Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
132 articles found
high
CVE AdvisoryVulnerabilityAug 9, 2026

HIGH: WordPress 7.0.3 Fixes Pre-Auth XSS Chaining to PHP Code Execution

WordPress 7.0.3 patches CVE-2026-64638, a pre-authentication cross-site scripting flaw on the login screen that researchers chained all the way to PHP code execution on the server. The CVSS 8.9 bug comes from a parser disagreement between strip_tags and KSES, affects every maintained version before 7.0.3, and was backported to the 4.7 branch. No confirmed exploitation in the wild yet, but the full technique is public.

Read more
critical
CVE AdvisoryVulnerabilityAug 7, 2026

CRITICAL: Cisco Patches Three CVSS 9.9 Catalyst SD-WAN Flaws and Seven IOS XE Bugs

Cisco shipped security hardening releases for Catalyst SD-WAN and IOS XE on August 5, 2026, fixing 12 flaws including three rated CVSS 9.9 and a 9.8 command injection. There are no workarounds and no configuration mitigations, only fixed images, and the low privileges required rating means any authenticated account on SD-WAN Manager is now a critical severity foothold.

Read more
critical
CVE AdvisoryVulnerabilityAug 6, 2026

CRITICAL: Veeam Service Provider Console CVE-2026-58073 Allows Unauthenticated Credential Theft

Veeam patched four flaws in Service Provider Console, the multi-tenant console that MSPs and hosting providers use to manage customer backups. The most severe, CVE-2026-58073 at CVSS 9.5, lets an unauthenticated attacker impersonate a managed agent and steal that agent's credentials. Every version 9 build through 9.2.1.33875 is affected, and build 9.3.0.35057 is the fix.

Read more
critical
CVE AdvisoryVulnerabilityAug 5, 2026

CRITICAL: Langflow CVE-2026-9198 Hits CISA KEV as Exploit Code Spreads

IBM Langflow carries a CVSS 9.8 unauthenticated remote code execution flaw, CVE-2026-9198, that chains a token minting auto-login endpoint with a code validation endpoint running exec(). CISA added it to the Known Exploited Vulnerabilities catalog with an August 7 federal deadline, public exploit code is circulating, and roughly 7,000 instances are reachable online. Upgrade to 1.10.1 or later and rotate every secret the instance could read.

Read more
high
CVE AdvisoryVulnerabilityAug 3, 2026

HIGH: N-able N-central Auth Bypass Exploited After Incomplete Patch

N-able confirmed that attackers exploited an authentication bypass in N-central to take over administrator accounts on customer RMM servers, then found its original patch was incomplete. CVE-2026-18577 widens the affected range to every build before 2026.3.1.7, which shipped on August 2. Attackers pivoted from compromised consoles into managed endpoints and planted Cloudflare tunnels that survive both reboots and revoked console access.

Read more
critical
CVE AdvisoryVulnerabilityJul 31, 2026

CRITICAL: Azure Cosmos DB CVE-2026-66803 Exposed a Platform-Wide Master Key

Microsoft has disclosed CVE-2026-66803, a CVSS 10.0 improper access control flaw in Azure Cosmos DB that let researchers escape the Gremlin query sandbox and reach a platform wide signing key capable of retrieving the primary key for any Cosmos DB account on the service. Microsoft says no customer data was accessed and no customer action is required, but the finding is a hard lesson in cloud key hygiene and blast radius.

Read more
CVE-2026-16812
critical
CVE AdvisoryVulnerabilityCVE-2026-16812 Jul 28, 2026

CRITICAL: Arista VeloCloud Orchestrator CVSS 10.0 Flaw Exploited in the Wild

Arista has patched CVE-2026-16812, a CVSS 10.0 unauthenticated OS command injection flaw in on-premises VeloCloud Orchestrator that is already under active exploitation. CISA added it to the Known Exploited Vulnerabilities catalog with a July 30, 2026 federal patching deadline, and compromise of the orchestrator can extend to the VeloCloud Edge devices it manages.

Read more
critical
CVE AdvisoryVulnerabilityJul 25, 2026

CRITICAL: Cl0p Is Ransacking PTC Windchill Through a 9.8 Deserialization Bug

Cl0p affiliates are actively exploiting CVE-2026-12569, a CVSS 9.8 unauthenticated RCE in PTC Windchill PDMLink and FlexPLM, chaining it with a FlexPLM WSDL information disclosure to drop JSP web shells and steal engineering data. Exploited as a zero-day since early June 2026 and on the CISA KEV list since June 25. Patch via PTC CS473270 and hunt for compromise now.

Read more
critical
CVE AdvisoryVulnerabilityJul 21, 2026

CRITICAL: ServiceNow AI Platform Pre-Auth RCE (CVE-2026-6875) Under Active Attack

A critical unauthenticated remote code execution flaw in the ServiceNow AI Platform, CVE-2026-6875, is under active attack after threat actors weaponized a sandbox escape against the /assessment_thanks.do endpoint. Scored 9.5 on CVSS 4.0, it lets attackers run code with no credentials. Patches reached hosted instances in April and self hosted customers in June, and every unpatched instance is now a live target.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 2 of 7Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.