers are sprinting through.

4 min read
Vulnerabilities

Two Defender flaws under active exploitation, Microsoft confirms

A SYSTEM-level link-following bug and a denial-of-service issue in Microsoft Defender are both being abused in the wild.

2 min read
Vulnerabilities

Cisco's Secure Workload Earns a Perfect 10, in the Wrong Sense

An unauthenticated REST API flaw rated CVSS 10.0 lets remote attackers help themselves to sensitive data. Cisco has issued fixes.

2 min read
Vulnerabilities

CISA's KEV List Just Picked Up Langflow and Apex One — Both Already Being Hit

Two flaws, one AI workflow tool and one veteran endpoint suite, now carry a federal patch deadline because attackers got there first.

2 min read
Vulnerabilities

When the Hardware Isn't There: Coaxing Vulnerable Drivers Into Range

BYOVD research keeps colliding with a stubborn problem — many kernel drivers refuse to talk unless their device is plugged in. New work shows how to make them talk anyway.

2 min read
Vulnerabilities

CISA Flags Exploited Drupal SQL Injection Flaw. Drupal Won't Say Who Got Hit.

CVE-2026-9082 is in the Known Exploited Vulnerabilities catalog. The advisory mentions active exploitation. It does not mention victims, telemetry, or how anyone found out.

2 min read
Vulnerabilities

LiteSpeed cPanel Plugin Flaw Hands Root to Any Logged-In User, and the Vendor Won't Say How Many Hosts Are Hit

CVE-2026-48172 carries a CVSS of 10.0, is already being exploited, and LiteSpeed has not answered three questions about exploitation telemetry.

2 min read
Vulnerabilities

Hard-coded ASP.NET machine keys in KnowledgeDeliver LMS abused to drop Godzilla, then Cobalt Strike

CVE-2026-5426 let attackers forge ViewState payloads against a Japanese LMS used across universities and corporate training portals. The bug was a zero-day before Digital Knowledge shipped a fix.

2 min read
Vulnerabilities

April Patch Tuesday Lands With 167 Microsoft Fixes, SharePoint Zero-Day Under Attack

BlueHammer Defender bug goes public, Adobe Reader flaw exploited since November, and Chrome ships its fourth zero-day of the year.

2 min read
Vulnerabilities

Microsoft Skips a Zero-Day for the First Time in Two Years. Nobody Wants to Talk About Why.

118 fixes shipped, none under active exploit, and a quiet Anthropic project keeps surfacing in vendor briefings. Microsoft, Apple and Oracle declined to discuss it on the record.

3 min read
Vulnerabilities

A SQL Bug in a Blogging Tool Just Became a ClickFix Delivery Truck

Attackers turned 700+ Ghost CMS sites into watering holes by exploiting CVE-2026-26980, smuggling fake CAPTCHA prompts that trick visitors into running malware on themselves.

2 min read
© 2026 Threat Vectr