Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated July 26, 2026 — 168 published advisories, with new analysis most weekdays. Recent coverage includes the PTC Windchill FlexPLM remote code execution flaw under Clop exploitation, a Zimbra webmail cross-site scripting campaign stealing two-factor codes, Check Point SmartConsole CVE-2026-16232, the SharePoint machine-key remote code execution chain (CVE-2026-50522), and a ServiceNow AI Platform remote code execution bug. If one of these touches a system you run and you are not sure what to do next, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
63 articles found
Featured Story
critical
Jun 16, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Defenders Race to Patch

Defused Cyber reported active exploitation of three CVSS 9.1 FortiSandbox vulnerabilities inside a 24-hour window. CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 allow unauthenticated remote code execution and authentication bypass on the appliance that other Fortinet products trust to verdict malware. Patches are available, but the 4.2 branch requires migration to a supported release.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityJun 5, 2026

CRITICAL: Cisco Unified CM SSRF Flaw CVE-2026-20230 Hands Attackers Root, PoC Already Public

Cisco patched CVE-2026-20230, an unauthenticated SSRF in the Unified Communications Manager WebDialer Web Service that lets remote attackers write arbitrary files and escalate to root. Public proof-of-concept code is already circulating. CVSS 8.6 with a Critical Security Impact Rating from Cisco PSIRT. Version 14SU6 is fixed, but the 15 train waits until September 2026 for 15SU5 with only an interim COP patch available now.

Read more
critical
CVE AdvisoryVulnerabilityJun 4, 2026

CRITICAL: Active Exploitation Hits Magento Stores via Mirasvit Cache Warmer Bug (CVE-2026-45247)

CISA added CVE-2026-45247, a CVSS 9.8 PHP object deserialization flaw in the Mirasvit Full Page Cache Warmer extension for Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog after Imperva confirmed active unauthenticated RCE attacks against gaming and business storefronts in the US, UK, France, and Australia. Patch to version 1.11.12 or disable the extension immediately.

Read more
critical
CVE AdvisoryVulnerabilityJun 1, 2026

CRITICAL: WP Maps Pro Bug (CVE-2026-8732) Spawns Admin Accounts on 15,000 WordPress Sites

A CVSS 9.8 unauthenticated admin account creation flaw in the WP Maps Pro WordPress plugin (CVE-2026-8732) is under active mass exploitation. Wordfence blocked 2,858 attempts and Defiant blocked more than 3,600 within a single 24 hour window. The bug abuses a vendor-support shortcut to mint administrator accounts via an unauthenticated AJAX endpoint. All versions through 6.1.0 are vulnerable. Patch to 6.1.1 and hunt for rogue admins emailed support@flippercode.com.

Read more
critical
CVE AdvisoryVulnerabilityMay 22, 2026

CRITICAL: Cisco Secure Workload Hit With CVSS 10.0 REST API Flaw That Hands Over Site Admin

Cisco disclosed CVE-2026-20223, a maximum severity CVSS 10.0 flaw in Secure Workload that allows unauthenticated remote attackers to gain Site Admin privileges by sending crafted requests to internal REST API endpoints. The vulnerability crosses tenant boundaries on both SaaS and on-premises deployments, has no workarounds, and is fixed in releases 3.10.8.3 and 4.0.3.17.

Read more
critical
CVE AdvisoryVulnerabilityMay 18, 2026

CRITICAL: 18-Year-Old NGINX Rewrite Module Flaw Hits Active Exploitation in Days

A heap buffer overflow lurking in NGINX's ngx_http_rewrite_module since 2008 went from coordinated disclosure to active in-the-wild exploitation in roughly seventy-two hours. CVE-2026-42945 affects every release from 0.6.27 through 1.30.0 across both Open Source and Plus, can crash worker processes trivially, and can reach remote code execution on hosts where ASLR is disabled. Patches are available in NGINX 1.30.1 and 1.31.0.

Read more
critical
CVE AdvisoryVulnerabilityMay 17, 2026

CRITICAL: Cisco Catalyst SD-WAN CVE-2026-20182 Hits CVSS 10.0 with Active Exploitation by UAT-8616

Cisco patched CVE-2026-20182, a CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Manager that lets an unauthenticated remote attacker gain administrative access via the vdaemon peering service on UDP/12346. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of May 17, 2026. Threat cluster UAT-8616 is actively exploiting it. No workarounds, only patches.

Read more
critical
CVE AdvisoryVulnerabilityMay 12, 2026

CRITICAL: cPanel WHM Authentication Bypass CVE-2026-41940 Exploited for Two Months Before Patch

cPanel and WHM are bleeding root through CVE-2026-41940, a CVSS 9.8 CRLF-injection authentication bypass that has been exploited in the wild since late February 2026. The April 28 patch is available now, but attackers running automated campaigns from over 2,000 source IPs have been deploying a cross-platform Go backdoor on compromised hosts for two months. Patch immediately and assume breach on any internet-exposed unpatched server.

Read more
critical
CVE AdvisoryVulnerabilityMay 6, 2026

CRITICAL: Palo Alto PAN-OS Zero-Day Hands Attackers Root on Internet-Facing Firewalls (CVE-2026-0300)

CVE-2026-0300 is an unauthenticated buffer overflow in the PAN-OS User-ID Authentication Portal that grants root code execution on PA-Series and VM-Series firewalls. Palo Alto has confirmed limited in-the-wild exploitation against internet-exposed portals. CVSS scores 9.3 for internet-exposed deployments, 8.7 for trusted-network only. Patches roll out from May 13 through May 28, 2026.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 2 of 4Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.