Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
88 articles found
Featured Story
critical
Jul 9, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: Ubiquiti Ships Emergency UniFi Fixes for CVSS 10.0 Unauthenticated Command Injection

Ubiquiti disclosed 25 vulnerabilities across the UniFi ecosystem on July 8, 2026, including seven critical flaws. The worst, CVE-2026-50746, is a CVSS 10.0 unauthenticated command injection in UniFi Connect that lets any network-adjacent attacker run commands as the host. With roughly 100,000 UniFi OS endpoints exposed to the internet, patching to the fixed releases is urgent.

By Danny MercerRead Full Article
CVE-2026-48282
critical
CVE AdvisoryVulnerabilityCVE-2026-48282 Jul 8, 2026

CRITICAL: Adobe ColdFusion Bug (CVE-2026-48282) Weaponized Within Hours as CISA Starts the Patch Clock

Adobe ColdFusion is under active attack through CVE-2026-48282, a CVSS 10.0 path traversal flaw in the Remote Development Services component that hands unauthenticated attackers remote code execution. Exploitation began within about two hours of disclosure, and CISA has added it to its Known Exploited Vulnerabilities catalog with a July 10 federal patch deadline. Patch to ColdFusion 2025 update 10 or 2023 update 21 now.

Read more
critical
CVE AdvisoryVulnerabilityJul 7, 2026

CRITICAL: BeyondTrust Auth Bypass Flaws Hand Attackers the Keys to Remote Support and PRA

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two unauthenticated CVSS 9.2 auth bypass bugs (CVE-2026-40138 and CVE-2026-40139) that let network-positioned attackers reach elevated accounts. All versions at or below 25.3.2 are vulnerable, with fixes in the 25.3.3 line. Cloud customers were patched April 21 2026, so self-hosted admins are the ones who need to move now.

Read more
critical
CVE AdvisoryVulnerabilityJun 19, 2026

CRITICAL: F5 Patches Two NGINX Flaws Handing Unauthenticated RCE to Remote Attackers

F5 disclosed two critical NGINX vulnerabilities on June 17, 2026, both scoring CVSS 4.0 9.2. CVE-2026-42530 is a use-after-free in the HTTP/3 QPACK encoder and CVE-2026-42055 is a heap-based buffer overflow in the HTTP/2 proxy and gRPC modules. Both are remotely exploitable by unauthenticated attackers and affect a huge swath of the NGINX Open Source and NGINX Plus install base.

Read more
critical
CVE AdvisoryVulnerabilityJun 17, 2026

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Attackers Chain Auth Bypass and Command Injection

Three critical FortiSandbox vulnerabilities are under active exploitation, led by CVE-2026-39813, a path traversal flaw in the JRPC API that lets unauthenticated attackers bypass authentication via crafted HTTP requests. Paired with two OS command injection bugs, the chain gives remote code execution on appliances running FortiSandbox 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8. Upgrade to 5.0.6 or 4.4.9 immediately.

Read more
critical
CVE AdvisoryVulnerabilityJun 16, 2026

CRITICAL: Three FortiSandbox Flaws Under Active Exploitation as Defenders Race to Patch

Defused Cyber reported active exploitation of three CVSS 9.1 FortiSandbox vulnerabilities inside a 24-hour window. CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 allow unauthenticated remote code execution and authentication bypass on the appliance that other Fortinet products trust to verdict malware. Patches are available, but the 4.2 branch requires migration to a supported release.

Read more
CVE-2026-42271
critical
CVE AdvisoryVulnerabilityCVE-2026-42271 Jun 9, 2026

CRITICAL: LiteLLM RCE Chain Hits CISA KEV as Attackers Hammer Exposed AI Gateways

LiteLLM CVE-2026-42271 chained with Starlette CVE-2026-48710 (BadHost) creates an unauthenticated RCE path scoring CVSS 10.0 against AI gateways. CISA added the flaw to the KEV catalog after confirming active exploitation. Patch LiteLLM 1.83.7 and Starlette 1.0.1 immediately or block the vulnerable MCP test endpoints at your reverse proxy.

Read more
CVE-2026-20230
critical
CVE AdvisoryVulnerabilityCVE-2026-20230 Jun 5, 2026

CRITICAL: Cisco Unified CM SSRF Flaw CVE-2026-20230 Hands Attackers Root, PoC Already Public

Cisco patched CVE-2026-20230, an unauthenticated SSRF in the Unified Communications Manager WebDialer Web Service that lets remote attackers write arbitrary files and escalate to root. Public proof-of-concept code is already circulating. CVSS 8.6 with a Critical Security Impact Rating from Cisco PSIRT. Version 14SU6 is fixed, but the 15 train waits until September 2026 for 15SU5 with only an interim COP patch available now.

