PolyShell flaw exposes Magento and Adobe Commerce to file upload attacksSecurity Affairs·Mar 21, 10:09 UTC · Mar 21, 2026Vulnerability in the wild60
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
A patched Windows attack surface is still exploitableKaspersky Securelist·Mar 14, 10:00 UTC · Mar 14, 2024Vulnerability in the wildCVE-2022-22047CVE-2022-37989CVE-2022-29104+3 CVEs60
Microsoft December 2021 Patch Tuesday fixes an actively exploited zeroSecurity Affairs·Dec 15, 15:08 UTC · Dec 15, 2021Vulnerability in the wildCVE-2021-43890CVE-2021-43240CVE-2021-41333+54 CVEs60
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account TakeoverThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wild60
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesCisco Talos·Jul 15, 14:52 UTC · Jul 15, 2026Vulnerability in the wildCVE-2026-56155CVE-2026-56164CVE-2026-50370+89 CVEs60
Containers on fire: from container escapes to supply chain attacksKaspersky Securelist·Jun 1, 10:00 UTC · Jun 1, 2026Vulnerability in the wildCVE-2019-5736CVE-2022-0492CVE-2024-21626160
Largest Patch Tuesday in 3 months includes 5 critical vulnerabilitiesCisco Talos·Jul 9, 18:10 UTC · Jul 9, 2024Vulnerability in the wildCVE-2024-38023CVE-2024-38060CVE-2024-38074+7 CVEs60
CISA Flags Actively Exploited Gogs Vulnerability With No PatchInfosecurity Magazine·Jan 13, 16:45 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-8110CVE-2024-5594760
Vulnerability Spotlight: Multiple vulnerabilities in Aspose APIsCisco Talos·Aug 20, 09:00 UTC · Aug 20, 2019Vulnerability in the wildCVE-2019-5032CVE-2019-5033CVE-2019-5041+1 CVEs60
Major Vulnerabilities Patched in SonicWall, Palo Alto Expedition, and Aviatrix ControllersThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Vulnerability in the wildCVE-2025-0103CVE-2025-0104CVE-2025-0105+5 CVEs60
Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zeroCisco Talos·May 14, 17:57 UTC · May 14, 2024Vulnerability in the wildCVE-2024-30044CVE-2024-29997CVE-2024-29998+9 CVEs60
Attackers are leveraging Cisco Smart Licensing Utility static admin credentials (CVE-2024-20439)Help Net Security·Apr 3, 00:00 UTC · Apr 3, 2025Vulnerability in the wildCVE-2024-20439CVE-2024-2044060
Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing UtilityThe Hacker News·Apr 3, 03:53 UTC · Apr 3, 2025Vulnerability in the wildCVE-2024-20439CVE-2024-20440CVE-2024-030560
Ivanti fixed a new critical Sentry API authentication bypass flawSecurity Affairs·Aug 22, 06:59 UTC · Aug 22, 2023Vulnerability in the wildCVE-2023-38035CVE-2023-35078CVE-2023-3508160
The Future of Serverless Security in 2025: From Logs to Runtime ProtectionThe Hacker News·Nov 28, 11:30 UTC · Nov 28, 2024Vulnerability in the wild60
Cisco flags ongoing exploitation of two recently patched Catalyst SDSecurity Affairs·Mar 6, 15:14 UTC · Mar 6, 2026Vulnerability in the wildCVE-2026-20128CVE-2026-20122CVE-2026-20127+1 CVEs60
Vulnerability Spotlight: Multiple Simple DirectMedia Layer VulnerabilitiesCisco Talos·Apr 11, 16:15 UTC · Apr 11, 2018Vulnerability in the wildCVE-2018-3837CVE-2018-3838CVE-2018-383960
Vulnerability Spotlight: Simple DirectMedia Layer’s SDL2_ImageCisco Talos·Mar 1, 21:21 UTC · Mar 1, 2018Vulnerability in the wildCVE-2017-12122CVE-2017-14440CVE-2017-14441+4 CVEs60
