Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
202 articles found
CVE-2026-9082
high
CVE AdvisoryVulnerabilityCVE-2026-9082 May 23, 2026

HIGH: Drupal Core SQL Injection CVE-2026-9082 Hits CISA KEV Days After Disclosure

Drupal disclosed SA-CORE-2026-004 (CVE-2026-9082), a Highly Critical SQL injection in the core database abstraction API that lets unauthenticated attackers escalate privileges and reach remote code execution on PostgreSQL-backed sites. Imperva is tracking 15,000+ attack attempts against nearly 6,000 sites across 65 countries. CISA added the bug to KEV on May 22 with a federal patch deadline of May 27, 2026.

Read more
CVE-2026-20223
critical
CVE AdvisoryVulnerabilityCVE-2026-20223 May 22, 2026

CRITICAL: Cisco Secure Workload Hit With CVSS 10.0 REST API Flaw That Hands Over Site Admin

Cisco disclosed CVE-2026-20223, a maximum severity CVSS 10.0 flaw in Secure Workload that allows unauthenticated remote attackers to gain Site Admin privileges by sending crafted requests to internal REST API endpoints. The vulnerability crosses tenant boundaries on both SaaS and on-premises deployments, has no workarounds, and is fixed in releases 3.10.8.3 and 4.0.3.17.

Read more
CVE-2026-41091
high
CVE AdvisoryVulnerabilityCVE-2026-41091 May 21, 2026

HIGH: Microsoft Defender Burns Again as Two New Zero-Days Hit Active Exploitation

Microsoft confirmed on May 21 that CVE-2026-41091, a CVSS 7.8 link-following privilege escalation in the Microsoft Malware Protection Engine, and CVE-2026-45498, a denial-of-service flaw in the Defender Antimalware Platform, are both under active exploitation. CISA added both to the KEV catalog with a June 3 federal remediation deadline. Defender engine version 1.1.26040.8 and Antimalware Platform 4.18.26040.7 contain the fixes and ship automatically through definition updates.

Read more
CVE-2026-45585
high
CVE AdvisoryVulnerabilityCVE-2026-45585 May 20, 2026

HIGH: Microsoft Ships Mitigation for YellowKey BitLocker Bypass Zero-Day (CVE-2026-45585)

Microsoft published mitigation guidance for CVE-2026-45585, the YellowKey BitLocker bypass zero-day publicly disclosed by researcher Chaotic Eclipse last week. The flaw lives in the FsTx Auto Recovery Utility inside Windows Recovery Environment and lets anyone with physical access and a USB stick spawn an unrestricted shell with the BitLocker-protected volume already mounted. Windows 11 24H2, 25H2, 26H1 and Windows Server 2025 are affected.

Read more
CVE-2020-17103
critical
CVE AdvisoryVulnerabilityCVE-2020-17103 May 19, 2026

CRITICAL: 'MiniPlasma' Windows 0-Day Resurrects 2020 SYSTEM Escalation Bug Microsoft Thought It Killed

A working zero-day exploit dubbed MiniPlasma escalates standard users to SYSTEM on fully patched Windows 11. It abuses cldflt.sys, the same Cloud Filter driver behind CVE-2020-17103 that Microsoft 'fixed' in 2020. PoC is public on GitHub. No patch yet. Assume compromise paths exist on every Windows endpoint until the next Patch Tuesday.

Read more
CVE-2026-42945
critical
CVE AdvisoryVulnerabilityCVE-2026-42945 May 18, 2026

CRITICAL: 18-Year-Old NGINX Rewrite Module Flaw Hits Active Exploitation in Days

A heap buffer overflow lurking in NGINX's ngx_http_rewrite_module since 2008 went from coordinated disclosure to active in-the-wild exploitation in roughly seventy-two hours. CVE-2026-42945 affects every release from 0.6.27 through 1.30.0 across both Open Source and Plus, can crash worker processes trivially, and can reach remote code execution on hosts where ASLR is disabled. Patches are available in NGINX 1.30.1 and 1.31.0.

