Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 340 results
criticalbug_reportVulnerabilityRed Hat Keycloak password-reset flaw enables account takeover
Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.
criticalbug_reportVulnerabilityCitrix NetScaler ADC/Gateway auth bypass requires immediate patching
Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.
criticalbug_reportVulnerabilityCritical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host
isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.
criticalbug_reportVulnerabilityCritical auth bypass in NetScaler Gateway/AAA servers (CVE-2026-19490)
Citrix NetScaler ADC and NetScaler Gateway customer-managed instances: versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, FIPS builds before 14.1-73.32 FIPS and 13.1-37.277.
criticalbug_reportVulnerabilityCISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild
MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.
criticalbug_reportVulnerabilityZimbra RCE flaw CVE-2026-73570 actively exploited in the wild
Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.
criticalbug_reportVulnerabilityCritical auth bypass and DoS flaws in Citrix NetScaler ADC/Gateway
Citrix NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and FIPS/NDcPP before 13.1-37.277. CVE-2026-19489 affects devices with SIP ALG enabled on LSN groups.
criticalbug_reportVulnerabilityMicrosoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 critical
Microsoft products and services across the ecosystem. 163 total vulnerabilities patched, including 8 critical severity issues. Specific affected products, CVE identifiers, and version details not provided in source material.
criticalbug_reportVulnerabilityZimbra Collaboration RCE under active exploitation, patch immediately
Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.
criticalbug_reportVulnerabilityCISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack
Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…
criticalbug_reportVulnerabilityWindows IKE Extension RCE (CVE-2026-33824) actively exploited
All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.
criticalperson_alertThreat ActorMedusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs
Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.
criticalbug_reportVulnerabilityClop deploys custom JSP web shell targeting PTC Windchill and FlexPLM
PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.
criticalbug_reportVulnerabilityMLflow SSRF and FUXA path traversal flaws under active exploitation
MLflow versions < 3.15.0 (CVE-2026-64849, CVSS 9.3) and FUXA versions <= 1.2.9 (CVE-2026-25895, CVSS 9.5). MLflow is an open-source AI platform; FUXA is open-source SCADA/HMI software for industrial automation.
criticalbug_reportVulnerabilityGitLab CE/EE critical code injection flaw with public PoC exploit
GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.
criticalbug_reportVulnerabilitySAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited
SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.
criticalbug_reportVulnerabilityRay framework CVE-2025-62593 exploited via DNS rebinding for browser RCE
Ray open-source Python distributed computing framework, versions prior to 2.52.0. Primarily affects developers running development/testing environments. Over 43,500 GitHub stars indicate wide adoption in AI/ML workflows.
criticalbug_reportVulnerabilityCritical GitLab GraphQL flaw allows unauthenticated project deletion
GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
criticalbug_reportVulnerabilityForminator WordPress plugin RCE affects 600K+ sites via file upload bypass
Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.
criticalbug_reportVulnerabilityGeoServer zero-day SQL injection under active exploitation
GeoServer (specific versions not disclosed in advisory). All unpatched instances potentially vulnerable to SQL injection attacks.
criticalbug_reportVulnerabilityCertighost (CVE-2026-54121): Domain user can escalate to DC via CA
Microsoft Active Directory Certificate Services (AD CS) in Enterprise CA configurations. All versions prior to July 14, 2026 patch. Affects organizations with default AD settings including MachineAccountQuota allowing machine account creation by stan…
criticalbug_reportVulnerabilityUnisoc modem flaw enables Android kernel takeover via VoLTE video call
Unisoc chipsets T606, T612, and T7250 used in Motorola E13, Realme C33, and Xiaomi Redmi A5. Devices with these chipsets sold across 140+ countries. Confirmed vulnerable on Motorola E13 (February 2025 patch) and Xiaomi Redmi A5 (January 2026 patch).
criticalbug_reportVulnerabilityIBM i systems face critical vulnerabilities requiring immediate patching
IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.
criticalbug_reportVulnerabilityAdobe Commerce critical vulnerability under active exploitation
Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.
criticalperson_alertThreat ActorChina-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware
A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.
criticalbug_reportVulnerabilitySAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch
SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.
criticalbug_reportVulnerabilitySAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch
SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.
criticalbug_reportVulnerabilityVMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access
VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.
criticalbug_reportVulnerabilitySonicWall GMS unauthenticated RCE flaws require immediate patching
SonicWall Global Management System (GMS). Specific affected versions not disclosed in available data. Both CVE-2026-66145 and CVE-2026-66147 enable unauthenticated remote code execution.
criticalbug_reportVulnerabilityCisco Secure Firewall DoS flaw under active exploitation
Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.