Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 340 results
Active filter:✕ clear
Red Hat Keycloak password-reset flaw enables account takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Red Hat Keycloak password-reset flaw enables account takeover

Red Hat build of Keycloak, specific versions not disclosed in source. Vulnerability exists in the password-reset flow mechanism.

Red Hat20 Aug · 12:36 UTC
Citrix NetScaler ADC/Gateway auth bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Citrix NetScaler ADC/Gateway auth bypass requires immediate patching

Citrix NetScaler ADC and NetScaler Gateway products. Specific affected versions not disclosed in available information. Authentication bypass vulnerability allows unauthorized access.

Citrix20 Aug · 12:25 UTC
Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on hostcriticalbug_reportVulnerability
bug_reportVulnerability

Critical sandbox escape in isolated-vm ≤7.0.0 enables RCE on host

isolated-vm library versions ≤7.0.0. Patched in versions 6.2.0 and 7.0.1. Affects Node.js environments using isolated-vm for sandboxing untrusted JavaScript. Package has ~1 million weekly npm downloads.

isolated-vm20 Aug · 11:48 UTC
Critical auth bypass in NetScaler Gateway/AAA servers (CVE-2026-19490)criticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass in NetScaler Gateway/AAA servers (CVE-2026-19490)

Citrix NetScaler ADC and NetScaler Gateway customer-managed instances: versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, FIPS builds before 14.1-73.32 FIPS and 13.1-37.277.

Citrix20 Aug · 11:35 UTC
CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Critical MLflow SSRF flaw (CVE-2026-64849) exploited in the wild

MLflow open-source AI engineering platform, all versions prior to 3.15.0. Default MLflow Tracking Server deployments without authentication are vulnerable.

MLflow20 Aug · 09:06 UTC
Zimbra RCE flaw CVE-2026-73570 actively exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra RCE flaw CVE-2026-73570 actively exploited in the wild

Zimbra Collaboration Suite (ZCS) versions prior to 10.1.20. Affects servers with SNMP notifications enabled. Over 12,100 Zimbra servers exposed online, primarily in Europe (4,382) and Asia (4,492). Impacts businesses and government agencies globally.

Zimbra20 Aug · 07:46 UTC
Critical auth bypass and DoS flaws in Citrix NetScaler ADC/Gatewaycriticalbug_reportVulnerability
bug_reportVulnerability

Critical auth bypass and DoS flaws in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway versions 14.1 before 14.1-73.32, 13.1 before 13.1-63.21, NetScaler ADC FIPS before 14.1-73.32 FIPS, and FIPS/NDcPP before 13.1-37.277. CVE-2026-19489 affects devices with SIP ALG enabled on LSN groups.

Citrix19 Aug · 16:13 UTC
Microsoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 critical

Microsoft products and services across the ecosystem. 163 total vulnerabilities patched, including 8 critical severity issues. Specific affected products, CVE identifiers, and version details not provided in source material.

Microsoft19 Aug · 11:46 UTC
Zimbra Collaboration RCE under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra Collaboration RCE under active exploitation, patch immediately

Zimbra Collaboration Suite - specific vulnerable versions not disclosed in advisory. Remote code execution vulnerability affecting internet-facing Zimbra instances.

Zimbra19 Aug · 11:28 UTC
CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attackcriticalbug_reportVulnerability
bug_reportVulnerability

CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack

Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…

CVE-2026-6540019 Aug · 09:01 UTC
Windows IKE Extension RCE (CVE-2026-33824) actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Windows IKE Extension RCE (CVE-2026-33824) actively exploited

All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.

Microsoft19 Aug · 08:12 UTC
Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgscriticalperson_alertThreat Actor
person_alertThreat Actor

Medusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs

Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.

BleepingComputer19 Aug · 06:00 UTC
Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLMcriticalbug_reportVulnerability
bug_reportVulnerability

Clop deploys custom JSP web shell targeting PTC Windchill and FlexPLM

PTC Windchill and FlexPLM servers vulnerable to CVE-2026-12569 (CVSS 9.3). All unpatched instances are at risk. These enterprise Product Lifecycle Management (PLM) systems store engineering data, product designs, and administrative credentials.

PTC19 Aug · 03:39 UTC
MLflow SSRF and FUXA path traversal flaws under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

MLflow SSRF and FUXA path traversal flaws under active exploitation

MLflow versions < 3.15.0 (CVE-2026-64849, CVSS 9.3) and FUXA versions <= 1.2.9 (CVE-2026-25895, CVSS 9.5). MLflow is an open-source AI platform; FUXA is open-source SCADA/HMI software for industrial automation.

