18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCEThe Hacker News·May 21, 07:24 UTC · May 21, 2026VulnerabilityCVE-2026-42945CVE-2026-42946CVE-2026-40701+1 CVEs60
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code ExecutionThe Hacker News·Jun 22, 05:37 UTC · Jun 22, 2026Vulnerability in the wildCVE-2026-42530CVE-2026-42055CVE-2026-4294560
Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945)Help Net Security·May 18, 00:00 UTC · May 18, 2026VulnerabilityCVE-2026-4294560
Critical Ingress NGINX Controller Vulnerability Allows RCE Without AuthenticationThe Hacker News·Apr 10, 06:49 UTC · Apr 10, 2025VulnerabilityCVE-2025-24513CVE-2025-24514CVE-2025-1097+2 CVEs60
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
Ingress-nginx vulnerabilities can lead to Kubernetes cluster takeoverHelp Net Security·Mar 25, 00:00 UTC · Mar 25, 2025VulnerabilityCVE-2025-1097CVE-2025-1098CVE-2025-24514+2 CVEs60
F5 Patches Critical NGINX Vulnerabilities Enabling Unauthenticated Code ExecutionSecurity Affairs·Jun 18, 14:07 UTC · Jun 18, 2026VulnerabilityCVE-2026-42530CVE-2026-42055CVE-2026-11311+1 CVEs60
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionThe Hacker News·Jul 28, 17:22 UTC · Jul 28, 2026Vulnerability in the wildCVE-2026-42533CVE-2026-42945CVE-2026-9256160
CVE-2026-33032: severe nginx-ui bug grants unauthenticated server accessSecurity Affairs·Apr 15, 18:17 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-3303260
CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server TakeoversSecurity Affairs·Jul 20, 09:50 UTC · Jul 20, 2026VulnerabilityCVE-2026-4253360
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
IngressNightmare: Four Critical Bugs Found in 40% of Cloud SystemsInfosecurity Magazine·Mar 25, 09:30 UTC · Mar 25, 2025VulnerabilityCVE-2025-1097CVE-2025-1098CVE-2025-24514+1 CVEs60
PHP RCE flaw actively exploited to pop NGINX serversHelp Net Security·Oct 28, 00:00 UTC · Oct 28, 2019Vulnerability in the wildCVE-2019-1104360
CVE-2019-11043 exposes Web servers using nginx and PHPSecurity Affairs·Oct 26, 15:10 UTC · Oct 26, 2019Vulnerability in the wildCVE-2019-11043160
QNAP warns of a PHP flaw that could lead to remote code executionSecurity Affairs·Jun 23, 10:48 UTC · Jun 23, 2022VulnerabilityCVE-2019-1104360
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersThe Hacker News·Jul 10, 11:47 UTC · Jul 10, 2026Vulnerability in the wildCVE-2026-4253060
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News·May 7, 17:58 UTC · May 7, 2026Vulnerability in the wildCVE-2026-030060
Critical PHP Vulnerability Exposes QNAP NAS Devices to Remote AttacksThe Hacker News·Jun 23, 06:36 UTC · Jun 23, 2022VulnerabilityCVE-2019-1104360
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
Palo Alto Networks warns that CVE-2025-0111 flaw is actively exploited in attacksSecurity Affairs·Feb 20, 06:32 UTC · Feb 20, 2025Vulnerability in the wildCVE-2025-0111CVE-2025-0108CVE-2024-947460
CISA urges to fix multiple critical flaws in Juniper Networks productsSecurity Affairs·Jul 16, 14:16 UTC · Jul 16, 2022VulnerabilityCVE-2021-23017CVE-2014-504460
Top 15 Vulnerabilities Attackers Exploited Millions of Times to Hack Linux SystemsThe Hacker News·Aug 23, 13:27 UTC · Aug 23, 2021Vulnerability in the wildCVE-2017-5638CVE-2017-9805CVE-2018-7600+12 CVEs60
What the AI patch gap means for enterprise securityHelp Net Security·Jul 2, 00:00 UTC · Jul 2, 2026Vulnerability in the wild160
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistantKaspersky Securelist·May 29, 07:00 UTC · May 29, 2026VulnerabilityCVE-2025-55182CVE-2023-4911CVE-2021-4034+3 CVEs60
Unpublished security flaws (0days) massively exploitedSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Found defunct.dat on your site? You've got a problem.Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account TakeoverThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wild60
Roundcube RCE: Dark web activity signals imminent attacks (CVE-2025-49113)Help Net Security·Feb 23, 10:54 UTC · Feb 23, 2026Vulnerability in the wildCVE-2025-49113CVE-2024-42009CVE-2025-6846160
Palo Alto Networks Patches Authentication Bypass Exploit in PANThe Hacker News·Feb 18, 06:46 UTC · Feb 18, 2025Vulnerability in the wildCVE-2025-0108CVE-2025-0109CVE-2025-0110+1 CVEs60
Vulnerability in popular ‘libwebp’ code more widespread than expectedThe Record·Sep 27, 18:08 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-4863CVE-2023-5129CVE-2023-4106460
Watch out! CVE-2023-5129 in libwebp library affects millions appsSecurity Affairs·Sep 27, 13:35 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-5129CVE-2023-4863CVE-2023-41064+1 CVEs160
Juniper Releases Patches for Critical Flaws in Junos OS and Contrail NetworkingThe Hacker News·Jul 19, 01:28 UTC · Jul 19, 2022VulnerabilityCVE-2021-2301760
Demystifying Kubernetes CVE-2018Palo Alto Unit 42·Jan 28, 20:53 UTC · Jan 28, 2022VulnerabilityCVE-2018-100210560
“Bash” (CVE-2014-6271) vulnerabilityKaspersky Securelist·Sep 25, 14:45 UTC · Sep 25, 2014Vulnerability in the wildCVE-2014-627160