32% Of Top-Exploited Vulnerabilities Are Over A Decade OldHelp Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Vulnerability in the wild157
Vulnerability landscape in Q4 2025Kaspersky Securelist·Mar 6, 10:00 UTC · Mar 6, 2026Vulnerability in the wildCVE-2018-0802CVE-2017-11882CVE-2017-0199+7 CVEs160
Remote Code Execution Discovered in Spotify's BackstageInfosecurity Magazine·Nov 15, 17:00 UTC · Nov 15, 2022Vulnerability in the wild60
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
Memory corruption vulnerability in Mitsubishi PLC could lead to DoS, code executionCisco Talos·May 26, 19:36 UTC · May 26, 2023Vulnerability in the wildCVE-2023-142460
White House releases maritime cybersecurity updateCyberScoop·Jan 5, 18:41 UTC · Jan 5, 2021Vulnerability in the wild60
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra ServersSecurity Affairs·Jul 24, 08:31 UTC · Jul 24, 2026Vulnerability in the wildCVE-2025-6637660
Traps Prevents In-The-Wild VBScript ZeroPalo Alto Unit 42·Sep 7, 12:00 UTC · Sep 7, 2018Vulnerability in the wildCVE-2018-8373CVE-2018-817460
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0The Hacker News·Sep 30, 14:51 UTC · Sep 30, 2025Vulnerability in the wildCVE-2025-1003560
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI MalwareThe Hacker News·Feb 23, 11:00 UTC · Feb 23, 2026Vulnerability in the wildCVE-2026-2441CVE-2026-1731CVE-2026-2070060
Detecting and Preventing Critical ZeroLogon Windows Server VulnerabilityThe Hacker News·Sep 23, 18:09 UTC · Sep 23, 2020Vulnerability in the wildCVE-2020-147260
CISA Issues Emergency Vulnerability WarningInfosecurity Magazine·Jul 17, 18:01 UTC · Jul 17, 2020Vulnerability in the wildCVE-2020-135060
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersThe Hacker News·Jul 10, 11:47 UTC · Jul 10, 2026Vulnerability in the wildCVE-2026-4253060
Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)Help Net Security·Jul 7, 00:00 UTC · Jul 7, 2026Vulnerability in the wildCVE-2026-4828260
Apache Commons Text flaw is not a repeat of Log4Shell (CVE-2022-42889)Help Net Security·Oct 19, 00:00 UTC · Oct 19, 2022Vulnerability in the wildCVE-2022-4288960
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Microsoft (& Apple) Patch Tuesday, April 2023 EditionKrebs on Security·Apr 12, 01:40 UTC · Apr 12, 2023Vulnerability in the wildCVE-2023-28206CVE-2023-28205CVE-2023-28252+4 CVEs60
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
CUPS vulnerabilities could be abused for DDoS attacksHelp Net Security·Oct 9, 08:19 UTC · Oct 9, 2024Vulnerability in the wildCVE-2024-47176CVE-2024-47076CVE-2024-47175+1 CVEs60
Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM CredentialsThe Hacker News·Sep 25, 17:16 UTC · Sep 25, 2025Vulnerability in the wildCVE-2025-51591CVE-2021-2131160
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More StoriesThe Hacker News·Jan 8, 16:52 UTC · Jan 8, 2026Vulnerability in the wildCVE-2024-36401CVE-2007-0671CVE-2002-036760
Vulnerability Spotlight: Buffer overflow vulnerability in AnyCubic Chitubox pluginCisco Talos·Jan 10, 14:40 UTC · Jan 10, 2022Vulnerability in the wildCVE-2021-2194860
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of DisclosureThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-4433860
June 2022 Patch Tuesday forecast: Internet Explorer fades into the sunsetHelp Net Security·Jun 14, 18:58 UTC · Jun 14, 2022Vulnerability in the wildCVE-2022-3019060
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and SecretsSecurity Affairs·Jul 7, 21:16 UTC · Jul 7, 2026Vulnerability in the wildCVE-2026-20896160
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
SolarWinds Web Help Desk Exploited for RCE in MultiThe Hacker News·Mar 7, 07:03 UTC · Mar 7, 2026Vulnerability in the wildCVE-2025-40551CVE-2025-40536CVE-2025-26399+1 CVEs60
Crimeware: A new round of confrontation begins…Kaspersky Securelist·Apr 29, 14:13 UTC · Apr 29, 2010Vulnerability in the wild57
High-Severity Vulnerability Discovered in Popular CMSInfosecurity Magazine·Sep 6, 11:30 UTC · Sep 6, 2023Vulnerability in the wildCVE-2023-2453CVE-2023-448060
A cyber-espionage effort against Tibetan leaders leveraged known Android, iOS vulnerabilitiesCyberScoop·Sep 24, 13:57 UTC · Sep 24, 2019Vulnerability in the wild60
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4681760
Cisco Issues Urgent Fix for ASA and FTD Software Vulnerability Under Active AttackThe Hacker News·Oct 24, 12:41 UTC · Oct 24, 2024Vulnerability in the wildCVE-2024-20481CVE-2024-20412CVE-2024-20424+1 CVEs60
CVE-2019-11043 exposes Web servers using nginx and PHPSecurity Affairs·Oct 26, 15:10 UTC · Oct 26, 2019Vulnerability in the wildCVE-2019-11043160
HTTP/2 CONTINUATION Flood technique can be exploited in DoS attacksSecurity Affairs·Apr 5, 02:41 UTC · Apr 5, 2024Vulnerability in the wildCVE-2024-27983CVE-2024-27919CVE-2024-2758+6 CVEs60
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active ExploitationThe Hacker News·Oct 31, 08:31 UTC · Oct 31, 2025Vulnerability in the wildCVE-2025-59287160
EngageLab SDK flaw opens door to private data on 50M Android devicesSecurity Affairs·Apr 10, 08:41 UTC · Apr 10, 2026Vulnerability in the wild60
Microsoft Patches Windows ZeroInfosecurity Magazine·Jul 13, 18:50 UTC · Jul 13, 2022Vulnerability in the wildCVE-2022-22047CVE-2022-22029CVE-2022-22039+2 CVEs160
BMC vulnerabilities in Supermicro servers allow remote takeover, data exfiltration attacksHelp Net Security·Sep 28, 10:09 UTC · Sep 28, 2023Vulnerability in the wild60
Legacy Windows Protocols Still Expose Networks to Credential TheftInfosecurity Magazine·Oct 14, 16:45 UTC · Oct 14, 2025Vulnerability in the wild60
Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)Help Net Security·Sep 23, 00:00 UTC · Sep 23, 2022Vulnerability in the wildCVE-2022-3540560