Read more
CVE-2026-20182
critical
CVE AdvisoryVulnerabilityCVE-2026-20182 May 17, 2026

CRITICAL: Cisco Catalyst SD-WAN CVE-2026-20182 Hits CVSS 10.0 with Active Exploitation by UAT-8616

Cisco patched CVE-2026-20182, a CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Manager that lets an unauthenticated remote attacker gain administrative access via the vdaemon peering service on UDP/12346. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of May 17, 2026. Threat cluster UAT-8616 is actively exploiting it. No workarounds, only patches.

Read more
CVE-2026-42897
high
CVE AdvisoryVulnerabilityCVE-2026-42897 May 16, 2026

HIGH: Microsoft Exchange Server XSS Flaw CVE-2026-42897 Under Active Attack

Microsoft Exchange Server CVE-2026-42897 is a cross-site scripting flaw in Outlook Web Access that lets a crafted email execute JavaScript in the victim OWA session. CISA added it to the Known Exploited Vulnerabilities catalog on May 15, 2026 after confirmed in-the-wild exploitation, with a May 29 federal mitigation deadline. Exchange Server 2016, 2019, and Subscription Edition are affected. Exchange Online is not. Microsoft scored it CVSS 8.1, and patches shipped in the May 2026 security update.

Read more
CVE-2026-41940
critical
CVE AdvisoryVulnerabilityCVE-2026-41940 May 12, 2026

CRITICAL: cPanel WHM Authentication Bypass CVE-2026-41940 Exploited for Two Months Before Patch

cPanel and WHM are bleeding root through CVE-2026-41940, a CVSS 9.8 CRLF-injection authentication bypass that has been exploited in the wild since late February 2026. The April 28 patch is available now, but attackers running automated campaigns from over 2,000 source IPs have been deploying a cross-platform Go backdoor on compromised hosts for two months. Patch immediately and assume breach on any internet-exposed unpatched server.

Read more
CVE-2026-6973
high
CVE AdvisoryVulnerabilityCVE-2026-6973 May 11, 2026

HIGH: Ivanti EPMM CVE-2026-6973 Under Active Exploitation, CISA Mandates 3-Day Federal Patch Deadline

Ivanti has confirmed in-the-wild exploitation of CVE-2026-6973, an authenticated remote code execution flaw in on-premises Endpoint Manager Mobile rated CVSS 7.2. CISA added the bug to its Known Exploited Vulnerabilities catalog on May 7 and gave federal agencies until May 10, 2026 to remediate. The exploitation pattern strongly suggests reuse of admin credentials harvested during the unauthenticated EPMM compromises disclosed in January 2026.

Read more
high
CVE AdvisoryVulnerabilityMay 9, 2026

Zara Joins the Anodot Casualty List as ShinyHunters Cashes In on Third-Party Trust

Inditex confirmed roughly 197,000 Zara customer records were exposed via Anodot, an Israeli AI analytics platform compromised by ShinyHunters. The crew used stolen authentication tokens to pivot into BigQuery instances of multiple downstream customers, hauling out 140GB from Zara alone. Email addresses, order IDs, SKUs, and support tickets leaked, but no payment data or passwords. The supply-chain pattern mirrors the 2024 Snowflake campaign.

Read more
CVE-2026-43284
high
CVE AdvisoryVulnerabilityCVE-2026-43284 May 9, 2026

HIGH: 'Dirty Frag' Linux Kernel Bugs Hand Locals Root, One Half Already Patched, RxRPC Half Still Open (CVE-2026-43284, CVE-2026-43500)

Two Linux kernel page-cache write bugs collectively named Dirty Frag let any unprivileged local user pop a root shell in one command. CVE-2026-43284 in xfrm-ESP was patched May 8. CVE-2026-43500 in RxRPC is still unpatched. Microsoft has already seen active exploitation in the wild and a public proof-of-concept is on GitHub.

Read more
CVE-2026-23918
high
CVE AdvisoryVulnerabilityCVE-2026-23918 May 7, 2026

HIGH: Apache HTTP/2 Double-Free (CVE-2026-23918) Lets Two Frames DoS Your Web Server, RCE Already Demoed

Apache HTTP Server 2.4.66 ships a double-free in mod_http2 that crashes worker processes with two HTTP/2 frames and no authentication. CVSS 8.8, DoS exploitation already in the wild, and a public PoC chain converts the bug to remote code execution on default Debian and Docker builds. The fix is in 2.4.67, released May 4.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

PreviousPage 5 of 11Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.