Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 340 results
Active filter:✕ clear
ServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCEcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow AI Platform: Three CVSS 10.0 flaws enable unauthenticated RCE

ServiceNow AI Platform versions: Xanadu (before Patch 11 HF 7a), Yokohama (before Patch 12 HF 3b / Patch 13 HF 4), Zurich (before Patch 7b HF 3 through Patch 12 depending on branch), Australia (before Patch 2 HF 3 through Patch 5).

ServiceNow28 Aug · 09:20 UTC
ZBT routers ship with factory implants granting root access via networkcriticalbug_reportVulnerability
bug_reportVulnerability

ZBT routers ship with factory implants granting root access via network

ZBT (Shenzhen Zhibotong Electronics) routers and white-labeled variants. CVE-2026-74233 (DARKLANTERN) affects 16+ models including WE1326, WE826-T2, WE5926, WG3526 on firmware builds from 2019-2020.

CVE-2026-7423228 Aug · 08:58 UTC
ServiceNow AI Platform: 3 critical unauthenticated flaws patchedcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow AI Platform: 3 critical unauthenticated flaws patched

ServiceNow AI Platform (formerly Now Platform): Xanadu Patch 11, Yokohama Patch 12-13, Zurich Patch 7-12, Australia Patch 2-5. Affects cloud (auto-patched) and self-hosted instances.

ServiceNow28 Aug · 08:29 UTC
PaperCut NG/MF zero-day exploited in wild; all versions affectedcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF zero-day exploited in wild; all versions affected

All versions of PaperCut NG and PaperCut MF print management software. Primary risk: Internet-exposed Application Servers with public-facing web interfaces.

PaperCut27 Aug · 14:31 UTC
Next.js critical RCE flaws in AVIF processing and Windows path traversalcriticalbug_reportVulnerability
bug_reportVulnerability

Next.js critical RCE flaws in AVIF processing and Windows path traversal

Next.js versions 13.4–15.5.23 and 16.0–16.3.2. CVE-2026-75604 (Windows path traversal, CVSS 9.0) affects Windows-hosted servers using Pages Router or App Router without Cache Components.

CVE-2026-7560427 Aug · 13:13 UTC
Apache Log4j2 deserialization filter bypass enables remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Apache Log4j2 deserialization filter bypass enables remote code execution

Apache Log4j2 logging library. Specific affected versions not disclosed in available information. Impacts Java applications using Log4j2 with deserialization features enabled.

Apache27 Aug · 12:57 UTC
Veeam ONE authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Veeam ONE authentication bypass requires immediate patching

Veeam ONE backup management platform. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Veeam27 Aug · 12:51 UTC
TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hitcriticalbug_reportVulnerability
bug_reportVulnerability

TeamPCP supply chain attack compromised Trivy, KICS, LiteLLM; 1000+ orgs hit

Open-source tools: Trivy scanner, Checkmarx KICS, LiteLLM AI gateway. Attack spanned GitHub Actions, Docker Hub, npm, PyPI, OpenVSX ecosystems. Over 1,000 organizations potentially compromised, 500,000+ credentials stolen, 300GB+ data exfiltrated.

Trivy27 Aug · 09:56 UTC
CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal agencies to patch exploited Citrix NetScaler RCE by Aug 29

Citrix NetScaler ADC and NetScaler Gateway appliances with Gateway VPN or AAA virtual server configurations. CVE-2026-8452 (high severity). Over 22,000 NetScaler ADC and 1,800 Gateway instances exposed online globally.

Citrix27 Aug · 07:16 UTC
WatchGuard Agent RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

WatchGuard Agent RCE flaws require immediate patching

WatchGuard Agent (specific versions not disclosed in available data). Remote code execution vulnerabilities affecting WatchGuard Agent software used for endpoint management and authentication.

WatchGuard27 Aug · 04:36 UTC
Avada WordPress theme RCE chain affects sites with theme + plugin activecriticalbug_reportVulnerability
bug_reportVulnerability

Avada WordPress theme RCE chain affects sites with theme + plugin active

Avada WordPress theme versions up to 7.16 and Fusion Builder plugin versions up to 3.16. Exploitation requires both components to be active simultaneously.

Avada26 Aug · 19:33 UTC
Ubiquiti patches three max-severity RCE flaws in UniFi productscriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches three max-severity RCE flaws in UniFi products

Ubiquiti UniFi Protect Application (fixed in 7.2.105+), UniFi Talk Application (fixed in 5.3.2+), and UniFi OS Server (5.1.21 and earlier). Over 100,000 UniFi OS instances exposed online.

Ubiquiti26 Aug · 11:17 UTC
Unpatched Kaltura mwEmbed flaws enable file read and RCE via deserializationcriticalbug_reportVulnerability
bug_reportVulnerability

Unpatched Kaltura mwEmbed flaws enable file read and RCE via deserialization

Kaltura mwEmbed (html5lib) v2.45, v2.103, and all earlier v2.x releases exposing mwEmbedLoader.php. Affects customer installations and Kaltura's shared multi-tenant CDN infrastructure.

