Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)Help Net Security·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-20182CVE-2026-20127CVE-2022-20775+6 CVEs60
A critical Palo Alto PAN-OS zeroCyberScoop·May 6, 19:48 UTC · May 6, 2026Exploit / PoC in the wildCVE-2026-030060
PoC exploit for abused PaperCut flaw is now public (CVE-2023-27350)Help Net Security·Apr 23, 13:48 UTC · Apr 23, 2026Exploit / PoCCVE-2023-27350CVE-2023-2735160
U.S. CISA adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 21, 09:21 UTC · Apr 21, 2026Exploit / PoC in the wildCVE-2026-20133CVE-2023-27351CVE-2024-27199+5 CVEs60
U.S. CISA adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 6, 08:42 UTC · Mar 6, 2026Exploit / PoC in the wildCVE-2023-43000CVE-2017-7921CVE-2021-22681+2 CVEs60
ClawJacked flaw exposed OpenClaw users to data theftSecurity Affairs·Mar 2, 09:42 UTC · Mar 2, 2026Exploit / PoC60
U.S. CISA adds Cisco SD-WAN flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 26, 15:04 UTC · Feb 26, 2026Exploit / PoC in the wildCVE-2022-20775CVE-2026-2012760
Global Cyber Agencies Urge Immediate Patching of Cisco SDInfosecurity Magazine·Feb 26, 09:30 UTC · Feb 26, 2026Exploit / PoCCVE-2026-20127CVE-2022-2077560
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Attackers exploit BeyondTrust CVE-2026Security Affairs·Feb 13, 15:19 UTC · Feb 13, 2026Exploit / PoC in the wildCVE-2026-173160
Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858)Help Net Security·Jan 28, 00:00 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin AccessThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wildCVE-2026-2355060
Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 releasedHelp Net Security·Dec 21, 00:00 UTC · Dec 21, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-40602CVE-2025-14174+1 CVEs160
Hewlett Packard Enterprise (HPE) fixed maximum severity OneView flawSecurity Affairs·Dec 18, 21:11 UTC · Dec 18, 2025Exploit / PoCCVE-2025-37164CVE-2025-3709360
NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs·Aug 28, 10:48 UTC · Aug 28, 2025Exploit / PoCCVE-2024-21887CVE-2023-46805CVE-2024-3400+3 CVEs160
Wiz Uncovers Critical Access Bypass Flaw in AIThe Hacker News·Jul 30, 07:43 UTC · Jul 30, 2025Exploit / PoC in the wild60
ToolShell: Details of CVEs affecting SharePoint serversCisco Talos·Jul 23, 15:32 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News·Jul 22, 03:59 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs60
Critical Golden dMSA Attack in Windows Server 2025 Enables CrossThe Hacker News·Jul 21, 06:31 UTC · Jul 21, 2025Exploit / PoC60
U.S. CISA adds Wing FTP Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 16, 00:01 UTC · Jul 16, 2025Exploit / PoC in the wildCVE-2025-4781260
Yet another SonicWall SMA100 vulnerability exploited in the wild (CVE-2025-32819)Help Net Security·May 8, 00:00 UTC · May 8, 2025Exploit / PoC in the wildCVE-2025-32819CVE-2025-32820CVE-2025-3282160
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active ExploitationThe Hacker News·Apr 8, 15:56 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
U.S. CISA adds Microsoft Windows, Zyxel device flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 12, 08:01 UTC · Feb 12, 2025Exploit / PoC in the wildCVE-2024-40891CVE-2024-40890CVE-2025-21418+1 CVEs60
Attackers exploit a new zeroSecurity Affairs·Feb 11, 23:06 UTC · Feb 11, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2024-55591160
3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security UpdateThe Hacker News·Jan 21, 15:30 UTC · Jan 21, 2025Exploit / PoC in the wildCVE-2024-7344CVE-2025-21333CVE-2025-21334+13 CVEs60
U.S. CISA adds Oracle WebLogic Server and Mitel MiCollab flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 8, 06:58 UTC · Jan 8, 2025Exploit / PoC in the wildCVE-2020-2883CVE-2024-41713CVE-2024-5555060
U.S. CISA adds Palo Alto Expedition, Android, CyberPanel and Nostromo nhttpd bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 7, 22:49 UTC · Nov 7, 2024Exploit / PoC in the wildCVE-2024-43093CVE-2024-51567CVE-2019-16278+2 CVEs60
Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively ExploitedThe Hacker News·Oct 11, 04:51 UTC · Oct 11, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+3 CVEs60
Three new Ivanti CSA zeroSecurity Affairs·Oct 8, 21:26 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixesHelp Net Security·Sep 12, 14:09 UTC · Sep 12, 2024Exploit / PoC in the wildCVE-2024-38217CVE-2024-38226CVE-2024-38014+6 CVEs160
New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code ExecutionThe Hacker News·Aug 9, 05:12 UTC · Aug 9, 2024Exploit / PoC in the wildCVE-2024-38856CVE-2024-36104CVE-2024-32113+1 CVEs60
Researchers warn of a new critical Apache OFBiz flawSecurity Affairs·Aug 5, 16:42 UTC · Aug 5, 2024Exploit / PoC in the wildCVE-2024-38856CVE-2024-32113CVE-2023-5146760
Network Security Trends: November 2021 to January 2022Palo Alto Unit 42·Jun 5, 20:41 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2021-44228CVE-2021-45046CVE-2021-38647+13 CVEs60
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
Hackers Exploit OpenMetadata Flaws to Mine Crypto on KubernetesThe Hacker News·Apr 23, 05:41 UTC · Apr 23, 2024Exploit / PoCCVE-2024-28847CVE-2024-28848CVE-2024-28253+3 CVEs60
Ivanti warns of a new auth bypass flaw in its Connect Secure, Policy Secure, and ZTA gateway devicesSecurity Affairs·Feb 9, 08:17 UTC · Feb 9, 2024Exploit / PoC in the wildCVE-2024-22024CVE-2023-46805CVE-2024-21887+2 CVEs60
Apple debuts new feature to frustrate iPhone thievesHelp Net Security·Jan 23, 00:00 UTC · Jan 23, 2024Exploit / PoC in the wild60
Experts warn of mass exploitation of Ivanti Connect Secure VPN flawsSecurity Affairs·Jan 16, 10:40 UTC · Jan 16, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760
Two zero-day bugs in Ivanti Connect Secure actively exploitedSecurity Affairs·Jan 11, 15:03 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760