Magento wish list exploit bypasses WAF protectionSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026VulnerabilityCVE-2022-2408660
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News·May 15, 00:00 UTC · May 15, 2026VulnerabilityCVE-2026-0300160
Active exploitation of Cisco IOS XE Software Web Management User Interface vulnerabilitiesCisco Talos·Oct 16, 15:05 UTC · Oct 16, 2023Vulnerability in the wildCVE-2023-20198CVE-2023-20273CVE-2021-1435160
Week in review: Patched curl and libcurl vulnerability, 15 free M365 security training modulesHelp Net Security·Oct 15, 00:00 UTC · Oct 15, 2023Vulnerability in the wildCVE-2023-43641CVE-2023-36563CVE-2023-41763+3 CVEs60
SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2025-54236260
Attackers deliver ShadowPad via newly patched WSUS RCE bugSecurity Affairs·Nov 24, 12:35 UTC · Nov 24, 2025Vulnerability in the wildCVE-2025-5928760
Threat Brief: CVE-2022Palo Alto Unit 42·Jun 5, 22:35 UTC · Jun 5, 2024Vulnerability in the wildCVE-2022-138860
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from JanuaryRecorded Future·Mar 13, 00:00 UTC · Mar 13, 2026Vulnerability in the wildCVE-2025-15556CVE-2026-21513CVE-2026-21533+4 CVEs160
Vulnerability landscape in Q4 2025Kaspersky Securelist·Mar 6, 10:00 UTC · Mar 6, 2026Vulnerability in the wildCVE-2018-0802CVE-2017-11882CVE-2017-0199+7 CVEs160
Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code ExecutionThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026VulnerabilityCVE-2025-64155CVE-2025-4785560
SharePoint vulnerability with 9.8 severity rating under exploit across globeArs Technica · Security·Jul 21, 19:30 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Hackers Targeting Unpatched Atlassian Confluence Servers to Deploy Crypto MinersThe Hacker News·Sep 22, 06:17 UTC · Sep 22, 2022Vulnerability in the wildCVE-2022-26134CVE-2021-403460
First Patch Tuesday of 2022 Brings Fix for a Critical 'Wormable' Windows VulnerabilityThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2022VulnerabilityCVE-2022-21907CVE-2021-22947CVE-2021-36976+10 CVEs60
Critical RCE vulnerability found in over a million GPON Home RoutersSecurity Affairs·May 8, 08:29 UTC · May 8, 2018VulnerabilityCVE-2018-10561CVE-2018-1056260
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryThe Hacker News·Jul 29, 15:39 UTC · Jul 29, 2026VulnerabilityCVE-2026-59726160
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's ServersThe Hacker News·Jul 24, 11:45 UTC · Jul 24, 2026VulnerabilityCVE-2026-32194CVE-2026-32191CVE-2016-3714160
Snowpick: Open-source ServiceNow exposure scannerHelp Net Security·Jul 22, 00:00 UTC · Jul 22, 2026VulnerabilityCVE-2025-364860
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App EndpointsThe Hacker News·Jun 30, 15:47 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
Gamaredon Uses WinRAR Vulnerability to Launch Modular Spy Campaign on Ukrainian TargetsSecurity Affairs·Jun 4, 10:53 UTC · Jun 4, 2026VulnerabilityCVE-2025-808860
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against UkraineThe Hacker News·Jun 2, 18:21 UTC · Jun 2, 2026VulnerabilityCVE-2025-8088CVE-2026-2150960
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager BackdoorThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-41940160
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of DisclosureThe Hacker News·Apr 24, 05:28 UTC · Apr 24, 2026Vulnerability in the wildCVE-2026-3998760
Magento Security Release APSB25Sansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026VulnerabilityCVE-2023-3821860
Surge in Magento 2 template attacksSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of DisclosureThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA SystemsThe Hacker News·Mar 23, 06:15 UTC · Mar 23, 2026VulnerabilityCVE-2025-3297560
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System AccessThe Hacker News·Nov 30, 09:05 UTC · Nov 30, 2025VulnerabilityCVE-2025-59287160
Product showcase: SecAlerts - Relevant, actionable, up-to-the-minute vulnerability alertsHelp Net Security·Nov 17, 00:00 UTC · Nov 17, 2025Vulnerability in the wild60
Hackers deploy DripDropper via Apache ActiveMQ flaw, patch systems to evade detectionSecurity Affairs·Aug 21, 16:30 UTC · Aug 21, 2025Vulnerability in the wildCVE-2023-4660460
Attackers exploit critical Zimbra vulnerability using cc’d email addressesArs Technica · Security·Oct 2, 21:50 UTC · Oct 2, 2024Vulnerability in the wildCVE-2024-4551960
Alert: Microsoft Releases Patch Updates for 5 New ZeroThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2023Vulnerability in the wildCVE-2023-36025CVE-2023-36033CVE-2023-36036+9 CVEs60
Cisco Warns of Critical Vulnerability in IOS XE SoftwareInfosecurity Magazine·Oct 17, 12:00 UTC · Oct 17, 2023Vulnerability in the wildCVE-2023-2019860
Nearly 12,000 Juniper Firewalls Found Vulnerable to Recently Disclosed RCE VulnerabilityThe Hacker News·Sep 19, 10:29 UTC · Sep 19, 2023Vulnerability in the wildCVE-2023-36845CVE-2023-36844CVE-2023-36846+1 CVEs60
Microsoft fixes OMIGOD bugs in secret Azure appThe Record·Dec 13, 00:00 UTC · Dec 13, 2022VulnerabilityCVE-2021-38647CVE-2021-38648CVE-2021-38645+1 CVEs60
Atlassian Confluence bug CVE-2022-26134 exploited in cryptocurrency mining campaignSecurity Affairs·Sep 22, 11:06 UTC · Sep 22, 2022Vulnerability in the wildCVE-2022-2613460
CISA urges to fix multiple critical flaws in Juniper Networks productsSecurity Affairs·Jul 16, 14:16 UTC · Jul 16, 2022VulnerabilityCVE-2021-23017CVE-2014-504460
Microsoft Issues Out-ofInfosecurity Magazine·Jan 18, 10:03 UTC · Jan 18, 2022VulnerabilityCVE-2022-21839CVE-2022-21919CVE-2022-21836+3 CVEs60
Microsoft Starts 2022 with 97 CVEs in January Patch TuesdayInfosecurity Magazine·Jan 12, 09:36 UTC · Jan 12, 2022Vulnerability in the wildCVE-2022-21839CVE-2022-21919CVE-2022-21836+3 CVEs60
‘Wormable’ Flaw Leads January 2022 Patch TuesdayKrebs on Security·Jan 11, 22:53 UTC · Jan 11, 2022Vulnerability in the wildCVE-2022-21907CVE-2022-21846CVE-2021-22947+2 CVEs60