Vulnerabilities — Page 25

Vulnerabilities

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited

The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

2 min read
Vulnerabilities

No Patch, No CVE: Argo CD Repo-Server Flaw Opens Door to Kubernetes Cluster Takeover

Synacktiv reported the unauthenticated RCE bug to maintainers. There's still no fix.

3 min read
Vulnerabilities

Adobe Ships Emergency Fixes for Seven CVSS 10.0 Bugs in ColdFusion, Campaign Classic

Out-of-band advisories cover arbitrary code execution and privilege escalation paths. Administrators face a short remediation window before public exploit code is likely.

2 min read
Vulnerabilities

Active Exploitation Reported Against Progress Kemp LoadMaster Pre-Auth RCE (CVE-2026-8037)

Threat responders flag in-the-wild attempts against a 9.6-rated OS command injection flaw in the load balancer, days after Progress issued a fixed build.

2 min read
Vulnerabilities

Citrix Patches Six NetScaler Flaws, Including HTTP/2 Bomb DoS and a CitrixBleed Echo

Citrix is pushing customers to patch NetScaler after disclosing six vulnerabilities — among them a denial-of-service vector exploiting HTTP/2 frame handling and a high-severity information disclosure bug drawing uncomfortable comparisons to last year's CitrixBleed.

2 min read
Vulnerabilities

Apple Ships Multi-Component Patch Round Covering iOS, macOS, and Safari

Fixes land for WebKit, the kernel, WebRTC, and Web Extensions — touching every major Apple platform in a single release cycle.

2 min read
Vulnerabilities

Citrix Ships Fixes for Six NetScaler Bugs, Including a File-Read Flaw Scoring 8.8

The patch batch covers NetScaler ADC and Gateway, with input-validation and DoS issues that admins should not sit on.

2 min read
Vulnerabilities

Langflow RCE Is Back on the Menu — This Time for a Monero Miner

Attackers are still pillaging exposed Langflow instances through CVE-2026-33017, turning forgotten AI workflow servers into XMR mining rigs.

3 min read
Vulnerabilities

SimpleHelp OIDC Bypass Gets Weaponized: TaskWeaver and Djinn Stealer Land on Unpatched Servers

An unauthenticated auth bypass scoring a perfect 10.0 is dropping two new malware families on remote-support boxes that nobody remembered were internet-facing.

2 min read
Vulnerabilities

Six Bugs in AirDrop and Quick Share Let Anyone Within Range Knock Out File Sharing

Researchers chained wireless-range flaws to crash receiving devices and bypass Quick Share permission checks — no taps, no pairing, no prompts.

3 min read
Vulnerabilities

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now

CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

3 min read
Vulnerabilities

Apple Ships Three Dozen Fixes, Including WebKit Bugs Surfaced by LLM-Assisted Review

Four of the patched WebKit flaws were found with help from Claude and Codex — a quiet data point on how vendors are folding AI into vulnerability discovery.

2 min read
Vulnerabilities

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit

CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is happening now.

2 min read
Vulnerabilities

CISA Flags Three Daktronics Controller Flaws That Could Let Attackers Hijack Highway Signs

A researcher found the vulnerabilities in controllers widely used to drive digital billboards and roadway message signs. Exploitation could mean someone else controls what drivers read.

2 min read
Vulnerabilities

DirtyClone: New Linux Kernel Flaw Hands Unprivileged Users the Root Keys

A page-cache manipulation bug related to DirtyFrag lets local, unprivileged attackers escalate to root — no credentials required beyond a shell.

2 min read
© 2026 Threat Vectr