Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated July 26, 2026 — 168 published advisories, with new analysis most weekdays. Recent coverage includes the PTC Windchill FlexPLM remote code execution flaw under Clop exploitation, a Zimbra webmail cross-site scripting campaign stealing two-factor codes, Check Point SmartConsole CVE-2026-16232, the SharePoint machine-key remote code execution chain (CVE-2026-50522), and a ServiceNow AI Platform remote code execution bug. If one of these touches a system you run and you are not sure what to do next, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
128 articles found
Featured Story
critical
Jul 28, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Arista VeloCloud Orchestrator CVSS 10.0 Flaw Exploited in the Wild

Arista has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator that is already under active exploitation. CISA added it to the Known Exploited Vulnerabilities catalog with a July 30, 2026 federal patching deadline, and compromise of the orchestrator can extend to the VeloCloud Edge devices it manages.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityJul 26, 2026

CRITICAL: Fastjson 1.x CVE-2026-16723 Exploited in the Wild With No Patch

Alibaba disclosed a critical remote code execution flaw in Fastjson 1.2.68 through 1.2.83 that works against the library's default configuration, and attackers began exploiting it within a day. CVE-2026-16723 carries a CVSS score of 9.0 and affects Spring Boot applications deployed as executable fat JARs. No patched 1.x release exists, so SafeMode or migration to Fastjson2 is the only real remediation.

Read more
critical
CVE AdvisoryVulnerabilityJul 25, 2026

CRITICAL: Cl0p Is Ransacking PTC Windchill Through a 9.8 Deserialization Bug

Cl0p affiliates are actively exploiting CVE-2026-12569, a CVSS 9.8 unauthenticated RCE in PTC Windchill PDMLink and FlexPLM, chaining it with a FlexPLM WSDL information disclosure to drop JSP web shells and steal engineering data. Exploited as a zero-day since early June 2026 and on the CISA KEV list since June 25. Patch via PTC CS473270 and hunt for compromise now.

Read more
high
CVE AdvisoryVulnerabilityJul 24, 2026

HIGH: Russian Spies Turned a Medium-Severity Zimbra Bug Into a 2FA Heist

Russian state-supported actor LAUNDRY BEAR (Void Blizzard) exploited a zero-click Zimbra Collaboration XSS flaw, CVE-2025-66376, as a zero-day for months, stealing 90 days of email, Global Address Lists, saved passwords, and 2FA recovery codes from NATO and Ukrainian targets before minting rogue application passwords for persistent MFA-bypassing access. Patched in November 2025 and now on the CISA KEV list.

Read more
critical
CVE AdvisoryVulnerabilityJul 21, 2026

CRITICAL: ServiceNow AI Platform Pre-Auth RCE (CVE-2026-6875) Under Active Attack

A critical unauthenticated remote code execution flaw in the ServiceNow AI Platform, CVE-2026-6875, is under active attack after threat actors weaponized a sandbox escape against the /assessment_thanks.do endpoint. Scored 9.5 on CVSS 4.0, it lets attackers run code with no credentials. Patches reached hosted instances in April and self hosted customers in June, and every unpatched instance is now a live target.

Read more
critical
CVE AdvisoryVulnerabilityJul 20, 2026

CRITICAL: SonicWall SMA 1000 Zero-Days Chained for Root, Exploited a Month Before Disclosure

A previously unknown threat actor tracked as UTA0533 chained two SonicWall SMA 1000 zero-days, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410, to gain root on internet-facing VPN appliances starting June 22, 2026, weeks before disclosure. Root access let attackers steal credentials, session databases, and MFA seed configurations, then pivot into corporate networks. There are no workarounds. Patch to 12.4.3-03453 or 12.5.0-02835 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJul 17, 2026

CRITICAL: Microsoft SharePoint Server Zero-Day CVE-2026-58644 Under Active Attack, CISA Sets Three-Day Clock

Microsoft confirmed CVE-2026-58644, a critical CVSS 9.8 deserialization flaw in on-premises SharePoint Server, was exploited as a zero-day before patches shipped. CISA added it to the KEV catalog with a July 19, 2026 federal deadline. It affects SharePoint Subscription Edition, 2019, and 2016, and attackers are stealing IIS machine keys for persistence.

