February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from JanuaryRecorded Future·Mar 13, 00:00 UTC · Mar 13, 2026Vulnerability in the wildCVE-2025-15556CVE-2026-21513CVE-2026-21533+4 CVEs160
Bug in widely used VoIP phones allows stealthy network footholds, call interception (CVE-2026-2329)Help Net Security·Feb 19, 00:00 UTC · Feb 19, 2026VulnerabilityCVE-2026-232960
Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164)Help Net Security·Jan 16, 12:58 UTC · Jan 16, 2026Vulnerability in the wildCVE-2025-3716460
Vulnerability landscape analysis for Q2 2025Kaspersky Securelist·Aug 27, 10:00 UTC · Aug 27, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Critical flaw in Zyxel firewalls grants access to corporate networks (CVE-2022-30525)Help Net Security·May 16, 10:05 UTC · May 16, 2022Vulnerability in the wildCVE-2022-3052560
NSA urges Windows Users and admins to Patch BlueKeep flawSecurity Affairs·Jun 5, 14:10 UTC · Jun 5, 2019VulnerabilityCVE-2019-070860
CVE-2017-7494 Samba vulnerability, patch your installation now!Security Affairs·Jul 18, 21:48 UTC · Jul 18, 2017VulnerabilityCVE-2017-749460
Microsoft In-The-Wild Coverage - CVE-2012-1889 and CVE-2012Cisco Talos·Jun 21, 20:18 UTC · Jun 21, 2012Vulnerability in the wildCVE-2012-1889CVE-2012-187560
PHP-CGI vulnerabilityCisco Talos·May 8, 19:44 UTC · May 8, 2012Vulnerability in the wildCVE-2012-182360
200 new CVEs a day and no realistic way to patch them allHelp Net Security·Aug 4, 11:25 UTC · Aug 4, 2026Vulnerability in the wildCVE-2026-2508960
The vulnerability landscape in Q1 2026Kaspersky Securelist·May 7, 08:42 UTC · May 7, 2026VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+10 CVEs60
Notepad++ patches flaw used to hijack update systemSecurity Affairs·Feb 18, 19:28 UTC · Feb 18, 2026VulnerabilityCVE-2026-25926160
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code ExecutionThe Hacker News·Feb 18, 16:35 UTC · Feb 18, 2026VulnerabilityCVE-2026-232960
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilienceHelp Net Security·Feb 15, 00:00 UTC · Feb 15, 2026Vulnerability in the wildCVE-2026-1731CVE-2024-12356CVE-2026-1281+2 CVEs60
ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ StoriesThe Hacker News·Feb 5, 17:14 UTC · Feb 5, 2026Vulnerability in the wild160
⚡ Weekly Recap: Drift Breach Chaos, Zero-Days Active, Patch Warnings, Smarter Threats & MoreThe Hacker News·Dec 6, 11:14 UTC · Dec 6, 2025Vulnerability in the wildCVE-2025-53690CVE-2025-38352CVE-2025-48543+25 CVEs160
Analyzing the vulnerability landscape in Q3 2025Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Critical Next.js auth bypass vulnerability opens web apps to compromise (CVE-2025-29927)Help Net Security·Apr 2, 08:44 UTC · Apr 2, 2025Vulnerability in the wildCVE-2025-2992760
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access ToolsThe Hacker News·Dec 20, 06:30 UTC · Dec 20, 2024VulnerabilityCVE-2023-4878860
Malicious Actors Exploit ProjectSend Critical VulnerabilityInfosecurity Magazine·Nov 28, 13:00 UTC · Nov 28, 2024VulnerabilityCVE-2024-1168060
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, CrossPalo Alto Unit 42·Jun 5, 20:05 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-22954CVE-2022-22963CVE-2022-22965+20 CVEs60
NVD Leaves Exploited Vulnerabilities UncheckedInfosecurity Magazine·May 23, 14:00 UTC · May 23, 2024Vulnerability in the wild60
Prevent and detect Adobe ColdFusion exploitation (CVE-2023-26360, CVE-2023-26359)Help Net Security·Dec 6, 09:33 UTC · Dec 6, 2023Vulnerability in the wildCVE-2023-26360CVE-2023-26359CVE-2023-2636160
June Patch Tuesday forecast: Apply updates before BlueKeep hits the streetsHelp Net Security·Nov 15, 07:58 UTC · Nov 15, 2023VulnerabilityCVE-2019-070860
Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)Help Net Security·Sep 23, 00:00 UTC · Sep 23, 2022Vulnerability in the wildCVE-2022-3540560
Patch critical flaw in Atlassian Bitbucket Server and Data Center! (CVE-2022-36804)Help Net Security·Sep 21, 09:09 UTC · Sep 21, 2022VulnerabilityCVE-2022-3680460
Week in review: F5 BIG-IP RCE exploitation, URL spoofing flaws in Zoom, Google DocsHelp Net Security·May 15, 00:00 UTC · May 15, 2022Vulnerability in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+2 CVEs60
April Records First Patch Tuesday of 2022 to Top 100 CVEsInfosecurity Magazine·Apr 13, 09:00 UTC · Apr 13, 2022Vulnerability in the wildCVE-2022-24521CVE-2022-26904CVE-2022-24491+1 CVEs160
Tens of thousands unpatched GitLab servers under attack via CVE-2021-22205Help Net Security·Nov 4, 00:00 UTC · Nov 4, 2021Vulnerability in the wildCVE-2021-2220560
Attackers are bypassing F5 BIG-IP RCE mitigation - you might want to patch after allHelp Net Security·Jul 8, 00:00 UTC · Jul 8, 2020Vulnerability in the wildCVE-2020-590260
Cyber Command backs 'urgent' patch for F5 security vulnerabilityCyberScoop·Jul 6, 17:12 UTC · Jul 6, 2020Vulnerability in the wildCVE-2020-590260
If you haven't yet patched the BlueKeep RDP vulnerability, do so nowHelp Net Security·Jun 7, 11:33 UTC · Jun 7, 2019VulnerabilityCVE-2019-070860
Critical Samba code execution hole plugged, patch ASAP!Help Net Security·Oct 15, 09:22 UTC · Oct 15, 2018VulnerabilityCVE-2017-749460
Crooks included the code for CVE-2018-8174 IE ZeroSecurity Affairs·Jun 3, 07:32 UTC · Jun 3, 2018Vulnerability in the wildCVE-2018-8174CVE-2016-018960
Oracle releases security patches for Apache Struts CVE-2017Security Affairs·Sep 26, 06:34 UTC · Sep 26, 2017Vulnerability in the wildCVE-2017-9805CVE-2017-7672CVE-2017-9787+5 CVEs60
Software vulnerabilities used to spread WannaCry are favorites for hackers, FireEye saysCyberScoop·Jun 2, 20:05 UTC · Jun 2, 2017Vulnerability in the wild60
The CVE-2017-5638 Apache Struts 2 command execution flaw affects Cisco productsSecurity Affairs·Mar 13, 11:55 UTC · Mar 13, 2017Vulnerability in the wildCVE-2017-563860
Patch Apache Struts 2 Now! Hackers are exploiting a remote code execution zeroSecurity Affairs·Mar 13, 11:06 UTC · Mar 13, 2017Vulnerability in the wildCVE-2017-563860
Attackers are exploiting a recently patched highSecurity Affairs·Oct 13, 13:59 UTC · Oct 13, 2016VulnerabilityCVE-2016-277660