ProBackend
Vulnerabilities & Exploits

Vulnerabilities & Exploits

CVEs, zero-days, patching and exploited weaknesses.

mfa bypass authentication attacksJun 23, 20263 min

Vulnerability in VS Code Web Sandbox Exposes Unscoped GitHub OAuth Tokens via Malicious Webviews

Security researcher Ammar Askar disclosed a zero-day vulnerability in github.dev that allows attackers to exfiltrate unscoped GitHub OAuth tokens using the postMessage keyboard shortcut event bubbling of VS Code webviews.

cyber threat intelligenceJun 22, 20263 min

New CTP Vulnerability Allows Remote Speaker Control and Device Infection

A newly discovered vulnerability in the CTP protocol enables attackers to compromise speakers via Bluetooth or USB, potentially leading to unauthorized control and further device infection.

cloud security incidentsJun 22, 20263 min

CISA Orders Agencies to Patch Critical Check Point VPN Flaw

CISA has mandated that U.S. government agencies patch a critical vulnerability in Check Point security gateways following reports of its exploitation in zero-day attacks by the Qilin ransomware gang.

cyber threat intelligenceJun 22, 20265 min

The 'Sender' Spoofing Vulnerability: Misconfiguration Exploitation

An exploration of widespread email spoofing vulnerabilities stemming from misconfigured SPF, DKIM, and DMARC settings, and how attackers are actively exploiting these gaps in the wild. Ensuring robust and proactive email security posture by effectively managing and enforcing authentication protocols is more critical than ever.

cybersecurityJun 19, 20265 min

Microsoft Patches Exchange Server Zero-Day CVE-2026-42897 Exploited in Active Attacks

Microsoft has patched CVE-2026-42897, a high-severity spoofing vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition that allows remote attackers to execute arbitrary JavaScript in cross-site scripting attacks against Outlook Web Access users.

cybersecurityJun 19, 20264 min

Cisco SD-WAN Zero-Day (CVE-2026-20245) - Root Privilege Escalation Vulnerability

High-severity unpatched vulnerability in Cisco Catalyst SD-WAN Manager actively exploited for root privilege escalation. CVE-2026-20245 enables attackers to escalate privileges, install backdoors, and manipulate network traffic. Immediate mitigation steps and patch timeline.

cybersecurityJun 18, 20263 min

"Sender" Email Spoofing Vulnerability: How Exchange Misconfiguration Enables Active Attacks

Detailed analysis of the Sender email spoofing vulnerability exploiting Exchange Server misconfigurations, including active exploitation evidence and remediation guidance.

cybersecurityJun 18, 20264 min

Check Point links VPN zero-day attacks to Qilin ransomware gang

Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks linked to the Qilin ransomware gang.

cybersecurityJun 18, 20263 min

Max Severity Ivanti Sentry Vulnerability Now Exploited in Attacks

Attackers are now targeting CVE-2026-10520, a recently patched maximum-severity flaw in Ivanti Sentry that allows remote code execution with root privileges on Internet-exposed secure mobile gateways.

cybersecurityJun 15, 20265 min

Oracle PeopleSoft RCE Vulnerability CVE-2026-35273: Emergency Alert for Zero-Day Exploited by ShinyHunters

Critical unauthenticated remote code execution flaw (CVSS 9.8) in Oracle PeopleSoft PeopleTools actively exploited by ShinyHunters extortion gang targeting 300+ instances across 100+ organizations.

ai agent security safetyJun 14, 20265 min

Langflow Path Traversal Vulnerability CVE-2026-5027 Actively Exploited in Attacks

Attackers are actively exploiting a high-severity path traversal vulnerability in Langflow, the popular AI development platform. The flaw allows unauthenticated attackers to write arbitrary files on exposed servers, potentially leading to remote code execution. This article details the vulnerability, its exploitation timeline, and necessary mitigation steps.