Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 226 results
criticalbug_reportVulnerabilityWordPress wp2shell flaws enable unauthenticated RCE, active exploitation
WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.
criticalbug_reportVulnerabilitySonicWall SMA1000 VPN appliances exploited via two zero-day flaws
SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.
criticalbug_reportVulnerabilityCritical NGINX heap overflow enables RCE via crafted HTTP requests
NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.
criticalbug_reportVulnerabilitySonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.
criticalbug_reportVulnerabilityWordPress Core RCE "wp2shell" exploits now public, patch immediately
WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".
criticalbug_reportVulnerabilityWordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active
WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.
criticalbug_reportVulnerabilityDigiCert breach linked to Chinese APT; code-signing certs stolen
DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).
criticalbug_reportVulnerabilityFortinet FortiSandbox critical RCE and privilege escalation flaw
Fortinet FortiSandbox - specific affected versions not disclosed in available advisory. Product used for malware analysis and threat detection in enterprise environments.
criticalbug_reportVulnerabilityWindows zero-day LegacyHive enables privilege escalation on patched systems
All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.
criticalbug_reportVulnerabilitySiemens ROX II OT switches vulnerable to chained zero-day privilege escalation
Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Fortinet FortiSandbox flaws
Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.
criticalbug_reportVulnerabilityCISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited
Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.
criticalbug_reportVulnerabilityCISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalog
KNX Protocol implementations used in building automation and smart home systems. Specific affected products and versions not disclosed in available information.
criticalbug_reportVulnerabilityUbiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0
Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Langflow auth bypass by Friday
Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.
criticalbug_reportVulnerabilityUbiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE
Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.
criticalbug_reportVulnerabilityCISA orders patching of actively exploited Adobe ColdFusion flaw
Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.
criticalbug_reportVulnerability15-year-old Linux kernel flaw allows local privilege escalation to root
Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.
criticalbug_reportVulnerabilityGoogle Dialogflow CX flaw lets attackers hijack agents in same GCP project
Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.
criticalbug_reportVulnerabilityWriter AI platform session isolation flaw enables cross-tenant access
Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.
criticalbug_reportVulnerabilityBeyondTrust RS and PRA authentication bypass flaws require patching
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.
criticalbug_reportVulnerabilityTenda router backdoor allows admin access bypass (CVE-2026-11405)
Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.
criticalbug_reportVulnerabilityBeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)
BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.
criticalbug_reportVulnerability16-year KVM hypervisor flaw enables guest-to-host kernel corruption
Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).
criticalbug_reportVulnerabilityGitea Docker auth bypass under active probing (CVE-2026-20896)
Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.
criticalbug_reportVulnerabilityAdobe ColdFusion CVE-2026-48282 under active exploitation
Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.
criticalbug_reportVulnerabilityLinux kernel "Bad Epoll" flaw grants unprivileged root access
Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.
criticalperson_alertThreat ActorJADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack
JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…
criticalbug_reportVulnerabilityMicrosoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)
Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.
criticalbug_reportVulnerabilityArgo CD repo-server RCE enables cluster takeover, no patch available
Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.