Vulnerabilities — Page 31

Vulnerabilities

CISA Flags Magento Cache Extension Bug as Actively Exploited

CVE-2026-45247, an unsafe deserialization flaw in Mirasvit Cache Warmer, lands in KEV after in-the-wild abuse against Magento storefronts.

2 min read
Vulnerabilities

GitHub's Browser VSCode Handed Attackers a Skeleton Key to Your Private Repos

An unscoped OAuth token, a Jupyter notebook, and a skipped publisher trust check. That's all it took.

3 min read
Vulnerabilities

Redis Patches Two-Year-Old Use-After-Free Surfaced by Autonomous AI Bug Hunter

CVE-2026-23479 sat in the blocking-client code from Redis 7.2.0 until the May 5 fixes. An authenticated user could parlay it into arbitrary OS command execution.

2 min read
Vulnerabilities

Privilege Escalation Attacks Hit Kirki and Burst Statistics WordPress Plugins

Threat actors are actively exploiting flaws in two widely-used WordPress plugins to grab admin access and seize site control.

2 min read
Vulnerabilities

HTTP/2 Default Configs Leave Web Servers Open to Compression-Bomb, Slowloris Combo Attack

A chained exploit targeting HTTP/2's default settings can take servers offline in seconds — no patch issued yet for the underlying configuration exposure.

2 min read
Vulnerabilities

Second Windows URI Handler Bug Leaks NTLMv2 Hashes — Still Unpatched

Researchers flag a search: URI handler flaw that mirrors the recently patched ms-screensketch issue. Microsoft hasn't shipped a fix.

2 min read
Vulnerabilities

Microsoft Threatened a Bug Hunter With Legal Action. Now It's Walking That Back.

A researcher dropped unpatched zero-days with working exploits. Microsoft's first response was to reach for the lawyers. That went poorly.

2 min read
Vulnerabilities

HTTP/2 Bomb: Default Configs in NGINX, Apache, IIS, Envoy and Pingora Open Door to Remote DoS

A chained protocol abuse discovered by OpenAI Codex and disclosed by Calif knocks over five of the most widely deployed web servers in their out-of-the-box state.

2 min read
Vulnerabilities

CISA Adds Two-Year-Old Oracle WebLogic Flaw to KEV, Gives Feds Four Days to Patch

CVE-2024-21182 sat quietly at CVSS 7.3 for two years before threat actors noticed the unpatched stragglers. Now federal agencies have until Thursday.

2 min read
Vulnerabilities

Root on Your Conference Phone: HP Poly Flaw Turns VoIP Hardware Into an AI Deepfake Feed

A CVSS 9.2 stack overflow in HP Poly's ICE implementation hands attackers unauthenticated root — and a front-row seat to every executive call.

2 min read
Vulnerabilities

Android June 2026 Bulletin: 124 Fixes, One Framework Bug Already Being Exploited

CVE-2025-48595 is a no-interaction privilege escalation in the Android Framework. Google says it's seen in the wild.

2 min read
Vulnerabilities

CISA Flags Oracle WebLogic Bug CVE-2024-21182 as Actively Exploited

A two-year-old T3/IIOP flaw in WebLogic Server is back in the spotlight after CISA added it to the KEV catalog. Federal agencies have three weeks to patch.

2 min read
Vulnerabilities

A Dev Flag Left Microsoft Account Tokens Exposed Across Billions of Android Installs

A single misconfigured development setting bypassed token-protection controls in Microsoft's Android apps. The blast radius was massive.

2 min read
Vulnerabilities

Miasma Campaign Infects Red Hat npm Packages

Latest supply chain attack reveals persistent threat of credential theft

2 min read
Vulnerabilities

CVE-2026-0257: Palo Alto GlobalProtect Authentication Bypass Hit in the Wild Within Days of Disclosure

A credential-less VPN session forgery flaw in PAN-OS moved from 'medium severity, no known exploitation' to CISA's KEV catalog in sixteen days. Federal agencies had 72 hours to patch.

2 min read
© 2026 Threat Vectr