Vulnerabilities — Page 30

Vulnerabilities

Chrome Ships Emergency V8 Fix for CVE-2026-11645 Already Under Attack

An out-of-bounds read/write in V8 is being exploited in the wild. Google's update covers 74 issues. Patch, then verify your browser fleet actually restarted.

2 min read
Vulnerabilities

Check Point Issues Emergency Patches After IKEv1 Auth Bypass Draws Qilin Affiliate

Two certificate-validation flaws in Check Point's VPN stack — one already exploited, one caught during the ensuing review — have prompted hotfixes across nine Quantum software versions.

2 min read
Vulnerabilities

Cisco SD-WAN Manager Has an Unpatched Privilege-Escalation Flaw Under Active Exploitation

A command-injection bug in Catalyst SD-WAN Manager is already being used in the wild. No patch exists yet — and a known espionage group may be involved.

2 min read
Vulnerabilities

Public Exploit Drops for nf_tables UAF: CVE-2026-23111 Gives Local Root, Container Escape

Exodus Intelligence published a full walkthrough four months after the upstream patch. The kernel bug is a one-liner. The exploit is not.

2 min read
Vulnerabilities

Six Flaws in protobuf.js Turn Serialized Schemas Into Execution Vectors

The JavaScript Protocol Buffers library — pulled 50 million times a week — ships patches for a cluster of CVEs that let attackers use schema metadata to run arbitrary code inside Node.js processes.

2 min read
Vulnerabilities

Check Point Confirms Active Exploitation of IKEv1 Cert-Bypass Flaw in Remote Access VPN

CVE-2026-50751 lets unauthenticated attackers slip past authentication on gateways still running the deprecated IKEv1 key exchange. Patch is out. Exploitation is not theoretical.

3 min read
Vulnerabilities

Schema as Weapon: Six Flaws in protobuf.js Open a Path to Remote Code Execution

Cyera researchers found that protobuf.js — pulled into apps 50 million times a week — will, under exploitable conditions, turn schema metadata into running code.

2 min read
Vulnerabilities

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft

A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

3 min read
Vulnerabilities

CISA Flags SolarWinds Serv-U DoS Bug as Actively Exploited

CVE-2026-28318 crashes the file transfer service. Federal agencies get the usual three-week patch window.

2 min read
Vulnerabilities

FFmpeg Gets 21 New Bugs from an AI Fuzzer; Chrome 149 Ships a Record 429 Fixes

An autonomous agent dug up zero-days in the codec library that ships in everything. Google's browser shipped its largest single security release on record. Same week.

2 min read
Vulnerabilities

Cisco SD-WAN Manager Bug Under Active Exploit, No Fix Yet

CVE-2026-20245 affects on-prem and FedRAMP deployments. Cisco confirms exploitation in the wild while customers wait on a patch.

2 min read
Vulnerabilities

RubyGems Adds Installation Cooldown to Bundler as Supply Chain Defense

A configurable delay before newly published gems install gives the community time to spot malicious code before it reaches developer machines.

2 min read
Vulnerabilities

OWASP's CVE Lite CLI Puts Dependency Scanning in the Terminal

A new OWASP Incubator project lets developers scan project dependencies for known vulnerabilities from the command line — no dashboard, no subscription, no delay.

2 min read
Vulnerabilities

Fuel, Chemicals, Food: CISA Warns ATG Attacks Can Drain Tanks Silently

Hardcoded credentials and unauthenticated command execution leave automated tank gauges wide open. The fix list is embarrassingly short.

2 min read
Vulnerabilities

900+ Fuel Tank Gauges Still Hanging Off the Public Internet

ATG systems in gas stations, hospitals, and military sites are exposed to known CVEs — and nobody owns the patch cycle.

2 min read
© 2026 Threat Vectr