Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 226 results
Active filter:tag: #critical✕ clear
WordPress wp2shell flaws enable unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress wp2shell flaws enable unauthenticated RCE, active exploitation

WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.

CVE-2026-6013721 Jul · 06:59 UTC
SonicWall SMA1000 VPN appliances exploited via two zero-day flawscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 VPN appliances exploited via two zero-day flaws

SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.

SonicWall20 Jul · 20:23 UTC
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253319 Jul · 18:42 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".

WordPress18 Jul · 15:22 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress17 Jul · 19:20 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert17 Jul · 14:39 UTC
Fortinet FortiSandbox critical RCE and privilege escalation flawcriticalbug_reportVulnerability
bug_reportVulnerability

Fortinet FortiSandbox critical RCE and privilege escalation flaw

Fortinet FortiSandbox - specific affected versions not disclosed in available advisory. Product used for malware analysis and threat detection in enterprise environments.

Fortinet17 Jul · 13:35 UTC
Windows zero-day LegacyHive enables privilege escalation on patched systemscriticalbug_reportVulnerability
bug_reportVulnerability

Windows zero-day LegacyHive enables privilege escalation on patched systems

All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.

Microsoft17 Jul · 09:05 UTC
Siemens ROX II OT switches vulnerable to chained zero-day privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Siemens ROX II OT switches vulnerable to chained zero-day privilege escalation

Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.

Siemens17 Jul · 08:00 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet17 Jul · 05:03 UTC
CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited

Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.

CVE-2026-5864417 Jul · 04:42 UTC
CISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalogcriticalbug_reportVulnerability
bug_reportVulnerability

CISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalog

KNX Protocol implementations used in building automation and smart home systems. Specific affected products and versions not disclosed in available information.

CVE-2023-434616 Jul · 13:26 UTC
Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0criticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0

Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).

CVE-2026-507468 Jul · 12:38 UTC
CISA orders federal patch for exploited Langflow auth bypass by Fridaycriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Langflow auth bypass by Friday

Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.

Langflow8 Jul · 07:58 UTC
Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE

Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.

Ubiquiti8 Jul · 06:15 UTC
CISA orders patching of actively exploited Adobe ColdFusion flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Adobe ColdFusion flaw

Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.

Adobe8 Jul · 05:16 UTC
15-year-old Linux kernel flaw allows local privilege escalation to rootcriticalbug_reportVulnerability
bug_reportVulnerability

15-year-old Linux kernel flaw allows local privilege escalation to root

Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.

CVE-2026-434998 Jul · 04:16 UTC
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google7 Jul · 14:37 UTC
Writer AI platform session isolation flaw enables cross-tenant accesscriticalbug_reportVulnerability
bug_reportVulnerability

Writer AI platform session isolation flaw enables cross-tenant access

Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.

Writer7 Jul · 11:27 UTC
BeyondTrust RS and PRA authentication bypass flaws require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust RS and PRA authentication bypass flaws require patching

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.

BeyondTrust7 Jul · 06:12 UTC
Tenda router backdoor allows admin access bypass (CVE-2026-11405)criticalbug_reportVulnerability
bug_reportVulnerability

Tenda router backdoor allows admin access bypass (CVE-2026-11405)

Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.

CVE-2026-114057 Jul · 04:40 UTC
BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)criticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)

BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.

CVE-2026-401387 Jul · 03:16 UTC
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-533596 Jul · 15:37 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-208966 Jul · 14:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-482826 Jul · 11:18 UTC
Linux kernel "Bad Epoll" flaw grants unprivileged root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel "Bad Epoll" flaw grants unprivileged root access

Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.

CVE-2026-462423 Jul · 17:40 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow2 Jul · 07:13 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-456592 Jul · 03:46 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD1 Jul · 17:40 UTC