Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

12 / 702 results
Active filter:✕ clear
Code Runner MCP Server missing authentication flaw allows unauthorized accesshighbug_reportVulnerability
bug_reportVulnerability

Code Runner MCP Server missing authentication flaw allows unauthorized access

Code Runner MCP Server (all versions not specified). The vulnerability affects critical functions within the server, allowing unauthenticated access to protected operations. Specific version ranges have not been disclosed by CERT.PL.

CVE-2026-502912 May · 08:55 UTC
3onedata GW1101 Modbus gateway vulnerable to OS command injectionhighbug_reportVulnerability
bug_reportVulnerability

3onedata GW1101 Modbus gateway vulnerable to OS command injection

3onedata GW1101-1D(RS-485)-TB-P Modbus gateways. Specific affected firmware versions not disclosed. These are industrial IoT devices used for Modbus protocol conversion in OT/ICS environments.

CVE-2025-136054 May · 12:55 UTC
Orca heat pumps lack authentication, transmit cleartext data to servershighbug_reportVulnerability
bug_reportVulnerability

Orca heat pumps lack authentication, transmit cleartext data to servers

Orca heat pumps (specific models and versions not disclosed). Vulnerability affects device-to-server communication and server-side data processing.

CVE-2026-2559917 Apr · 03:11 UTC
MikroTik RouterOS auth bypass via certificate validation flawhighbug_reportVulnerability
bug_reportVulnerability

MikroTik RouterOS auth bypass via certificate validation flaw

MikroTik RouterOS - versions not specified. Affects OpenVPN, CAPsMAN (wireless management), and 802.1X (Dot1x) services that rely on certificate-based authentication.

CVE-2025-4261110 Apr · 07:08 UTC
Cisco SD-WAN Manager auth bypass exploited in wild since 2023criticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN Manager auth bypass exploited in wild since 2023

Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. Specific affected versions not provided in advisory summary. CVE-2026-20127 allows administrative access compromise.

CVE-2026-2012726 Feb · 18:38 UTC
Ivanti EPMM critical RCE flaws under limited exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Ivanti EPMM critical RCE flaws under limited exploitation

Ivanti Endpoint Manager Mobile (EPMM) products. Specific affected versions not provided in advisory summary. Two critical vulnerabilities enabling unauthenticated remote code execution.

Ivanti30 Jan · 09:09 UTC
Fortinet FortiCloud SSO bypass exploited to extract LDAP passwordshighbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO bypass exploited to extract LDAP passwords

Fortinet FortiGate appliances with FortiCloud SSO enabled. CVE-2025-59718 and CVE-2025-59719 allow authentication bypass. All FortiGate instances share a default static encryption key that enables decryption of LDAP credentials and private keys from…

CVE-2025-5971827 Jan · 15:16 UTC
Fortinet FortiCloud SSO auth bypass under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiCloud SSO auth bypass under active exploitation

Fortinet FortiCloud SSO SAML authentication processing (CVE-2025-59718, CVE-2025-59719). Affects management interfaces of FortiGate and potentially other Fortinet products using FortiCloud SSO.

CVE-2025-5971822 Jan · 14:41 UTC
Cisco Secure Email Gateway critical flaw unpatched, check for compromisecriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Email Gateway critical flaw unpatched, check for compromise

Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. Specific affected versions not provided in advisory summary. No patch available as of December 17, 2025.

Cisco18 Dec · 09:08 UTC
React Server Components RCE flaw enables unauthenticated remote executioncriticalbug_reportVulnerability
bug_reportVulnerability

React Server Components RCE flaw enables unauthenticated remote execution

React Server Components and integrating frameworks (e.g., Next.js, Remix). All versions using React Server Components are potentially affected until patched.

Meta4 Dec · 13:50 UTC
Microsoft patches critical WSUS RCE flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical WSUS RCE flaw with public PoC exploit

Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.

Microsoft24 Oct · 16:42 UTC
Fortinet patches high severity FortiOS vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Fortinet patches high severity FortiOS vulnerability

FortiOS (specific versions not disclosed in summary). Fortinet advisory published October 14, 2025.

Fortinet15 Oct · 18:41 UTC