Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
New CTP Vulnerability Allows Remote Speaker Control and Device Infection
A newly discovered vulnerability in the CTP protocol enables attackers to compromise speakers via Bluetooth or USB, potentially leading to unauthorized control and further device infection.
CISA Orders Agencies to Patch Critical Check Point VPN Flaw
CISA has mandated that U.S. government agencies patch a critical vulnerability in Check Point security gateways following reports of its exploitation in zero-day attacks by the Qilin ransomware gang.
The 'Sender' Spoofing Vulnerability: Misconfiguration Exploitation
An exploration of widespread email spoofing vulnerabilities stemming from misconfigured SPF, DKIM, and DMARC settings, and how attackers are actively exploiting these gaps in the wild. Ensuring robust and proactive email security posture by effectively managing and enforcing authentication protocols is more critical than ever.
Microsoft Patches Exchange Server Zero-Day CVE-2026-42897 Exploited in Active Attacks
Microsoft has patched CVE-2026-42897, a high-severity spoofing vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition that allows remote attackers to execute arbitrary JavaScript in cross-site scripting attacks against Outlook Web Access users.
Cisco SD-WAN Zero-Day (CVE-2026-20245) - Root Privilege Escalation Vulnerability
High-severity unpatched vulnerability in Cisco Catalyst SD-WAN Manager actively exploited for root privilege escalation. CVE-2026-20245 enables attackers to escalate privileges, install backdoors, and manipulate network traffic. Immediate mitigation steps and patch timeline.