Tag

#active exploitation

18 stories taggedactive exploitation.

Full-frame edge-to-edge photoreal shot of a dimly lit enterprise server rack with a single network orchestrator appliance glowing amber, blurred fiber patch cab
Vulnerabilities

Arista Says a VeloCloud Orchestrator Bug Is Already Being Exploited

A remote attacker with no login can reach privileged functions on the server that runs an entire SD-WAN network. On-prem customers using certificate authentication need to act now.

3 min read
An email security appliance device with its status lights glowing, a terminal window open in front showing command execution with root permissions, and network
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in Cisco's Email Security Appliance

A zero-day vulnerability in Cisco Secure Email Gateway lets an unauthenticated attacker run any command they like as the most powerful user on the system. No login required.

3 min read
A WSO2 API Manager interface on multiple monitors with authentication token generation systems highlighted, digital signatures being forged and administrator ac
Vulnerabilities

Hackers Are Forging Admin Tokens to Take Over WSO2 API Manager

A critical signature-verification bug tracked as CVE-2026-5430 lets attackers forge login tokens and seize administrator accounts. Exploitation is already under way.

4 min read
A telecommunications server room with blinking indicator lights and cables, a computer screen in the foreground showing active system access logs and unauthoriz
Vulnerabilities

Hackers Are Actively Exploiting a Critical Issabel Flaw That Hands Over Full Server Control

CVE-2026-89026 lets unauthenticated attackers run any command they want on vulnerable phone-system servers. Attacks are already happening.

4 min read
A corporate server room with Oracle WebLogic servers and associated hardware, with critical alert notifications flashing on monitoring dashboards, showing activ
Vulnerabilities

CISA Flags Critical Oracle WebLogic Flaw as Attackers Hit Unpatched Servers

The bug, rated a perfect 10 on the severity scale, lets attackers reach sensitive data without needing a password.

3 min read
A computer screen displaying a login authentication dialog with error messages and warning alerts cascading across the interface, while in the background a netw
Vulnerabilities

Check Point Rushes Fix for SmartConsole Flaw Already Being Exploited

A critical authentication bypass in Check Point's management console let attackers walk past the login screen. The vendor confirms real-world attacks are already happening.

3 min read
Photoreal editorial shot of a dimly lit corporate server room, rows of rack-mounted servers glowing with amber and blue status lights, one rack door slightly aj
Vulnerabilities

Third SharePoint Flaw From July Patch Batch Is Now Being Attacked

CVE-2026-50522 lets unauthenticated attackers run code on SharePoint servers. A public proof-of-concept dropped, and the exploitation followed.

4 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, one server bay glowing with a warning-red status LED while others sh
Vulnerabilities

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns

A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

3 min read
Photoreal editorial image, full frame 16:9, of a modern office desk IP phone glowing softly in a dim server-room setting, with faint blue network cable light tr
Vulnerabilities

Cisco admits hackers are breaking into its phone system software — here's what that means

A flaw in Cisco Unified Communications Manager, the software that runs office phone systems, is now being actively abused after a patch and public exploit code lit the fuse.

4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately

A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

3 min read
Vulnerabilities

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit

CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is confirmed now.

3 min read
Vulnerabilities

CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation

A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

2 min read
Vulnerabilities

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop

A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

3 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

3 min read
Vulnerabilities

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse

CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

3 min read
© 2026 Threat Vectr