Read more
CVE-2026-45247
critical
CVE AdvisoryVulnerabilityCVE-2026-45247 Jun 4, 2026

CRITICAL: Active Exploitation Hits Magento Stores via Mirasvit Cache Warmer Bug (CVE-2026-45247)

CISA added CVE-2026-45247, a CVSS 9.8 PHP object deserialization flaw in the Mirasvit Full Page Cache Warmer extension for Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalog after Imperva confirmed active unauthenticated RCE attacks against gaming and business storefronts in the US, UK, France, and Australia. Patch to version 1.11.12 or disable the extension immediately.

Read more
CVE-2026-0257
critical
CVE AdvisoryVulnerabilityCVE-2026-0257 Jun 2, 2026

CRITICAL: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation

An authentication bypass flaw in PAN-OS GlobalProtect portal and gateway (CVE-2026-0257, CVSS 9.1) is under active exploitation. Rapid7 confirmed in-the-wild attacks beginning May 17, and the CISA federal remediation deadline expired June 1. Patches and workarounds are available across PAN-OS 10.2, 11.1, 11.2, and 12.1 branches.

Read more
CVE-2026-8732
critical
CVE AdvisoryVulnerabilityCVE-2026-8732 Jun 1, 2026

CRITICAL: WP Maps Pro Bug (CVE-2026-8732) Spawns Admin Accounts on 15,000 WordPress Sites

A CVSS 9.8 unauthenticated admin account creation flaw in the WP Maps Pro WordPress plugin (CVE-2026-8732) is under active mass exploitation. Wordfence blocked 2,858 attempts and Defiant blocked more than 3,600 within a single 24 hour window. The bug abuses a vendor-support shortcut to mint administrator accounts via an unauthenticated AJAX endpoint. All versions through 6.1.0 are vulnerable. Patch to 6.1.1 and hunt for rogue admins emailed support@flippercode.com.

Read more
CVE-2026-35616
critical
CVE AdvisoryVulnerabilityCVE-2026-35616 May 29, 2026

CRITICAL: FortiClient EMS Bug CVE-2026-35616 Weaponized to Push EKZ Infostealer Across Managed Fleets

Threat actors are abusing CVE-2026-35616, a CVSS 9.1 pre-authentication API bypass in FortiClient EMS, to hijack endpoint management consoles and push the newly identified EKZ infostealer to every managed endpoint disguised as FortiEndpoint_Patch.exe. Patch to 7.4.7 immediately and hunt for indicators in EMS logs and on managed hosts.

Read more
CVE-2026-20223
critical
CVE AdvisoryVulnerabilityCVE-2026-20223 May 22, 2026

CRITICAL: Cisco Secure Workload Hit With CVSS 10.0 REST API Flaw That Hands Over Site Admin

Cisco disclosed CVE-2026-20223, a maximum severity CVSS 10.0 flaw in Secure Workload that allows unauthenticated remote attackers to gain Site Admin privileges by sending crafted requests to internal REST API endpoints. The vulnerability crosses tenant boundaries on both SaaS and on-premises deployments, has no workarounds, and is fixed in releases 3.10.8.3 and 4.0.3.17.

Read more
CVE-2020-17103
critical
CVE AdvisoryVulnerabilityCVE-2020-17103 May 19, 2026

CRITICAL: 'MiniPlasma' Windows 0-Day Resurrects 2020 SYSTEM Escalation Bug Microsoft Thought It Killed

A working zero-day exploit dubbed MiniPlasma escalates standard users to SYSTEM on fully patched Windows 11. It abuses cldflt.sys, the same Cloud Filter driver behind CVE-2020-17103 that Microsoft 'fixed' in 2020. PoC is public on GitHub. No patch yet. Assume compromise paths exist on every Windows endpoint until the next Patch Tuesday.

Read more
CVE-2026-42945
critical
CVE AdvisoryVulnerabilityCVE-2026-42945 May 18, 2026

CRITICAL: 18-Year-Old NGINX Rewrite Module Flaw Hits Active Exploitation in Days

A heap buffer overflow lurking in NGINX's ngx_http_rewrite_module since 2008 went from coordinated disclosure to active in-the-wild exploitation in roughly seventy-two hours. CVE-2026-42945 affects every release from 0.6.27 through 1.30.0 across both Open Source and Plus, can crash worker processes trivially, and can reach remote code execution on hosts where ASLR is disabled. Patches are available in NGINX 1.30.1 and 1.31.0.

Read more
CVE-2026-20182
critical
CVE AdvisoryVulnerabilityCVE-2026-20182 May 17, 2026

CRITICAL: Cisco Catalyst SD-WAN CVE-2026-20182 Hits CVSS 10.0 with Active Exploitation by UAT-8616

Cisco patched CVE-2026-20182, a CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Manager that lets an unauthenticated remote attacker gain administrative access via the vdaemon peering service on UDP/12346. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of May 17, 2026. Threat cluster UAT-8616 is actively exploiting it. No workarounds, only patches.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 3 of 5Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.