Vulnerability Spotlight: YAML Parsing Remote Code Execution Vulnerabilities in Ansible Vault and TablibCisco Talos·Sep 14, 14:30 UTC · Sep 14, 2017Vulnerability in the wildCVE-2017-2809CVE-2017-2810160
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Help Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-4681760
Palo Alto Networks firewalls, Expedition under attack (CVE-2024-9463, CVE-2024-9465)Help Net Security·Nov 15, 00:00 UTC · Nov 15, 2024Vulnerability in the wildCVE-2024-9463CVE-2024-9465CVE-2024-9464+1 CVEs60
Vulnerability Spotlight: Multiple vulnerabilities in Aspose PDF APICisco Talos·Sep 17, 14:58 UTC · Sep 17, 2019Vulnerability in the wildCVE-2019-5042CVE-2019-5066CVE-2019-506760
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code ExecutionThe Hacker News·Jan 9, 09:18 UTC · Jan 9, 2026Vulnerability in the wildCVE-2025-5269160
Critical Patches Issued for Cisco Expressway Series, TelePresence VCS ProductsThe Hacker News·Mar 3, 13:33 UTC · Mar 3, 2022Vulnerability in the wildCVE-2022-20754CVE-2022-20755CVE-2022-20665+2 CVEs60
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI FrameworksThe Hacker News·Mar 27, 08:07 UTC · Mar 27, 2026Vulnerability in the wildCVE-2026-34070CVE-2025-68664CVE-2025-67644+2 CVEs160
RCE in popular ThemeREX WordPress Plugin has been actively exploitedSecurity Affairs·Mar 11, 21:27 UTC · Mar 11, 2020Vulnerability in the wild60
Critical CVSS 9.8 Flaw Found in IBM API Connect Authentication SystemThe Hacker News·Jan 1, 05:05 UTC · Jan 1, 2026Vulnerability in the wildCVE-2025-1391560
ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitationArs Technica · Security·Nov 29, 00:38 UTC · Nov 29, 2023Vulnerability in the wildCVE-2023-49103CVE-2023-4966CVE-2023-94105+1 CVEs60
CVE-2026-20262: CISCO Catalyst SD-WAN Flaw Under Active Targeted ExploitationSecurity Affairs·Jun 16, 10:53 UTC · Jun 16, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-20245CVE-2026-20122+5 CVEs60
Ivanti fixed a critical EPM flaw that can result in RCESecurity Affairs·Jan 19, 14:01 UTC · Jan 19, 2024Vulnerability in the wildCVE-2023-39336CVE-2023-35078CVE-2023-35082+1 CVEs60
SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2025-54236160
Experts disclose technical details of now-patched CVE-2022-37969 Windows ZeroSecurity Affairs·Oct 14, 22:30 UTC · Oct 14, 2022Vulnerability in the wildCVE-2022-3796960
Cisco warns of SD-WAN Manager exploitation, fixes 48 firewall vulnerabilitiesHelp Net Security·Mar 5, 00:00 UTC · Mar 5, 2026Vulnerability in the wildCVE-2026-20128CVE-2026-20122CVE-2026-20127+2 CVEs60
Cisco Fixes High-Risk Vulnerability Impacting Unity Connection SoftwareThe Hacker News·Jan 11, 04:55 UTC · Jan 11, 2024Vulnerability in the wildCVE-2024-20272CVE-2024-2028760
Cisco Issues Security Patch Updates for 32 Flaws in its ProductsThe Hacker News·Sep 6, 08:53 UTC · Sep 6, 2018Vulnerability in the wildCVE-2018-11776CVE-2018-0435CVE-2018-042360
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHubThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Vulnerability in the wildCVE-2018-15133CVE-2024-5555660
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances ExposedThe Hacker News·Apr 7, 05:56 UTC · Apr 7, 2026Vulnerability in the wildCVE-2025-59528CVE-2025-8943CVE-2025-2631960
Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer AccountsThe Hacker News·Sep 10, 01:08 UTC · Sep 10, 2025Vulnerability in the wildCVE-2025-54236CVE-2025-5426160