CVE-2026-1991226 Aug · 09:55 UTC
Gitea CVE-2026-60004 RCE exploited in wild; CISA orders 3-day patchcriticalbug_reportVulnerability
bug_reportVulnerability

Gitea CVE-2026-60004 RCE exploited in wild; CISA orders 3-day patch

Gitea self-hosted Git service versions prior to 1.27.1. Approximately 5,000 instances exposed online. Default configurations with self-registration enabled are exploitable by unauthenticated attackers.

Gitea26 Aug · 09:07 UTC
OAuth2 Proxy authentication bypass allows unauthorized accesscriticalbug_reportVulnerability
bug_reportVulnerability

OAuth2 Proxy authentication bypass allows unauthorized access

OAuth2 Proxy (specific versions not disclosed in available data). All deployments using OAuth2 Proxy for authentication are potentially at risk.

OAuth2 Proxy25 Aug · 13:03 UTC
Oracle critical vulnerability under active exploitation, patching urgentcriticalbug_reportVulnerability
bug_reportVulnerability

Oracle critical vulnerability under active exploitation, patching urgent

Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.

Oracle25 Aug · 11:51 UTC
Oracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Oracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.

CVE-2026-2196225 Aug · 04:12 UTC
miniOrange SAML SSO plugin flaws actively exploited for WordPress admin accesscriticalbug_reportVulnerability
bug_reportVulnerability

miniOrange SAML SSO plugin flaws actively exploited for WordPress admin access

miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP…

miniOrange24 Aug · 17:26 UTC
PostgreSQL RCE vulnerability with PoC exploit requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

PostgreSQL RCE vulnerability with PoC exploit requires immediate patching

PostgreSQL database servers (specific affected versions not disclosed in available information). Scope: remote code execution vulnerability affecting PostgreSQL installations.

PostgreSQL24 Aug · 11:29 UTC
Critical Keycloak flaw allows unauthenticated account takeover via password resetcriticalbug_reportVulnerability
bug_reportVulnerability

Critical Keycloak flaw allows unauthenticated account takeover via password reset

Keycloak identity and access management server: upstream versions prior to 26.7.2; Red Hat build of Keycloak (RHBK) 26.4 prior to 26.4.15 and 26.6 prior to 26.6.6. All realms with "Forgot password" feature enabled are vulnerable.

CVE-2026-1896324 Aug · 09:56 UTC
CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders 3-day patch for exploited Zimbra RCE (CVE-2026-73570)

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Exploitation requires SNMP notifications to be enabled. Over 12,000 Zimbra servers exposed online; 270+ confirmed compromised instances detected by Shadowserver.

Zimbra24 Aug · 08:45 UTC
CISA orders patching of two actively exploited TrueConf Server flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of two actively exploited TrueConf Server flaws

TrueConf Server, a self-hosted corporate messaging and video conferencing platform. CVE-2026-72529 (critical missing authentication allowing remote script execution via TCP port 4307) and CVE-2026-72530 (critical sandbox escape enabling arbitrary OS…

TrueConf21 Aug · 10:25 UTC
Microsoft Entra ID deserialization flaw exploited; already patchedcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Entra ID deserialization flaw exploited; already patched

Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.

Microsoft21 Aug · 09:04 UTC
Cisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0criticalbug_reportVulnerability
bug_reportVulnerability

Cisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0

Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0).

Cisco21 Aug · 08:03 UTC
GitLab CVE-2026-19478 code injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

GitLab CVE-2026-19478 code injection under active exploitation

GitLab Community Edition (CE) and Enterprise Edition (EE): versions 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Affects self-hosted instances with publicly accessible projects.

CVE-2026-1947821 Aug · 05:04 UTC
Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)

Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.

Microsoft21 Aug · 04:06 UTC
Rust crates compromised via account takeover; build-time malware deployedcriticalbug_reportVulnerability
bug_reportVulnerability

Rust crates compromised via account takeover; build-time malware deployed

Three Rust crates (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9) with 245 million combined downloads. Malicious versions were live for 86-107 minutes on August 20, 2026.

Rust Project20 Aug · 18:22 UTC
Zero-click RCE in Zoom clients requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Zero-click RCE in Zoom clients requires immediate patching

Zoom clients (specific versions not disclosed in available data). Zero-click remote code execution vulnerability affects users without interaction required.

Zoom20 Aug · 16:29 UTC
Rust crate arrayref compromised via maintainer account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Rust crate arrayref compromised via maintainer account takeover

Rust crate arrayref (vendor: arrayref). Specific malicious versions not detailed in source. Affects developers using this dependency during compilation. Scope: Rust ecosystem supply chain.

arrayref20 Aug · 15:53 UTC
Elementor Pro WordPress plugin allows arbitrary file upload and RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Elementor Pro WordPress plugin allows arbitrary file upload and RCE

Elementor Pro WordPress plugin. Specific vulnerable versions not disclosed in available data. Affects WordPress sites with Elementor Pro installed.

Elementor20 Aug · 12:39 UTC