Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 340 results
criticalbug_reportVulnerabilityServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCE
ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5).
criticalbug_reportVulnerabilityZBT routers ship with factory implants granting root access via network
ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.
criticalbug_reportVulnerabilityServiceNow AI Platform: 3 critical unauthenticated flaws patched
ServiceNow AI Platform (formerly Now Platform): Xanadu Patch 11, Yokohama Patch 12-13, Zurich Patch 7-12, Australia Patch 2-5. Affects cloud (auto-patched) and self-hosted instances.
criticalbug_reportVulnerabilityPaperCut NG/MF zero-day exploited in wild; all versions affected
All versions of PaperCut NG and PaperCut MF print management software. Primary risk: Internet-exposed Application Servers with public-facing web interfaces.
criticalbug_reportVulnerabilityNext.js critical RCE flaws in AVIF processing and Windows path traversal
Next.js versions 13.4–15.5.23 and 16.0–16.3.2. CVE-2026-75604 (Windows path traversal, CVSS 9.0) affects Windows-hosted servers using Pages Router or App Router without Cache Components.
criticalbug_reportVulnerabilityApache Log4j2 deserialization filter bypass enables remote code execution
Apache Log4j2 logging library. Specific affected versions not disclosed in available information. Impacts Java applications using Log4j2 with deserialization features enabled.
criticalbug_reportVulnerabilityVeeam ONE authentication bypass requires immediate patching
Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
criticalbug_reportVulnerabilityTeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit
Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29
Citrix NetScaler ADC and NetScaler Gateway appliances with Gateway VPN or AAA virtual server configurations. CVE-2026-8452 (high severity). Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.
criticalbug_reportVulnerabilityWatchGuard Agent RCE flaws require immediate patching
WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.
criticalbug_reportVulnerabilityAvada WordPress theme RCE chain affects sites with theme + plugin active
Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously.
criticalbug_reportVulnerabilityUbiquiti patches three max-severity RCE flaws in UniFi products
Ubiquiti UniFi Protect Application (fixed in 7.2.105+), UniFi Talk Application (fixed in 5.3.2+), and UniFi OS Server (5.1.21 and earlier). Over 100,000 UniFi OS instances exposed online.
criticalbug_reportVulnerabilityUnpatched Kaltura mwEmbed flaws enable file read and RCE via deserialization
Kaltura mwEmbed (html5lib) v2.45, v2.103, and all earlier v2.x releases exposing mwEmbedLoader.php. Affects customer installations and Kaltura's shared multi-tenant CDN infrastructure.
criticalbug_reportVulnerabilityGitea CVE-2026-60004 RCE exploited in wild; CISA orders 3-day patch
Gitea self-hosted Git service versions prior to 1.27.1. Approximately 5,000 instances exposed online. Default configurations with self-registration enabled are exploitable by unauthenticated attackers.
criticalbug_reportVulnerabilityOAuth2 Proxy authentication bypass allows unauthorized access
OAuth2 Proxy (specific versions not disclosed in available data). All deployments using OAuth2 Proxy for authentication are potentially at risk.
criticalbug_reportVulnerabilityOracle critical vulnerability under active exploitation, patching urgent
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.
criticalbug_reportVulnerabilityOracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.
criticalbug_reportVulnerabilityminiOrange SAML SSO plugin flaws actively exploited for WordPress admin access
miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP…
criticalbug_reportVulnerabilityPostgreSQL RCE vulnerability with PoC exploit requires immediate patching
PostgreSQL database servers (specific affected versions not disclosed in available information). Scope: remote code execution vulnerability affecting PostgreSQL installations.
criticalbug_reportVulnerabilityCritical Keycloak flaw allows unauthenticated account takeover via password reset
Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.
criticalbug_reportVulnerabilityCISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.
criticalbug_reportVulnerabilityCISA orders patching of two actively exploited TrueConf Server flaws
TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…
criticalbug_reportVulnerabilityMicrosoft Entra ID deserialization flaw exploited; already patched
Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.
criticalbug_reportVulnerabilityCisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0
Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0).
criticalbug_reportVulnerabilityGitLab CVE-2026-19478 code injection under active exploitation
GitLab Community Edition (CE) and Enterprise Edition (EE): versions 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Affects self-hosted instances with publicly accessible projects.
criticalbug_reportVulnerabilityMicrosoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)
Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.
criticalbug_reportVulnerabilityRust crates compromised via account takeover; build-time malware deployed
Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.
criticalbug_reportVulnerabilityZero-click RCE in Zoom clients requires immediate patching
Zoom clients (specific versions not disclosed in available data). Zero-click remote code execution vulnerability affects users without interaction required.
criticalbug_reportVulnerabilityRust crate arrayref compromised via maintainer account takeover
Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.
criticalbug_reportVulnerabilityElementor Pro WordPress plugin allows arbitrary file upload and RCE
Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.