September Patch Tuesday forecast: Evaluate third-party updates alongside Microsoft releaseHelp Net Security·Oct 5, 06:34 UTC · Oct 5, 2018Vulnerability in the wildCVE-2018-1177660
Kaspersky Lab report: Evaluating the threat level of software vulnerabilitiesKaspersky Securelist·Feb 1, 14:30 UTC · Feb 1, 2013Vulnerability in the wild160
Broadcom Patches Critical ESXi Vulnerability Enabling Host Code ExecutionSecurity Affairs·Jul 29, 13:02 UTC · Jul 29, 2026Vulnerability in the wildCVE-2026-47876CVE-2026-59309CVE-2026-59310+2 CVEs60
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionThe Hacker News·Jul 28, 17:22 UTC · Jul 28, 2026Vulnerability in the wildCVE-2026-42533CVE-2026-42945CVE-2026-9256160
Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security·May 3, 00:00 UTC · May 3, 2026Vulnerability in the wildCVE-2026-32202CVE-2026-21510CVE-2026-21513+3 CVEs260
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security·Jun 21, 00:00 UTC · Jun 21, 2026Vulnerability in the wildCVE-2026-20262CVE-2026-48558CVE-2026-39813+3 CVEs160
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain ExposedThe Hacker News·Mar 12, 05:18 UTC · Mar 12, 2026Vulnerability in the wildCVE-2025-68613CVE-2026-2757760
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored CredentialsThe Hacker News·Mar 11, 14:51 UTC · Mar 11, 2026Vulnerability in the wildCVE-2026-27577CVE-2026-27493CVE-2026-27495+1 CVEs60
ServiceNow Flaw CVE-2025-3648 Could Lead to Data Exposure via Misconfigured ACLsThe Hacker News·Jul 10, 07:51 UTC · Jul 10, 2025Vulnerability in the wildCVE-2025-3648CVE-2025-1729CVE-2025-4797860
CISA: Patch Critical GeoServer GeoTools Bug NowInfosecurity Magazine·Jul 17, 09:30 UTC · Jul 17, 2024Vulnerability in the wildCVE-2024-3640160
CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools SoftwareThe Hacker News·Jul 17, 05:14 UTC · Jul 17, 2024Vulnerability in the wildCVE-2024-36401CVE-2024-36404CVE-2024-29510160
China hides homegrown hacks from its vulnerability disclosure processCyberScoop·Nov 16, 13:00 UTC · Nov 16, 2017Vulnerability in the wildCVE-2017-0199CVE-2016-10136CVE-2016-1013860
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 CrossThe Hacker News·Aug 5, 14:27 UTC · Aug 5, 2026Vulnerability in the wildCVE-2026-58073CVE-2026-58072CVE-2026-58067+10 CVEs160
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsInfosecurity Magazine·Jul 31, 15:00 UTC · Jul 31, 2026Vulnerability in the wildCVE-2026-33017CVE-2026-21858CVE-2025-68613+5 CVEs60
Public Exploit Released for Patched vBulletin PreThe Hacker News·Jul 27, 14:40 UTC · Jul 27, 2026Vulnerability in the wildCVE-2026-61511CVE-2025-48827CVE-2025-4882860
Lookout identifies exploitable vulnerabilities in mobile appsHelp Net Security·Jul 22, 00:00 UTC · Jul 22, 2026Vulnerability in the wild160
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026Security Affairs·Jul 21, 06:08 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-687560
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logsHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2026Vulnerability in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+2 CVEs60
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App EndpointsThe Hacker News·Jun 30, 15:47 UTC · Jun 30, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes timeHelp Net Security·Jun 19, 12:06 UTC · Jun 19, 2026Vulnerability in the wild60
UK weakens proposed telecoms defenses against Chinese hackers after industry pushbackThe Record·Jun 10, 06:46 UTC · Jun 10, 2026Vulnerability in the wild60
Week in review: Cisco SD-WAN 0-day exploited, Patch Tuesday forecastHelp Net Security·Jun 7, 00:00 UTC · Jun 7, 2026Vulnerability in the wildCVE-2026-0257CVE-2026-41089CVE-2025-48595+1 CVEs60
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior SignalsRecorded Future·May 14, 00:00 UTC · May 14, 2026Vulnerability in the wild60
Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security·May 10, 00:00 UTC · May 10, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-4670CVE-2026-5174+4 CVEs60
Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code executionCyberScoop·Apr 21, 15:43 UTC · Apr 21, 2026Vulnerability in the wild60
Axonius updates Asset Cloud with AI, exposure management, and asset trust standardHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wild60
Attackers Exploit RCE Flaw as 14,000 F5 BIGSecurity Affairs·Apr 6, 13:08 UTC · Apr 6, 2026Vulnerability in the wildCVE-2025-5352160
Protos AI delivers agent-driven threat intelligence without vendor lock-inHelp Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Vulnerability in the wild60
Threat and Vulnerability Management in 2026Recorded Future·Jan 14, 00:00 UTC · Jan 14, 2026Vulnerability in the wild60
Threat Actors Remember the Vulnerabilities We ForgetRecorded Future·Jan 12, 00:00 UTC · Jan 12, 2026Vulnerability in the wildCVE-2004-011360
When Attacks Come Faster Than Patches: Why 2026 Will be the Year of MachineThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Vulnerability in the wild60
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange ServersThe Hacker News·Nov 1, 13:31 UTC · Nov 1, 2025Vulnerability in the wildCVE-2025-59287260
"Perfect" Adobe Experience Manager vulnerability is being exploited (CVE-2025-54253)Help Net Security·Oct 16, 00:00 UTC · Oct 16, 2025Vulnerability in the wildCVE-2025-54253CVE-2025-54254160
Broadcom patches VMware ZeroSecurity Affairs·Sep 30, 14:06 UTC · Sep 30, 2025Vulnerability in the wildCVE-2025-41244CVE-2025-41245CVE-2025-4124660
Sudo local privilege escalation vulnerabilities fixed (CVE-2025-32462, CVE-2025-32463)Help Net Security·Sep 30, 09:28 UTC · Sep 30, 2025Vulnerability in the wildCVE-2025-32462CVE-2025-3246360
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse ConcernsThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Vulnerability in the wild157
2021 Vulnerability LandscapeRecorded Future·Jul 28, 00:00 UTC · Jul 28, 2025Vulnerability in the wildCVE-2021-4422860
Week in review: Microsoft fixes wormable RCE bug on Windows, check for CitrixBleed 2 exploitationHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2025Vulnerability in the wildCVE-2025-47981CVE-2025-49719CVE-2025-5777160
Risk-Based Vulnerability Intelligence Does What CVSS Can’tRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability in the wild60
Mirai botnets exploit Wazuh RCE, Akamai warnedSecurity Affairs·Jun 10, 10:27 UTC · Jun 10, 2025Vulnerability in the wildCVE-2025-24016CVE-2024-3721160