CISA has added three critical Linux kernel vulnerabilities with active exploit evidence to its Known Exploited Vulnerabilities catalog, including a severe TLS receive path flaw scored 9.8.
CISA has identified two Linux Kernel vulnerabilities, CVE-2025-39964 and CVE-2026-53266, as actively exploited and added them to its Known Exploited Vulnerabilities Catalog, urging high-priority remediation.
Gyazo confirmed a data breach after a server vulnerability was exploited to steal 23.6 million user records, underscoring risks in platform security.
Multiple critical vulnerabilities with CVSS scores up to 9.9 impact Hitachi Energy's FACTS Control Platform, risking confidentiality, integrity, and availability in energy sector control systems.
Attackers exploit chained critical vulnerabilities in JFrog Artifactory to bypass authentication, gain admin access, and deploy Rust-based backdoors on self-hosted servers.
A Russian-speaking threat actor used hundreds of AI agents to exploit vulnerabilities in PaperCut NG/MF servers, compromising 395 organizations worldwide and highlighting the operational risks of AI-driven cyberattacks.
CISA has listed two critical actively exploited MikroTik RouterOS vulnerabilities in its Known Exploited Vulnerabilities Catalog, highlighting the need for prioritized remediation.
Two patched vulnerabilities in Cisco Secure Firewall Management Center are actively exploited by ransomware gangs and state-sponsored hackers, threatening critical network security infrastructure.
Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities including two actively exploited zero-day flaws.
N-able has released an emergency hotfix for a critical remote code execution vulnerability in its N-central RMM platform that is actively exploited.
CISA has added CVE-2026-85046, a type confusion vulnerability in Google Chromium V8, to its Known Exploited Vulnerabilities Catalog due to active exploitation, requiring urgent attention for remediation.
CISA added CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities Catalog after active exploitation was observed.
CISA has included two actively exploited TrueConf Server vulnerabilities in its Known Exploited Vulnerabilities Catalog, emphasizing critical risks to federal agencies and beyond.
CISA added the actively exploited Ray-Project code injection vulnerability CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, highlighting urgent remediation needs.
Threat actors are exploiting the critical directory traversal vulnerability CVE-2026-59310 in VMware vCenter, enabling remote code execution and requiring immediate attention from defenders.
Microsoft's August 2026 Patch Tuesday addresses 400 security flaws, including one actively exploited zero-day and two publicly disclosed zero-day vulnerabilities.
CISA has added CVE-2026-8037, a critical Progress LoadMaster command injection vulnerability actively exploited in the wild, to its Known Exploited Vulnerabilities Catalog, requiring prioritized remediation by federal agencies under BOD 26-04.
CISA added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities Catalog due to active exploitation, prioritizing federal agency remediation under BOD 26-04.
A zero-day remote code execution vulnerability in the FastJson Java library is actively exploited by hackers against US organizations, posing a critical threat to enterprise applications.
CISA has added CVE-2026-16232 and CVE-2026-50522 to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation targeting Check Point SmartConsole and Microsoft SharePoint.
Microsoft released its largest Patch Tuesday, addressing 622 security flaws including two actively exploited zero-day vulnerabilities, critical for millions of affected systems.