ProBackend
Vulnerabilities & Exploits

Vulnerabilities & Exploits

CVEs, zero-days, patching and exploited weaknesses.

software supply chain security3 weeks ago5 min

PixelSmash (CVE-2026-8461): FFmpeg Flaw Lets Attackers Execute Code on Jellyfin via Media Library Scans

A newly disclosed heap out-of-bounds write in FFmpeg's MagicYUV decoder (CVE-2026-8461) — dubbed PixelSmash — enables remote code execution on Jellyfin under ASLR-disabled conditions and denial-of-service attacks across media apps including Kodi, OBS Studio, PhotoPrism, Emby, and Nextcloud.

cloud security incidents3 weeks ago5 min

Root Access via WebDialer: Active Exploitation of Cisco CUCM's SSRF Flaw

Attackers are actively exploiting CVE-2026-20230, a high-severity Server-Side Request Forgery (SSRF) vulnerability in the WebDialer component of Cisco Unified Communications Manager, to achieve root privileges via unauthorized file writes.

insurance regulatory data security3 weeks ago3 min

CVE-2026-35273 Under Fire: Inside the ShinyHunters Global Enterprise Data Extortion Wave

A deep dive into CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft PeopleTools exploited by the ShinyHunters gang to breach hundreds of organizations, steal sensitive personnel and regulatory data, and demand ransoms.

cloud security incidents3 weeks ago4 min

ShinyHunters Exploits PeopleSoft Zero-Day to Steal 454,600 Student Records from Nottingham’s Global Campuses

Over 450,000 Nottingham students had their records stolen because of a PeopleSoft exploit chain. Here is how legacy integrations create massive blind spots for enterprise cloud defense.

ai policy ethics3 weeks ago5 min

Beating the 38-Hour Exploit Window: The Fatal Risk of Lagging Vulnerability Metrics

With the median time to exploitation dropping to just 1.6 days, traditional database-driven vulnerability alerts are no longer fast enough. This article outlines why organizations must shift away from slow public registries toward real-time telemetry and automated asset inventory matching.

ai cyber threats nation state phishing3 weeks ago5 min

Analyzing the Tri-CVE Chain Permitting Full Administrative Hijacks on Ubiquiti Management Controllers

A detailed security analysis of the high-impact three-vulnerability exploit chain (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) affecting Ubiquiti UniFi OS Server, detailing how Nginx gateway routing mismatches enable unauthenticated remote code execution, active KEV exploitation trends, and mandatory post-compromise cleanup.

vulnerability patch management3 weeks ago5 min

Seven Critical ColdFusion and Campaign Flaws Patched as Adobe Accelerates Release Cycles

Adobe has released security updates addressing multiple maximum-severity vulnerabilities in ColdFusion and Campaign Classic platforms, with high risks of exploitation, urging swift mitigation.

ai national securityJun 30, 20265 min

Beyond the Noise: Unpacking the HTTP/2 Bomb Vulnerability

A closer look at the high-severity CVE-2026-49975 flaw, its impact on large-scale web architecture, and the urgent need for consistent patching across vulnerable server environments.

cloud security incidentsJun 26, 20264 min

Active Attacks Target Critical SSRF Vulnerability in Cisco Unified Communications Manager

Threat actors are actively leveraging a newly disclosed server-side request forgery (SSRF) flaw, CVE-2026-20230, in Cisco's Unified Communications Manager. This high-severity issue, which permits arbitrary file-write operations, is currently being used for reconnaissance, with concerns for potential remote code execution and root privilege escalation.

vulnerability patch managementJun 24, 20267 min

Emergency Security Patch Addresses Low-Privilege Remote Code Execution in SharePoint Server

Microsoft released an emergency out-of-band security fix for CVE-2026-45659, a critical remote code execution (RCE) vulnerability in on-premises SharePoint Server. CISA has now added it to the KEV catalog as actively exploited, ordering federal agencies to patch by Saturday under BOD 26-04. Shadowserver tracks over 10,000 exposed SharePoint servers online with no confirmed patch coverage.

cybersecurityJun 18, 20266 min

AI Accelerates Vulnerability Discovery: Record 206 CVEs on Patch Tuesday Signal New Normal

Artificial intelligence is transforming the cybersecurity landscape by dramatically accelerating the speed and scale of vulnerability discovery, as evidenced by Microsoft's June 2026 Patch Tuesday which addressed a record-breaking 206 vulnerabilities. This unprecedented volume signals that voluminous patch updates could soon become the norm.

ai agent security safetyJun 16, 20265 min

Copilot SearchLeak Attack: A Critical Three-Stage Vulnerability Patched

A critical three-stage attack exploiting Microsoft 365 Copilot's search functionality allowed 1-click data theft. Learn how the SearchLeak vulnerability worked and what defenders need to know about this new wave of AI prompt-injection issues.