Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
28 / 358 results
criticalbug_reportVulnerabilityChromaDB FastAPI RCE allows unauthenticated arbitrary code execution
ChromaDB latest Python FastAPI version. Affects exposed ChromaDB servers accessible over the network. No CVE assigned yet.
criticalbug_reportVulnerabilityCritical nginx vulnerabilities enable RCE and rate-limit bypass
nginx web server (specific versions not provided by CERT.BE advisory). Affects organizations running vulnerable nginx instances, particularly those exposed to the internet or untrusted networks.
highbug_reportVulnerabilityPoC released for DirtyDecrypt LPE in Linux kernel (CVE-2026-31635)
Linux kernel - specific vulnerable versions not provided. Local privilege escalation vulnerability affecting systems running vulnerable kernel versions.
highbug_reportVulnerabilityOver 600 malicious npm packages published in Shai-Hulud campaign
npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.
highbug_reportVulnerabilitySonicWall releases patches for multiple high-severity vulnerabilities
SonicWall products (specific models and versions not disclosed in summary). CERT.BE advisory indicates multiple vulnerabilities requiring immediate patching across SonicWall product line.
highbug_reportVulnerabilityMicrosoft sees rise in privilege escalation and identity abuse flaws
Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.
highbug_reportVulnerabilityABB CoreSense path traversal flaw allows unauthenticated system access
ABB CoreSense HM (versions prior to v2.3.4) and CoreSense M10 (versions prior to v1.4.1.31). Path traversal vulnerability affects unauthenticated remote attackers.
criticalbug_reportVulnerabilityScadaBR 1.2.0 critical flaws enable unauthenticated remote code execution
ScadaBR version 1.2.0, a SCADA system used in critical infrastructure sectors including energy, water, and manufacturing worldwide. All four CVEs affect the same version.
criticalbug_reportVulnerabilityZKTeco CCTV cameras expose credentials via unauthenticated config port
ZKTeco CCTV cameras, specifically model SSC335-GC2063-Face-0b77, running firmware versions prior to V5.0.1.2.20260421. Vulnerability affects an undocumented configuration export port that allows unauthenticated access to camera credentials and config…
highbug_reportVulnerabilityKieback & Peter DDC controllers vulnerable to XSS attacks
Kieback & Peter DDC (Direct Digital Control) Building Controllers. Specific affected versions not disclosed in available data.
highbug_reportVulnerabilityBuffer overflow in PAN-OS User-ID portal enables unauthenticated RCE
Palo Alto Networks PAN-OS on PA-Series and VM-Series firewalls; Siemens RUGGEDCOM APE1808 devices. Specific affected PAN-OS versions not provided in summary.
criticalbug_reportVulnerabilityMicrosoft Exchange Server XSS flaw actively exploited for session hijacking
Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.
criticalbug_reportVulnerabilityCritical PAN-OS vulnerabilities enable auth bypass and code execution
Palo Alto Networks PAN-OS (specific versions not provided in summary). Affects authentication controls, code execution surface, and availability.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.
highbug_reportVulnerabilityIvanti releases security updates for multiple products
Multiple Ivanti products affected. Specific product names, versions, and CVE identifiers not disclosed in available information. High severity rating indicates significant security risk.
criticalbug_reportVulnerabilityMultiple critical vulnerabilities in Fortinet products require patching
Fortinet products: FortiSandbox, FortiOS, FortiAP, FortiAnalyzer, and FortiManager. Specific affected versions not provided in advisory. Multiple vulnerabilities ranging from critical to medium severity.
highbug_reportVulnerabilityCode Runner MCP Server missing authentication flaw allows unauthorized access
Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.
highbug_reportVulnerability3onedata GW1101 Modbus gateway vulnerable to OS command injection
3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.
highbug_reportVulnerabilityOrca heat pumps lack authentication, transmit cleartext data to servers
Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.
highbug_reportVulnerabilityMikroTik RouterOS auth bypass via certificate validation flaw
MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.
criticalbug_reportVulnerabilityCisco SD-WAN Manager auth bypass exploited in wild since 2023
Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. Specific affected versions not provided in advisory summary. CVE-2026-20127 allows administrative access compromise.
criticalbug_reportVulnerabilityIvanti EPMM critical RCE flaws under limited exploitation
Ivanti Endpoint Manager Mobile (EPMM) products. Specific affected versions not provided in advisory summary. Two critical vulnerabilities enabling unauthenticated remote code execution.
highbug_reportVulnerabilityFortinet FortiCloud SSO bypass exploited to extract LDAP passwords
Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…
criticalbug_reportVulnerabilityFortinet FortiCloud SSO auth bypass under active exploitation
Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.
criticalbug_reportVulnerabilityCisco Secure Email Gateway critical flaw unpatched, check for compromise
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. Specific affected versions not provided in advisory summary. No patch available as of December 17, 2025.
criticalbug_reportVulnerabilityReact Server Components RCE flaw enables unauthenticated remote execution
React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.
criticalbug_reportVulnerabilityMicrosoft patches critical WSUS RCE flaw with public PoC exploit
Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.
highbug_reportVulnerabilityFortinet patches high severity FortiOS vulnerability
FortiOS (specific versions not disclosed in summary). Fortinet advisory published October 14, 2025.