F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code ExecutionThe Hacker News·Jun 22, 05:37 UTC · Jun 22, 2026Vulnerability in the wildCVE-2026-42530CVE-2026-42055CVE-2026-4294560
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-33032CVE-2026-27944CVE-2026-27825+1 CVEs60
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionThe Hacker News·Jul 28, 17:22 UTC · Jul 28, 2026Vulnerability in the wildCVE-2026-42533CVE-2026-42945CVE-2026-9256160
CVE-2026-33032: severe nginx-ui bug grants unauthenticated server accessSecurity Affairs·Apr 15, 18:17 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-3303260
Malicious NGINX Configurations Enable LargeThe Hacker News·Feb 6, 11:32 UTC · Feb 6, 2026Vulnerability in the wildCVE-2025-55182160
PHP RCE flaw actively exploited to pop NGINX serversHelp Net Security·Oct 28, 00:00 UTC · Oct 28, 2019Vulnerability in the wildCVE-2019-1104360
CVE-2019-11043 exposes Web servers using nginx and PHPSecurity Affairs·Oct 26, 15:10 UTC · Oct 26, 2019Vulnerability in the wildCVE-2019-11043160
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ServersThe Hacker News·Jul 10, 11:47 UTC · Jul 10, 2026Vulnerability in the wildCVE-2026-4253060
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
PAN-OS RCE Exploit Under Active Use Enabling Root Access and EspionageThe Hacker News·May 7, 17:58 UTC · May 7, 2026Vulnerability in the wildCVE-2026-030060
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0The Hacker News·Jul 21, 04:34 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-63030CVE-2026-60137CVE-2026-15409+26 CVEs160
Palo Alto Networks warns that CVE-2025-0111 flaw is actively exploited in attacksSecurity Affairs·Feb 20, 06:32 UTC · Feb 20, 2025Vulnerability in the wildCVE-2025-0111CVE-2025-0108CVE-2024-947460
Top 15 Vulnerabilities Attackers Exploited Millions of Times to Hack Linux SystemsThe Hacker News·Aug 23, 13:27 UTC · Aug 23, 2021Vulnerability in the wildCVE-2017-5638CVE-2017-9805CVE-2018-7600+12 CVEs60
What the AI patch gap means for enterprise securityHelp Net Security·Jul 2, 00:00 UTC · Jul 2, 2026Vulnerability in the wild160
Unpublished security flaws (0days) massively exploitedSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Found defunct.dat on your site? You've got a problem.Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account TakeoverThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wild60
Roundcube RCE: Dark web activity signals imminent attacks (CVE-2025-49113)Help Net Security·Feb 23, 10:54 UTC · Feb 23, 2026Vulnerability in the wildCVE-2025-49113CVE-2024-42009CVE-2025-6846160
Palo Alto Networks Patches Authentication Bypass Exploit in PANThe Hacker News·Feb 18, 06:46 UTC · Feb 18, 2025Vulnerability in the wildCVE-2025-0108CVE-2025-0109CVE-2025-0110+1 CVEs60
Vulnerability in popular ‘libwebp’ code more widespread than expectedThe Record·Sep 27, 18:08 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-4863CVE-2023-5129CVE-2023-4106460
Watch out! CVE-2023-5129 in libwebp library affects millions appsSecurity Affairs·Sep 27, 13:35 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-5129CVE-2023-4863CVE-2023-41064+1 CVEs160
“Bash” (CVE-2014-6271) vulnerabilityKaspersky Securelist·Sep 25, 14:45 UTC · Sep 25, 2014Vulnerability in the wildCVE-2014-627160