ProBackend
Vulnerabilities & Exploits

Vulnerabilities & Exploits

CVEs, zero-days, patching and exploited weaknesses.

active vulnerability exploitationJul 24, 20264 min

ServiceNow AI Platform RCE: How CVE-2026-6875 Went From Disclosure to Active Exploitation in Weeks

A critical pre-authentication sandbox-escape vulnerability in the ServiceNow AI Platform is being actively exploited in the wild just one week after patches for self-hosted instances were released, putting Fortune 500 enterprise workflows at risk.

vulnerability patch managementJul 22, 20263 min

CISA Mandates Federal Patch for Actively Exploited Adobe ColdFusion Zero-Day

The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch a critical Adobe ColdFusion vulnerability by Friday after threat actors began exploiting it within hours of disclosure.

active vulnerability exploitationJul 22, 20265 min

Public Exploits Released for Critical wp2shell RCE Vulnerabilities in WordPress Core — Patch Now

Critical unauthenticated remote code execution vulnerabilities in WordPress Core (CVE-2026-63030 and CVE-2026-60137) have been weaponized in the wild, requiring immediate patching to 7.0.2 or 6.9.5.

vulnerability exploitsJul 20, 20265 min

HollowByte: An 11-Byte Kill Switch for OpenSSL Servers

A newly disclosed vulnerability in OpenSSL allows unauthenticated attackers to exhaust server memory via a minimal 11-byte TLS handshake payload, leading to permanent heap fragmentation and service disruption.

cloud security incidentsJul 20, 20265 min

Attackers Are Now Exploiting a Maximum-Severity Adobe ColdFusion Vulnerability

Attackers are actively exploiting a maximum-severity vulnerability in Adobe ColdFusion, tracked as CVE-2026-48282, enabling unauthenticated remote code execution. Adobe issued emergency patches on July 1, 2026, but exploitation began within two hours of public disclosure.

active vulnerability exploitationJul 20, 20264 min

CISA Orders Emergency Patch for Actively Exploited FortiSandbox Flaws by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency has added two critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog and issued a Binding Operational Directive requiring federal agencies to patch the flaws by Sunday, July 19.

cloud security incidentsJul 18, 20263 min

INC Ransomware: How Operational Discipline Beat Flashy Exploits

INC ransomware emerges as a top-tier RaaS operation by mastering fundamentals—targeting pressured sectors, leveraging timing from competitor shutdowns, and rewriting its malware in Rust—claiming 800+ victims since 2023.

ai powered vulnerability discoveryJul 17, 20264 min

AI Cybersecurity in Action: How a Vulnerability Vending Machine Turns Code Slices Into Zero-Days

Intruder’s AI pipeline automates zero-day discovery in WordPress plugins using code slicing and LLMs — not theory, but a working system that found a critical SQL injection with no human input.

active vulnerability exploitationJul 17, 20263 min

Microsoft Links Upcoming Patch Tuesday Surge to AI-Powered Discovery

As Microsoft adopts AI-based vulnerability scanning tools like MDASH, the company warns that customers should prepare for more frequent and voluminous security update releases.

active vulnerability exploitationJul 17, 20265 min

AI Cybersecurity Threats: CISA Warns of Actively Exploited SharePoint Flaws Enabling RCE and Persistence

CISA has issued an urgent alert: attackers are weaponizing three SharePoint Server vulnerabilities to bypass authentication, execute remote code, and steal IIS machine keys for persistent access. Federal agencies have just days to patch.

windows security updatesJul 16, 20264 min

Windows 10’s Last Stand: The 570-Flaw Patch That Bought Us Until 2027

Microsoft's final extended security update for Windows 10 patches 300+ vulnerabilities, enforces TDI transport registration, and quietly shifts Secure Boot certificate deployment — a last gasp before the OS exits stage left.

ai open source vulnerability patchingJul 3, 20266 min

AI Cybersecurity in Action: How IBM’s $5 Billion Patching Bet Rewrites the Rules

IBM and Red Hat have launched Project Lightwell, a $5 billion initiative to accelerate the patching of open-source vulnerabilities faster than AI systems can discover them. The program combines AI-driven vulnerability detection with automated remediation pipelines and a global coalition of developers, security researchers, and enterprise partners.