Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated September 11, 2026 — all 201 published advisories are browsable here. The newest one is on the appliance that is supposed to be doing the protecting: a Cisco firewall management flaw under active attack and added to CISA's known-exploited list, on the console that controls the firewalls guarding the whole network (CVE-2026-20079). Behind it, a Chrome zero-day exploited in the wild, where simply visiting a booby-trapped site is enough to get code running on the machine (CVE-2026-87491), and a FreeIPA flaw that hands full administrator rights to anyone who connects without a password, on the directory server that decides who gets into everything else (CVE-2026-76578). The one readers keep coming back to is the Magento and Adobe Commerce zero-day being exploited against live online stores with no vendor patch available (StyleSmuggler). Every one of these sits on a device or service that faces the internet, so the clock starts the day the advisory drops — and a missed patch window is what turns a routine Tuesday into downtime, a breach-notification bill, and lost revenue. If you are not sure whether yours is patched, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
72 articles found
high
CVE AdvisoryVulnerabilityAug 9, 2026

HIGH: WordPress 7.0.3 Fixes Pre-Auth XSS Chaining to PHP Code Execution

WordPress 7.0.3 patches CVE-2026-64638, a pre-authentication cross-site scripting flaw on the login screen that researchers chained all the way to PHP code execution on the server. The CVSS 8.9 bug comes from a parser disagreement between strip_tags and KSES, affects every maintained version before 7.0.3, and was backported to the 4.7 branch. No confirmed exploitation in the wild yet, but the full technique is public.

Read more
high
CVE AdvisoryVulnerabilityAug 3, 2026

HIGH: N-able N-central Auth Bypass Exploited After Incomplete Patch

N-able confirmed that attackers exploited an authentication bypass in N-central to take over administrator accounts on customer RMM servers, then found its original patch was incomplete. CVE-2026-18577 widens the affected range to every build before 2026.3.1.7, which shipped on August 2. Attackers pivoted from compromised consoles into managed endpoints and planted Cloudflare tunnels that survive both reboots and revoked console access.

Read more
high
CVE AdvisoryVulnerabilityJul 24, 2026

HIGH: Russian Spies Turned a Medium-Severity Zimbra Bug Into a 2FA Heist

Russian state-supported actor LAUNDRY BEAR (Void Blizzard) exploited a zero-click Zimbra Collaboration XSS flaw, CVE-2025-66376, as a zero-day for months, stealing 90 days of email, Global Address Lists, saved passwords, and 2FA recovery codes from NATO and Ukrainian targets before minting rogue application passwords for persistent MFA-bypassing access. Patched in November 2025 and now on the CISA KEV list.

Read more
CVE-2026-46242
high
CVE AdvisoryVulnerabilityCVE-2026-46242 Jul 5, 2026

HIGH: Bad Epoll Linux Kernel Flaw Hands Any User Root on Servers and Android (CVE-2026-46242)

A use-after-free race condition in the Linux kernel epoll subsystem lets an unprivileged local user escalate to root with roughly 99 percent reliability. It affects kernel 6.4 and newer across servers, desktops, and Android, can be triggered from a Chrome renderer sandbox, and has no workaround. Only a patched kernel fixes it.

Read more
high
CVE AdvisoryVulnerabilityJun 18, 2026

HIGH: Microsoft Defender RoguePlanet Zero-Day Hits SYSTEM Without a Patch in Sight (CVE-2026-50656)

Researcher Nightmare Eclipse dropped a public PoC for CVE-2026-50656 (RoguePlanet), a TOCTOU race condition in the Microsoft Defender Malware Protection Engine that yields NT AUTHORITY\SYSTEM on fully patched Windows 10 and Windows 11. Microsoft has confirmed the flaw, rated it CVSS 7.8, and is still working on a patch. The PoC works whether real-time protection is enabled or not, leaving defenders with detection and containment as the only options for now.

Read more
high
CVE AdvisoryVulnerabilityJun 13, 2026

HIGH: Velvet Ant Backdoored Linux PAM and OpenSSH to Live in One Network for Nearly a Decade

Sygnia disclosed Operation Highland this week, a China-nexus campaign by the Velvet Ant cluster that compromised core Linux authentication on a victim network from 2016 through 2026. Nine variants of backdoored PAM modules and patched OpenSSH binaries delivered hardcoded magic-password access plus continuous credential and command logging. A parallel commodity tool called PamDOORa now sells for $900 on a Russian forum, putting the same authentication-layer tradecraft within reach of any ransomware affiliate with root.

Read more
CVE-2026-5027
high
CVE AdvisoryVulnerabilityCVE-2026-5027 Jun 11, 2026

HIGH: Langflow Path Traversal CVE-2026-5027 Lets Unauthenticated Attackers Plant Code on Roughly 7,000 Exposed AI Servers

A path traversal flaw in Langflow's POST /api/v2/files endpoint allows unauthenticated attackers to write files anywhere the platform process can reach, opening a clean route to remote code execution on the roughly seven thousand exposed instances Censys is currently tracking. Tenable disclosed CVE-2026-5027 in late March, the maintainers shipped a fix in version 1.10.0 on June 10, and VulnCheck honeypots are catching exploitation right now. Patch immediately or pull the instance off the public internet.

Read more
CVE-2026-11645
high
CVE AdvisoryVulnerabilityCVE-2026-11645 Jun 10, 2026

HIGH: Chrome V8 Zero-Day CVE-2026-11645 Under Active Exploitation, Patch Today

Google confirmed active in the wild exploitation of CVE-2026-11645, an out-of-bounds read and write vulnerability in Chrome V8 with a CVSS score of 8.8. The fifth Chrome zero day patched in 2026 lets attackers run code inside the browser sandbox via a crafted HTML page. Update to Chrome 149.0.7827.102 or .103 immediately and force a relaunch across the fleet.

Read more
high
CVE AdvisoryVulnerabilityJun 8, 2026

HIGH: Miasma Worm Detonates 73 Microsoft GitHub Repos in npm Supply Chain Cascade

GitHub disabled 73 repositories across four Microsoft organizations after the Miasma worm spread through 57 npm packages, including @vapi-ai/server-sdk and ai-sdk-ollama. The TeamPCP-linked variant of Mini Shai-Hulud uses a Phantom Gyp binding.gyp injection plus AI coding assistant rule files in Claude Code, Cursor, Gemini CLI, and VS Code to harvest AWS, GCP, Azure, Vault, and GitHub Actions credentials.

Read more
CVE-2026-20230
high
CVE AdvisoryVulnerabilityCVE-2026-20230 Jun 7, 2026

HIGH: Cisco Unified Communications Manager SSRF Flaw Has a Public PoC and a Root-Level Punchline (CVE-2026-20230)

Cisco's June 3 advisory for CVE-2026-20230 details a critical-rated SSRF in the Unified Communications Manager WebDialer service, with a CVSS 8.6 base score and a public proof-of-concept already in circulation. An unauthenticated attacker on the network can write arbitrary files to the underlying OS and chain that into root. Cisco has released fixes in 14SU6 and an interim COP for the 15 line, with 15SU5 due in September 2026. Disabling WebDialer is the recommended interim mitigation.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Page 1 of 4Next

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.