U.S. CISA adds SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 15, 10:52 UTC · Jul 15, 2026Exploit / PoC in the wildCVE-2026-15409CVE-2026-15410CVE-2026-56155+1 CVEs60
Patch Tuesday security updates for July 2026, the largest update ever. 621 CVEs in one monthSecurity Affairs·Jul 14, 21:33 UTC · Jul 14, 2026Vulnerability in the wildCVE-2026-56155CVE-2026-56164CVE-2026-57092+5 CVEs60
JADEPUFFER: First End-to-End AISecurity Affairs·Jul 3, 11:29 UTC · Jul 3, 2026Ransomware in the wildCVE-2025-3248CVE-2021-2944160
AI Agent Exploits Langflow RCE to Automate Database Ransomware AttackThe Hacker News·Jul 2, 09:13 UTC · Jul 2, 2026Ransomware in the wildCVE-2025-3248CVE-2021-29441160
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of DisclosureThe Hacker News·May 15, 00:00 UTC · May 15, 2026Vulnerability in the wildCVE-2026-4433860
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of DisclosureThe Hacker News·Mar 26, 06:26 UTC · Mar 26, 2026Vulnerability in the wildCVE-2026-33017CVE-2025-3248160
44% Surge in App Exploits as AI Speeds Up CyberInfosecurity Magazine·Feb 25, 14:30 UTC · Feb 25, 2026Ransomware57
U.S. CISA adds SmarterTools SmarterMail and React Native Community CLI flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 6, 09:22 UTC · Feb 6, 2026Exploit / PoC in the wildCVE-2025-11953CVE-2026-2442360
Top 25 Most Dangerous Software Weaknesses of 2025 RevealedInfosecurity Magazine·Dec 15, 10:45 UTC · Dec 15, 2025Data breach in the wild60
U.S. CISA adds an Oracle Fusion Middleware flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:34 UTC · Nov 22, 2025Exploit / PoC in the wildCVE-2025-6175760
ShadowRay 2.0 Exploits Unpatched Ray Flaw to Build SelfThe Hacker News·Nov 21, 06:45 UTC · Nov 21, 2025VulnerabilityCVE-2023-48022160
SAP September 2025 Patch Day fixed 4 critical flawsSecurity Affairs·Sep 9, 20:38 UTC · Sep 9, 2025VulnerabilityCVE-2025-42944CVE-2025-42922CVE-2023-27500+1 CVEs60
CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active ExploitationThe Hacker News·Sep 3, 07:38 UTC · Sep 3, 2025Exploit / PoC in the wildCVE-2020-24363CVE-2025-55177CVE-2025-4330060
Langflow: CVE-2025Recorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-324860
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT FirewallsThe Hacker News·Aug 11, 15:08 UTC · Aug 11, 2025Vulnerability in the wildCVE-2025-3243360
Autoswagger: Open-source tool to expose hidden API authorization flawsHelp Net Security·Jul 24, 00:00 UTC · Jul 24, 2025Vulnerability30
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS AttacksThe Hacker News·Jun 21, 09:10 UTC · Jun 21, 2025Vulnerability in the wildCVE-2025-324860
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities CatalogThe Hacker News·Jun 12, 05:02 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-32433CVE-2024-42009CVE-2025-3102260
U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 10, 13:34 UTC · Jun 10, 2025Exploit / PoC in the wildCVE-2025-32433CVE-2024-4200960
Week in review: The impact of a CVE-free future on cyber defense, Patch Tuesday forecastHelp Net Security·May 11, 00:00 UTC · May 11, 2025Vulnerability in the wildCVE-2025-32819CVE-2025-27363CVE-2025-3248+1 CVEs60
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation EvidenceThe Hacker News·May 8, 13:52 UTC · May 8, 2025Exploit / PoC in the wildCVE-2025-324860
Microsoft Patches Actively Exploited Power Pages Privilege Escalation VulnerabilityThe Hacker News·Feb 22, 05:06 UTC · Feb 22, 2025Vulnerability in the wildCVE-2025-21355CVE-2025-2498960
Microsoft fixed actively exploited flaw in Power PagesSecurity Affairs·Feb 20, 11:20 UTC · Feb 20, 2025Exploit / PoC in the wildCVE-2025-21355CVE-2025-2498960
Pwn2Own Automotive 2025 Day 2: organizers awarded $335,500Security Affairs·Jan 23, 20:48 UTC · Jan 23, 2025Exploit / PoC60
Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active AttacksThe Hacker News·Dec 1, 07:13 UTC · Dec 1, 2024Exploit / PoC in the wildCVE-2024-49035CVE-2024-49038CVE-2024-49052+1 CVEs160
Critical Vulnerabilities Uncovered in Industrial Wireless Access PointInfosecurity Magazine·Nov 28, 11:15 UTC · Nov 28, 2024VulnerabilityCVE-2024-50370CVE-2024-50371CVE-2024-50372+3 CVEs60
CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active AttacksThe Hacker News·Nov 27, 04:06 UTC · Nov 27, 2024Vulnerability in the wildCVE-2023-28461CVE-2023-45727CVE-2023-2799760
More bugs in Palo Alto Expedition see active exploitation, CISA warnsCyberScoop·Nov 15, 16:31 UTC · Nov 15, 2024Advisory in the wildCVE-2024-9463CVE-2024-9465CVE-2024-5910+2 CVEs60
watchTowr Finds New ZeroInfosecurity Magazine·Nov 15, 12:15 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-47575CVE-2024-2311360
Palo Alto Advises Securing PAN-OS Interface Amid Potential RCE Threat ConcernsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Vulnerability in the wildCVE-2024-591060
CISA Warns of Critical Software Vulnerabilities in Industrial DevicesInfosecurity Magazine·Nov 1, 11:45 UTC · Nov 1, 2024VulnerabilityCVE-2024-10386CVE-2024-10387CVE-2023-6943+1 CVEs60
Fortinet warns of active campaign exploiting bug in FortiManager productsCyberScoop·Oct 24, 21:22 UTC · Oct 24, 2024Threat actor in the wildCVE-2024-4757560
Fortinet Confirms Exploitation of Critical FortiManager ZeroInfosecurity Magazine·Oct 24, 11:45 UTC · Oct 24, 2024Exploit / PoC in the wildCVE-2024-47575CVE-2024-2311360
Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilitiesCisco Talos·Oct 8, 19:04 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+10 CVEs60
Critical Unpatched Ray AI Platform Vulnerability Exploited for Cryptocurrency MiningThe Hacker News·Mar 28, 04:46 UTC · Mar 28, 2024Vulnerability in the wildCVE-2023-4802260
Juniper Networks Releases Urgent Junos OS Updates for HighThe Hacker News·Jan 30, 07:40 UTC · Jan 30, 2024Exploit / PoC in the wildCVE-2024-21619CVE-2024-21620CVE-2023-36846+2 CVEs60
What is opening EV charging stations to cyberattacks?Help Net Security·Dec 12, 12:53 UTC · Dec 12, 2023Vulnerability55
Trend Micro Releases Urgent Fix for Actively Exploited Critical Security VulnerabilityThe Hacker News·Oct 9, 06:46 UTC · Oct 9, 2023Vulnerability in the wildCVE-2023-41179CVE-2014-8361CVE-2017-6884+9 CVEs60
Juniper Networks fixes flaws leading to RCE in firewalls and switchesHelp Net Security·Aug 29, 18:24 UTC · Aug 29, 2023Vulnerability in the wildCVE-2023-36844CVE-2023-36845CVE-2023-36846+1 CVEs60