U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 4, 10:26 UTC · May 4, 2026Exploit / PoC in the wildCVE-2026-3143160
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Microsoft Fixes 114 Windows Flaws in January 2026 Patch, One Actively ExploitedThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Vulnerability in the wildCVE-2025-65046CVE-2026-0628CVE-2026-20805+5 CVEs160
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and MoreThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability in the wildCVE-2026-27681CVE-2026-34621CVE-2026-34619+7 CVEs60
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever ShippedThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-24990CVE-2025-59230CVE-2025-47827+5 CVEs160
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
Nearly every Linux system built since 2017 vulnerable to ‘Copy Fail’ flawThe Record·May 1, 12:17 UTC · May 1, 2026Exploit / PoC in the wildCVE-2026-3143160
Microsoft Fixes 80 Flaws — Including SMB PrivEsc and Azure CVSS 10.0 BugsThe Hacker News·Sep 11, 08:56 UTC · Sep 11, 2025Vulnerability in the wildCVE-2025-53791CVE-2025-55234CVE-2025-54914+9 CVEs60
Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL ServerThe Hacker News·Jul 10, 07:02 UTC · Jul 10, 2025Vulnerability in the wildCVE-2025-49719CVE-2025-47981CVE-2025-49735+9 CVEs60
Meta Warns of FreeType Vulnerability (CVE-2025The Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Vulnerability in the wildCVE-2025-2736360
Meta warns of actively exploited flaw in FreeType librarySecurity Affairs·Mar 13, 11:02 UTC · Mar 13, 2025Exploit / PoC in the wildCVE-2025-2736360
Urgent: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux DistrosThe Hacker News·Apr 2, 04:39 UTC · Apr 2, 2024Malware in the wildCVE-2024-309460
Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active ExploitationThe Hacker News·Feb 12, 10:28 UTC · Feb 12, 2025Vulnerability in the wildCVE-2025-21391CVE-2025-21418CVE-2024-38193+4 CVEs60
Microsoft Fixes 78 Flaws, 5 Zero-Days Exploited; CVSS 10 Bug Impacts Azure DevOps ServerThe Hacker News·May 15, 00:00 UTC · May 15, 2025Vulnerability in the wildCVE-2025-30397CVE-2025-30400CVE-2025-32701+10 CVEs160
3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security UpdateThe Hacker News·Jan 21, 15:30 UTC · Jan 21, 2025Exploit / PoC in the wildCVE-2024-7344CVE-2025-21333CVE-2025-21334+13 CVEs60
Microsoft Patches 125 Flaws Including Actively Exploited Windows CLFS VulnerabilityThe Hacker News·Apr 10, 06:48 UTC · Apr 10, 2025Vulnerability in the wildCVE-2025-29824CVE-2022-24521CVE-2022-37969+15 CVEs60
Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the WildThe Hacker News·Oct 9, 12:48 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+7 CVEs60
Microsoft Patches 67 Vulnerabilities Including WEBDAV ZeroThe Hacker News·Jun 12, 15:47 UTC · Jun 12, 2025Vulnerability in the wildCVE-2025-33053CVE-2025-47966CVE-2025-32713+3 CVEs160
URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited ZeroThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Vulnerability in the wildCVE-2025-26643CVE-2025-24983CVE-2025-24984+5 CVEs160
Microsoft's July Update Patches 143 Flaws, Including Two Actively ExploitedThe Hacker News·Jul 11, 09:02 UTC · Jul 11, 2024Vulnerability in the wildCVE-2024-38080CVE-2024-38112CVE-2024-37985+3 CVEs60
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs60
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-31431CVE-2022-27666CVE-2026-43284+1 CVEs60
Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS VulnerabilityThe Hacker News·Dec 11, 15:01 UTC · Dec 11, 2024Vulnerability in the wildCVE-2024-49138CVE-2022-24521CVE-2022-37969+6 CVEs60
Microsoft Issues Patches for 79 Flaws, Including 3 Actively Exploited Windows FlawsThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2024Vulnerability in the wildCVE-2024-38014CVE-2024-38217CVE-2024-38226+3 CVEs60
Microsoft Issues Patches for 90 Flaws, Including 10 Critical ZeroThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2024Vulnerability in the wildCVE-2024-38189CVE-2024-38178CVE-2024-38193+13 CVEs160
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-4630060
Dirty Frag: Unpatched Linux vulnerability delivers root accessHelp Net Security·May 11, 09:48 UTC · May 11, 2026Vulnerability in the wildCVE-2026-43284CVE-2026-43500CVE-2026-3143160
Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)Help Net Security·May 11, 11:22 UTC · May 11, 2026Vulnerability in the wildCVE-2026-3143160
DirtyDecrypt: PoC Released for yet another Linux flawSecurity Affairs·May 20, 07:36 UTC · May 20, 2026Exploit / PoC in the wildCVE-2026-31635CVE-2026-31431CVE-2026-43284+4 CVEs60
Incomplete disclosures by Apple and Google create “huge blindspot” for 0Ars Technica · Security·Sep 21, 22:19 UTC · Sep 21, 2023Exploit / PoC in the wildCVE-2023-41064CVE-2023-486360
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-YearThe Hacker News·Apr 17, 14:47 UTC · Apr 17, 2026Ransomware in the wildCVE-2026-33825CVE-2009-0238160
Tech giants launch AI-powered ‘Project Glasswing’ to identify critical software vulnerabilitiesCyberScoop·Apr 7, 19:35 UTC · Apr 7, 2026Vulnerability in the wild60
Firefox Releases Critical Patch Update to Stop Ongoing ZeroThe Hacker News·Jun 21, 09:12 UTC · Jun 21, 2019Vulnerability in the wildCVE-2019-1170760
Anthropic expanding access to Project GlasswingCyberScoop·Jun 3, 13:24 UTC · Jun 3, 2026Exploit / PoC in the wild60
White House hosts open-source software security summit in light of expansive Log4j flawCyberScoop·Jan 13, 14:08 UTC · Jan 13, 2022Exploit / PoC in the wild60
Hackers Exploit Pandoc CVE-2025-51591 to Target AWS IMDS and Steal EC2 IAM CredentialsThe Hacker News·Sep 25, 17:16 UTC · Sep 25, 2025Vulnerability in the wildCVE-2025-51591CVE-2021-2131160
Meet 'Meltdown' and 'Spectre,' the chip flaws causing problems for nearly everyoneCyberScoop·Jan 3, 22:52 UTC · Jan 3, 2018Exploit / PoC in the wildCVE-2017-5753CVE-2017-5717CVE-2017-575460
Threat AdvisoryCisco Talos·Dec 19, 16:50 UTC · Dec 19, 2025Advisory in the wildCVE-2026-20182CVE-2025-20333CVE-2025-20362+6 CVEs160
China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosureSecurity Affairs·May 26, 11:31 UTC · May 26, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860