Vulnerabilities — Page 29

Vulnerabilities

GreatXML Bypasses BitLocker Through a Trusted Recovery Path

A researcher's four-hour weekend project shows how Windows' own offline scan plumbing can sidestep full-disk encryption.

3 min read
Vulnerabilities

ServiceNow's Unauthenticated API Endpoint Left Tenant Data Exposed for Months

An API resource shipped with authentication disabled by default. Now enterprises are asking whether the 'security researcher' explanation fully covers what got accessed.

2 min read
Vulnerabilities

Oracle Patches PeopleSoft Flaw Tied to ShinyHunters Activity, Stays Quiet on Zero-Day Status

CVE-2026-35273 has a fix. Whether attackers got there first is a question Oracle isn't answering.

2 min read
Vulnerabilities

npm 12 Pulls the Plug on Install Scripts by Default

GitHub is finally turning off the lifecycle hook that's been quietly powering half a decade of supply chain attacks.

3 min read
Vulnerabilities

Ivanti Sentry Carries Two Critical Bugs — One a Perfect 10 — Enabling Full Appliance Takeover

A pair of unauthenticated flaws in the mobile gateway give attackers a clear path to root. Exploit code is already public.

2 min read
Vulnerabilities

Langflow Path Traversal Under Active Exploitation, No Patch Available

CVE-2026-5027 lets unauthenticated attackers write arbitrary files on Langflow servers. In-the-wild exploitation is being tracked now.

2 min read
Vulnerabilities

Patch Tuesday-Adjacent: FortiSandbox, Ivanti, and SAP Ship Fixes for Critical Bugs

A 9.1-rated command injection in FortiSandbox headlines a busy week of vendor advisories. Most of these land squarely on platform teams.

2 min read
Vulnerabilities

210 CVEs, Three Zero-Days, and a Microsoft Warning That This Is Just the Beginning

June Patch Tuesday sets a volume record. Microsoft says AI-assisted discovery is why, and that you should get used to it.

3 min read
Vulnerabilities

RoguePlanet Zero-Day Drops as Nightmare Eclipse–Microsoft Feud Reaches New Low

A race-condition bug in Microsoft Defender can yield a SYSTEM shell on fully patched Windows 11 and 10. No patch exists. The researcher dropped it the day after June Patch Tuesday.

3 min read
Vulnerabilities

Microsoft's October Dump: 206 CVEs, Three Already Public

A record Patch Tuesday hauls in 39 Critical bugs and a trio of zero-days that were knocking around before the fix shipped.

2 min read
Vulnerabilities

ServiceNow Patches Auth Bug After Attackers Pivot Deeper Into Hosted Instances

An unauthenticated flaw let intruders escalate access inside customer tenants before ServiceNow shipped a hosted-side fix.

2 min read
Vulnerabilities

RoguePlanet PoC Drops: Another Defender Race Condition, Another Path to SYSTEM

An anonymous researcher publishing as Chaotic Eclipse dropped a proof-of-concept against Microsoft Defender that wins SYSTEM on fully patched Windows — when the race goes their way.

3 min read
Vulnerabilities

protobuf.js Ships Six Bugs That Turn Schemas Into RCE Triggers

A single malicious descriptor is enough. Node.js services parsing untrusted Protobuf are the obvious blast radius.

2 min read
Vulnerabilities

Microsoft Ships Record 200-Bug Patch Tuesday as 'Nightmare Eclipse' Drops Windows Zero-Days

AI-assisted bug hunting, a confrontational researcher, and a Shai-Hulud worm variant inside Microsoft's own repos shape an outsized June rollup.

3 min read
Vulnerabilities

Microsoft Ships KB5094127 ESU as Secure Boot Cert Rollover Looms

The June 2026 extended security update for Windows 10 patches Patch Tuesday bugs and adds telemetry to track the Secure Boot certificate transition.

2 min read
© 2026 Threat Vectr