MLflow18 Aug · 15:44 UTC
GitLab CE/EE critical code injection flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

GitLab CE/EE critical code injection flaw with public PoC exploit

GitLab Community Edition (CE) and Enterprise Edition (EE). Specific affected versions not provided in source material. CVE identifier not yet assigned or disclosed.

GitLab18 Aug · 13:12 UTC
SAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited

SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.

SAP18 Aug · 13:07 UTC
Ray framework CVE-2025-62593 exploited via DNS rebinding for browser RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ray framework CVE-2025-62593 exploited via DNS rebinding for browser RCE

Ray open-source Python distributed computing framework, versions prior to 2.52.0. Primarily affects developers running development/testing environments. Over 43,500 GitHub stars indicate wide adoption in AI/ML workflows.

Ray18 Aug · 04:34 UTC
Critical GitLab GraphQL flaw allows unauthenticated project deletioncriticalbug_reportVulnerability
bug_reportVulnerability

Critical GitLab GraphQL flaw allows unauthenticated project deletion

GitLab Community Edition (CE) and Enterprise Edition (EE) self-managed installations: all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

CVE-2026-1947817 Aug · 19:03 UTC
Forminator WordPress plugin RCE affects 600K+ sites via file upload bypasscriticalbug_reportVulnerability
bug_reportVulnerability

Forminator WordPress plugin RCE affects 600K+ sites via file upload bypass

Forminator Forms WordPress plugin versions ≤1.56.1. Affects 600,000+ active installations. Exploitation requires a form with both File Upload and Select fields. Sites using custom file upload storage paths are at higher risk.

CVE-2026-1574817 Aug · 16:22 UTC
GeoServer zero-day SQL injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

GeoServer zero-day SQL injection under active exploitation

GeoServer (specific versions not disclosed in advisory). All unpatched instances potentially vulnerable to SQL injection attacks.

GeoServer17 Aug · 12:17 UTC
Certighost (CVE-2026-54121): Domain user can escalate to DC via CAcriticalbug_reportVulnerability
bug_reportVulnerability

Certighost (CVE-2026-54121): Domain user can escalate to DC via CA

Microsoft Active Directory Certificate Services (AD CS) in Enterprise CA configurations. All versions prior to July 14, 2026 patch. Affects organizations with default AD settings including MachineAccountQuota allowing machine account creation by stan…

CVE-2026-5412117 Aug · 12:00 UTC
Unisoc modem flaw enables Android kernel takeover via VoLTE video callcriticalbug_reportVulnerability
bug_reportVulnerability

Unisoc modem flaw enables Android kernel takeover via VoLTE video call

Unisoc chipsets T606, T612, and T7250 used in Motorola E13, Realme C33, and Xiaomi Redmi A5. Devices with these chipsets sold across 140+ countries. Confirmed vulnerable on Motorola E13 (February 2025 patch) and Xiaomi Redmi A5 (January 2026 patch).

Unisoc17 Aug · 08:52 UTC
IBM i systems face critical vulnerabilities requiring immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

IBM i systems face critical vulnerabilities requiring immediate patching

IBM i systems (formerly AS/400). Specific versions and CVE identifiers not disclosed in advisory. Scope appears to be multiple severe vulnerabilities across the platform.

IBM17 Aug · 07:37 UTC
Adobe Commerce critical vulnerability under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe Commerce critical vulnerability under active exploitation

Adobe Commerce (formerly Magento). Specific affected versions not disclosed in advisory. All unpatched instances should be considered at risk.

Adobe17 Aug · 07:14 UTC
China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomwarecriticalperson_alertThreat Actor
person_alertThreat Actor

China-Nexus APT Exploits VMware vCenter Flaws, Deploys Babuk Ransomware

A suspected China-nexus advanced persistent threat actor, assessed with moderate confidence by QUIRSO to be Chinese-speaking and operating in the UTC+08:00 time zone.

CVE-2026-5931017 Aug · 05:36 UTC
SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch

SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.

CVE-2026-5823115 Aug · 06:38 UTC
SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patchcriticalbug_reportVulnerability
bug_reportVulnerability

SAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.

SAP14 Aug · 11:45 UTC
VMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH accesscriticalbug_reportVulnerability
bug_reportVulnerability

VMware vCenter RCE (CVE-2026-59310) exploited for reverse SSH access

VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.

CVE-2026-5931013 Aug · 14:40 UTC
SonicWall GMS unauthenticated RCE flaws require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall GMS unauthenticated RCE flaws require immediate patching

SonicWall Global Management System (GMS). Specific affected versions not disclosed in available data. Both CVE-2026-66145 and CVE-2026-66147 enable unauthenticated remote code execution.

CVE-2026-6614513 Aug · 13:36 UTC
Cisco Secure Firewall DoS flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Cisco Secure Firewall DoS flaw under active exploitation

Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.

Cisco13 Aug · 06:31 UTC