Read more
critical
CVE AdvisoryVulnerabilityJul 15, 2026

CRITICAL: SonicWall SMA 1000 Zero-Days Under Active Attack, One Scoring a Perfect 10.0

SonicWall confirmed active exploitation of two SMA 1000 zero-days. CVE-2026-15409 is a maximum severity 10.0 unauthenticated SSRF that chains with CVE-2026-15410, a post-auth code injection, to hand attackers unauthenticated remote command execution as administrator. CISA added both to its KEV catalog with a July 17 federal patch deadline. Patch to 12.4.3-03453 or 12.5.0-02835 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJul 14, 2026

CRITICAL: iCagenda and Balbooa Forms Joomla Zero-Days Exploited for Unauthenticated RCE

Two Joomla extensions, iCagenda and Balbooa Forms, contain maximum severity CVSS 10.0 arbitrary file upload flaws (CVE-2026-48939 and CVE-2026-56291) that allow unauthenticated remote code execution. Both were exploited as zero-days before patches shipped and now sit in CISA's KEV catalog. Update iCagenda to 4.0.8 or 3.9.15 and Balbooa Forms to 2.4.1 immediately and hunt for planted web shells.

Read more
critical
CVE AdvisoryVulnerabilityJul 13, 2026

CRITICAL: Progress Orders ShareFile Customers to Shut Down Storage Zone Controllers Over Credible Threat

Progress ordered ShareFile customers to shut down the Windows servers running their Storage Zone Controllers on July 10, 2026, over a credible but undisclosed threat. The move follows April's chainable pre-authentication flaws CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1), which allow unauthenticated remote code execution on internet-facing controllers.

Read more
critical
CVE AdvisoryVulnerabilityJul 12, 2026

CRITICAL: Progress Orders ShareFile Customers to Pull Storage Zone Controllers Offline Over Credible Threat

Progress Software has ordered ShareFile customers to manually power down the Windows servers running Storage Zone Controllers over a credible external security threat, with no patch available and no CVE disclosed. The emergency shutdown targets the same internet facing component that had a pre authentication RCE chain, CVE-2026-2699 and CVE-2026-2701, disclosed in April 2026.

Read more
critical
CVE AdvisoryVulnerabilityJul 11, 2026

CRITICAL: Zimbra Classic Web Client Flaw Lets a Single Crafted Email Hijack Your Inbox

Zimbra shipped an emergency fix for a critical stored cross-site scripting flaw in its Classic Web Client that lets a crafted email run malicious code inside a victim's authenticated session the moment they open it. Google's Threat Analysis Group reported it, no CVE is assigned yet, and administrators should upgrade to Collaboration Suite 10.1.19 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJul 9, 2026

CRITICAL: Ubiquiti Ships Emergency UniFi Fixes for CVSS 10.0 Unauthenticated Command Injection

Ubiquiti disclosed 25 vulnerabilities across the UniFi ecosystem on July 8, 2026, including seven critical flaws. The worst, CVE-2026-50746, is a CVSS 10.0 unauthenticated command injection in UniFi Connect that lets any network-adjacent attacker run commands as the host. With roughly 100,000 UniFi OS endpoints exposed to the internet, patching to the fixed releases is urgent.

Read more
critical
CVE AdvisoryVulnerabilityJul 8, 2026

CRITICAL: Adobe ColdFusion Bug (CVE-2026-48282) Weaponized Within Hours as CISA Starts the Patch Clock

Adobe ColdFusion is under active attack through CVE-2026-48282, a CVSS 10.0 path traversal flaw in the Remote Development Services component that hands unauthenticated attackers remote code execution. Exploitation began within about two hours of disclosure, and CISA has added it to its Known Exploited Vulnerabilities catalog with a July 10 federal patch deadline. Patch to ColdFusion 2025 update 10 or 2023 update 21 now.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Page 1 of 7Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.