Full Disclosure·2h ago highopenEQUELLA authenticated RCE chain(s)#openequella#rce#deserializationVulnerability
Full Disclosure·2h ago high[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)#netsis#sql-injection#rceVulnerability 5 sources1
Full Disclosure·2h ago high[0day-rubbish] Lightstreamer Server 7.4.8 Shipped placeholder JMX/RMI credentials plus MLet remote class loading to root RCE (9.8)#lightstreamer#jmx#rmiVulnerability 2 sources
Full Disclosure·2h ago high[0day-rubbish] FME Flow 2026.2 Zip-Slip arbitrary file write to code execution as LocalSystem (8.8)#fme-flow#safe-software#zip-slipVulnerability
Cyber Security News·2h ago highCitrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks#citrix#netscaler#zero-day in the wild 4 min
The Hacker News·12h ago highShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants#shinyhunters#fbi#oracle-peoplesoft 21 sources in the wild 3 min
The Hacker News·22h ago criticalSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild#sharepoint#mikrotik#routeros 7 sources in the wild 2 min1
Cyber Security News·23h ago criticalHackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code#wordpress#cve-2026-87902#local-file-inclusion 16 sources in the wild 3 min5
oss-security·1d ago highCVE-2026-82384: Apache Roller: Unauthenticated deserialization in the XML-RPC endpoint#apache#apache-roller#deserializationCVE-2026-82384 17 sources
Rapid7 Blog·1d ago highMetasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?#metasploit#gitlab#cve-2026-85706 in the wild 4 min
Cyber Security News·1d ago highCritical GitLab Bugs Let Attackers Execute Code Through Malicious CI/CD Regex#gitlab#rce#ci-cd 2 sources 3 min2
BleepingComputer·1d ago highWordPress Click2Shell flaw lets hackers execute PHP on the server#wordpress#click2shell#csrf 6 sources 3 min
Qualys ThreatPROTECT·1d ago criticalCISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)#check-point#vpn#cisaCVE-2026-85102 15 sources in the wild 2 min
CERT/CC Vulnerability Notes·2d ago highVU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise#viewsonic#vcast#viewboardCVE-2026-82987 2 min
Canadian Centre for Cyber Security·2d ago criticalAL26-023 - Vulnerability Impacting Microsoft SharePoint Server - CVE-2026-65660#sharepoint#microsoft#cve-2026-65660 4 sources in the wild 3 min1
Canadian Centre for Cyber Security·2d ago highWebPros security advisory (AV26-961)#plesk#cpanel#webpros 6 sources
oss-security·2d ago high[OSSA-2026-039] OpenStack Octavia: HAProxy configuration injection leading to remote code execution in Octavia (CVE-2026-94572, CVE-2026-94571)#openstack#octavia#haproxyCVE-2026-94572 3 sources
The Hacker News·2d ago criticalF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers#apm#big-ip#cisa 14 sources in the wild 4 min
WIRED · Security·2d ago highAn OpenAI Agent Hacked Australia's Health Service. Their Government Found Out Months Later.#cve#observability#rce 5 sources 3 min
Datadog Security Labs·3d ago highDiscovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4)#opencode#rce#content-type-confusion 11 min
oss-security·3d agoCVE-2026-96443: Apache Doris: JDBC driver URL validation bypass leads to remote code execution#apache-doris#cve-2026-96443#jdbcCVE-2026-96443 2 sources1
Cyber Security News·3d ago highCritical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems#critical-patch#cve#financial-transaction-manager 3 min1
Cyber Security News·3d ago highCritical NEXT.JS Flaw Allows Remote Code Execution Via Weaponized SVG File#next.js#cve-2026-94545#rce 2 sources 3 min