Vulnerabilities — Page 31

CISA Flags Magento Cache Extension Bug as Actively Exploited
CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

GitHub's Browser VSCode Handed Attackers a Skeleton Key to Your Private Repos
An unscoped OAuth token, a Jupyter notebook, and a skipped publisher trust check. That's all it took.

Redis Patches Two-Year-Old Use-After-Free Surfaced by Autonomous AI Bug Hunter
CVE-2026-23479 sat in the blocking-client code from Redis 7.2.0 until the May 5 fixes. An authenticated user could parlay it into arbitrary OS command execution.

Privilege Escalation Attacks Hit Kirki and Burst Statistics WordPress Plugins
Threat actors are actively exploiting flaws in two widely-used WordPress plugins to grab admin access and seize site control.

HTTP/2 Default Configs Leave Web Servers Open to Compression-Bomb, Slowloris Combo Attack
A chained exploit targeting HTTP/2's default settings can take servers offline in seconds — no patch issued yet for the underlying configuration exposure.

Second Windows URI Handler Bug Leaks NTLMv2 Hashes — Still Unpatched
Researchers flag a search: URI handler flaw that mirrors the recently patched ms-screensketch issue. Microsoft hasn't shipped a fix.

Microsoft Threatened a Bug Hunter With Legal Action. Now It's Walking That Back.
A researcher dropped unpatched zero-days with working exploits. Microsoft's first response was to reach for the lawyers. That went poorly.

HTTP/2 Bomb: Default Configs in NGINX, Apache, IIS, Envoy and Pingora Open Door to Remote DoS
A chained protocol abuse discovered by OpenAI Codex and disclosed by Calif knocks over five of the most widely deployed web servers in their out-of-the-box state.

CISA Adds Two-Year-Old Oracle WebLogic Flaw to KEV, Gives Feds Four Days to Patch
CVE-2024-21182 sat quietly at CVSS 7.3 for two years before threat actors noticed the unpatched stragglers. Now federal agencies have until Thursday.

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed
A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root — and a front-row seat to every executive call.

Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited
CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

CISA Flags Oracle WebLogic Bug CVE-2024-21182 as Actively Exploited
A two-year-old T3/IIOP flaw in WebLogic Server is back in the spotlight after CISA added it to the KEV catalog. Federal agencies have three weeks to patch.

A Dev Flag Left Microsoft Account Tokens Exposed Across Billions of Android Installs
A single misconfigured development setting bypassed token-protection controls in Microsoft's Android apps. The blast radius was massive.

Miasma Campaign Infects Red Hat npm Packages
Latest supply chain attack reveals persistent threat of credential theft

CVE-2026-0257: Palo Alto GlobalProtect Authentication Bypass Hit in the Wild Within Days of Disclosure
A credential-less VPN session forgery flaw in PAN-OS moved from 'medium severity, no known exploitation' to CISA's KEV catalog in sixteen days. Federal agencies had 72 hours to patch.