Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 649 results
Active filter:tag: #vulnerability✕ clear
Critical command injection flaw in Fortinet FortiSandbox requires patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical command injection flaw in Fortinet FortiSandbox requires patching

Fortinet FortiSandbox (specific versions not disclosed in available data). Command injection vulnerability allows unauthorized command execution.

Fortinet11 Jun · 12:31 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub11 Jun · 04:23 UTC
Ivanti Sentry RCE flaw under active exploitation, root access possiblecriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry RCE flaw under active exploitation, root access possible

Ivanti Sentry (formerly MobileIron Sentry) - Internet-exposed secure mobile gateways. Specific vulnerable versions not provided in summary, but patch recently released.

Ivanti11 Jun · 04:20 UTC
Active exploitation of path traversal in Langflow AI platformhighbug_reportVulnerability
bug_reportVulnerability

Active exploitation of path traversal in Langflow AI platform

Langflow AI development platform. Specific affected versions not disclosed. Impacts internet-exposed Langflow servers vulnerable to arbitrary file write via path traversal (CVE-2026-5027).

CVE-2026-502710 Jun · 19:23 UTC
Miasma credential-stealing framework source code leaked on GitHubhighbug_reportVulnerability
bug_reportVulnerability

Miasma credential-stealing framework source code leaked on GitHub

Open-source software ecosystems and their supply chains. Organizations consuming packages from public repositories (npm, PyPI, RubyGems, etc.) are at increased risk. No specific vendor or product version affected; threat is ecosystem-wide.

BleepingComputer10 Jun · 18:27 UTC
Critical RCE in Veeam Backup & Replication requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Veeam Backup & Replication requires immediate patching

Veeam Backup & Replication (specific versions not disclosed in summary). Remote code execution vulnerability allows attackers to execute arbitrary code on affected systems.

Veeam10 Jun · 16:20 UTC
Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical

Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft10 Jun · 13:47 UTC
Ivanti Sentry critical RCE and auth bypass require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry critical RCE and auth bypass require immediate patching

Ivanti Sentry (specific versions not disclosed in summary). Vulnerabilities enable root-level remote code execution and authentication bypass. CVE identifiers not yet assigned or published.

Ivanti10 Jun · 13:13 UTC
Fortinet FortiSandbox command injection flaw enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox command injection flaw enables remote code execution

Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.

CVE-2026-2508910 Jun · 13:10 UTC
Langflow path traversal flaw (CVE-2026-5027) exploited for RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow path traversal flaw (CVE-2026-5027) exploited for RCE

Langflow open-source low-code AI platform, all unpatched versions. Vulnerability allows unauthenticated path traversal leading to arbitrary file write and remote code execution.

CVE-2026-502710 Jun · 13:00 UTC
Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)highbug_reportVulnerability
bug_reportVulnerability

Cisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)

Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).

CVE-2026-2024510 Jun · 12:44 UTC
Ivanti Sentry critical RCE flaws allow unauthenticated remote attackscriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry critical RCE flaws allow unauthenticated remote attacks

Ivanti Sentry products (specific versions not provided). Two critical vulnerabilities enable unauthenticated remote code execution on exposed devices.

Ivanti10 Jun · 11:55 UTC
Microsoft patches actively exploited XSS zero-day in Exchange Server OWAhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches actively exploited XSS zero-day in Exchange Server OWA

Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.

Microsoft10 Jun · 11:44 UTC
Aix-DB missing authentication flaw allows unauthorized critical accesshighbug_reportVulnerability
bug_reportVulnerability

Aix-DB missing authentication flaw allows unauthorized critical access

Aix-DB software (vendor: Aix-DB). Specific affected versions not disclosed. Vulnerability allows unauthenticated access to critical functions (CWE-306).

CVE-2026-833510 Jun · 08:55 UTC
Microsoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasmacriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma

All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.

Microsoft10 Jun · 07:57 UTC
Microsoft patches 206 vulnerabilities including 3 zero-days, 39 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 206 vulnerabilities including 3 zero-days, 39 critical

Microsoft software portfolio: 206 vulnerabilities patched including 56 remote code execution (RCE) flaws, 63 privilege escalation issues, 39 critical-severity vulnerabilities, and 3 actively exploited zero-day flaws.

Microsoft10 Jun · 07:38 UTC
Windows Server domain controllers under active RCE attackcriticalbug_reportVulnerability
bug_reportVulnerability

Windows Server domain controllers under active RCE attack

Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.

Microsoft10 Jun · 06:47 UTC
ServiceNow patches actively exploited auth bypass on hosted instanceshighbug_reportVulnerability
bug_reportVulnerability

ServiceNow patches actively exploited auth bypass on hosted instances

ServiceNow hosted customer instances (specific versions not disclosed). On-premise deployments may also be affected pending vendor guidance.

ServiceNow10 Jun · 05:02 UTC
Ivanti Sentry critical RCE allows unauthenticated root code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti Sentry critical RCE allows unauthenticated root code execution

Ivanti Sentry secure mobile gateway solution. Specific affected versions not disclosed. Two critical vulnerabilities patched, including one maximum-severity (likely CVSS 10.0) remote code execution flaw enabling unauthenticated attackers to execute a…

Ivanti10 Jun · 04:26 UTC
Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM accesscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM access

Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.

Microsoft10 Jun · 03:22 UTC
Six RCE and DoS flaws found in protobuf.js for Node.js applicationshighbug_reportVulnerability
bug_reportVulnerability

Six RCE and DoS flaws found in protobuf.js for Node.js applications

protobuf.js library (JavaScript/TypeScript implementation of Protocol Buffers) used in Node.js applications. Specific vulnerable versions not provided in summary.

protobuf.js10 Jun · 03:08 UTC
Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation

Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.

Microsoft9 Jun · 21:11 UTC
Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs

Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.

Microsoft9 Jun · 20:07 UTC
OpenClaw AI email agent vulnerable to phishing attackshighbug_reportVulnerability
bug_reportVulnerability

OpenClaw AI email agent vulnerable to phishing attacks

OpenClaw AI email agent (all versions). Scope: AI-powered email processing systems that handle user communications and may access sensitive user data.

OpenClaw9 Jun · 19:20 UTC
SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloudcriticalbug_reportVulnerability
bug_reportVulnerability

SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud

SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.

SAP9 Jun · 17:36 UTC
Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-dayshighbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days

Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft9 Jun · 15:57 UTC
Veeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4criticalbug_reportVulnerability
bug_reportVulnerability

Veeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4

Veeam Backup & Replication software. Specific affected versions not disclosed in available data. Requires authenticated domain user access to exploit.

CVE-2026-449639 Jun · 14:39 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft9 Jun · 13:42 UTC
SAP releases critical patches for multiple productscriticalbug_reportVulnerability
bug_reportVulnerability

SAP releases critical patches for multiple products

Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.

SAP9 Jun · 12:23 UTC
WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukrainehighbug_reportVulnerability
bug_reportVulnerability

WinRAR CVE-2025-8088 path traversal exploited by Russian APTs vs Ukraine

WinRAR versions prior to patched release (approximately one year old). Primary targets: Ukrainian organizations. Threat actors: Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned APT groups.

CVE-2025-80889 Jun · 10:26 UTC