Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
Attackers Exploit Claude AI's Legitimate Domain to Host Malicious Installer in Bing Malvertising Campaign
A malvertising campaign on Bing uses a fake Claude desktop app installer hosted on the legitimate Claude.ai domain to deliver SectopRAT malware, compromising at least 29 organizations.
Free Unofficial Patches for Windows LegacyHive Zero-Day Let Non-Admins Take Over Systems
ACROS Security’s micropatches block LegacyHive, a Windows User Profile Service flaw letting non-admins hijack registry hives and escalate privileges on up-to-date systems — without waiting for Microsoft.
CVE-2026-50522: How SharePoint's Deserialization Flaw Lets Attackers Steal Machine Keys and Stay Forever
Hackers are actively exploiting CVE-2026-50522, a deserialization flaw in Microsoft SharePoint, to steal machine keys and maintain long-term access to compromised systems.
Check Point Patches SmartConsole Zero-Day as Artificial Intelligence Cybersecurity Threats Escalate
Israeli cybersecurity firm Check Point Software addressed CVE-2026-16232, an authentication bypass vulnerability in the SmartConsole GUI admin panel that allows unauthenticated attackers to obtain administrator credentials, prompting CISA's BOD 26-04 mandate for federal agencies.
Critical U-Boot Flaws Open Door for Stealthy Firmware Attacks Before OS Boot
Six vulnerabilities in the widely used U-Boot bootloader discovered by Binarly could allow attackers to execute malicious code during device boot before the operating system starts, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.
CISA Mandates Immediate Remediation of Actively Exploited Langflow RCE Flaw
CISA has issued an emergency directive to U.S. federal agencies requiring the patching of a critical RCE vulnerability, CVE-2026-0770, in the Langflow framework, which is currently being exploited in the wild.
ServiceNow AI Platform RCE: How CVE-2026-6875 Went From Disclosure to Active Exploitation in Weeks
A critical pre-authentication sandbox-escape vulnerability in the ServiceNow AI Platform is being actively exploited in the wild just one week after patches for self-hosted instances were released, putting Fortune 500 enterprise workflows at risk.
CISA Mandates Federal Patch for Actively Exploited Adobe ColdFusion Zero-Day
The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch a critical Adobe ColdFusion vulnerability by Friday after threat actors began exploiting it within hours of disclosure.
Public Exploits Released for Critical wp2shell RCE Vulnerabilities in WordPress Core — Patch Now
Critical unauthenticated remote code execution vulnerabilities in WordPress Core (CVE-2026-63030 and CVE-2026-60137) have been weaponized in the wild, requiring immediate patching to 7.0.2 or 6.9.5.
HollowByte: An 11-Byte Kill Switch for OpenSSL Servers
A newly disclosed vulnerability in OpenSSL allows unauthenticated attackers to exhaust server memory via a minimal 11-byte TLS handshake payload, leading to permanent heap fragmentation and service disruption.
Attackers Are Now Exploiting a Maximum-Severity Adobe ColdFusion Vulnerability
Attackers are actively exploiting a maximum-severity vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, enabling unauthenticated remote code execution. Adobe issued emergency patches on July 1, 2026, but exploitation began within two hours of public disclosure.
CISA Orders Emergency Patch for Actively Exploited FortiSandbox Flaws by Sunday
The U.S. Cybersecurity and Infrastructure Security Agency has added two critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog and issued a Binding Operational Directive requiring federal agencies to patch the flaws by Sunday, July 19.