Vulnerabilities & Exploits
CVEs, zero-days, patching and exploited weaknesses.
PixelSmash (CVE-2026-8461): FFmpeg Flaw Lets Attackers Execute Code on Jellyfin via Media Library Scans
A newly disclosed heap out-of-bounds write in FFmpeg's MagicYUV decoder (CVE-2026-8461) — dubbed PixelSmash — enables remote code execution on Jellyfin under ASLR-disabled conditions and denial-of-service attacks across media apps including Kodi, OBS Studio, PhotoPrism, Emby, and Nextcloud.
Root Access via WebDialer: Active Exploitation of Cisco CUCM's SSRF Flaw
Attackers are actively exploiting CVE-2026-20230, a high-severity Server-Side Request Forgery (SSRF) vulnerability in the WebDialer component of Cisco Unified Communications Manager, to achieve root privileges via unauthorized file writes.
CVE-2026-35273 Under Fire: Inside the ShinyHunters Global Enterprise Data Extortion Wave
A deep dive into CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft PeopleTools exploited by the ShinyHunters gang to breach hundreds of organizations, steal sensitive personnel and regulatory data, and demand ransoms.
ShinyHunters Exploits PeopleSoft Zero-Day to Steal 454,600 Student Records from Nottingham’s Global Campuses
Over 450,000 Nottingham students had their records stolen because of a PeopleSoft exploit chain. Here is how legacy integrations create massive blind spots for enterprise cloud defense.
Beating the 38-Hour Exploit Window: The Fatal Risk of Lagging Vulnerability Metrics
With the median time to exploitation dropping to just 1.6 days, traditional database-driven vulnerability alerts are no longer fast enough. This article outlines why organizations must shift away from slow public registries toward real-time telemetry and automated asset inventory matching.
Analyzing the Tri-CVE Chain Permitting Full Administrative Hijacks on Ubiquiti Management Controllers
A detailed security analysis of the high-impact three-vulnerability exploit chain (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) affecting Ubiquiti UniFi OS Server, detailing how Nginx gateway routing mismatches enable unauthenticated remote code execution, active KEV exploitation trends, and mandatory post-compromise cleanup.
Seven Critical ColdFusion and Campaign Flaws Patched as Adobe Accelerates Release Cycles
Adobe has released security updates addressing multiple maximum-severity vulnerabilities in ColdFusion and Campaign Classic platforms, with high risks of exploitation, urging swift mitigation.
Beyond the Noise: Unpacking the HTTP/2 Bomb Vulnerability
A closer look at the high-severity CVE-2026-49975 flaw, its impact on large-scale web architecture, and the urgent need for consistent patching across vulnerable server environments.
Active Attacks Target Critical SSRF Vulnerability in Cisco Unified Communications Manager
Threat actors are actively leveraging a newly disclosed server-side request forgery (SSRF) flaw, CVE-2026-20230, in Cisco's Unified Communications Manager. This high-severity issue, which permits arbitrary file-write operations, is currently being used for reconnaissance, with concerns for potential remote code execution and root privilege escalation.
Emergency Security Patch Addresses Low-Privilege Remote Code Execution in SharePoint Server
Microsoft released an emergency out-of-band security fix for CVE-2026-45659, a critical remote code execution (RCE) vulnerability in on-premises SharePoint Server. CISA has now added it to the KEV catalog as actively exploited, ordering federal agencies to patch by Saturday under BOD 26-04. Shadowserver tracks over 10,000 exposed SharePoint servers online with no confirmed patch coverage.
AI Accelerates Vulnerability Discovery: Record 206 CVEs on Patch Tuesday Signal New Normal
Artificial intelligence is transforming the cybersecurity landscape by dramatically accelerating the speed and scale of vulnerability discovery, as evidenced by Microsoft's June 2026 Patch Tuesday which addressed a record-breaking 206 vulnerabilities. This unprecedented volume signals that voluminous patch updates could soon become the norm.
Copilot SearchLeak Attack: A Critical Three-Stage Vulnerability Patched
A critical three-stage attack exploiting Microsoft 365 Copilot's search functionality allowed 1-click data theft. Learn how the SearchLeak vulnerability worked and what defenders need to know about this new wave of AI prompt-injection issues.