Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 159 results
Active filter:✕ clear
Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs

Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.

Microsoft20:07 UTC
SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloudcriticalbug_reportVulnerability
bug_reportVulnerability

SAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud

SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.

SAP17:36 UTC
Veeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4criticalbug_reportVulnerability
bug_reportVulnerability

Veeam Backup & Replication RCE flaw (CVE-2026-44963) patched, CVSS 9.4

Veeam Backup & Replication software. Specific affected versions not disclosed in available data. Requires authenticated domain user access to exploit.

CVE-2026-4496314:39 UTC
SAP releases critical patches for multiple productscriticalbug_reportVulnerability
bug_reportVulnerability

SAP releases critical patches for multiple products

Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.

SAP12:23 UTC
Check Point VPN authentication flaw under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point VPN authentication flaw under active exploitation

Check Point VPN products with user authentication functionality. Specific affected versions not disclosed. CVE identifier not yet assigned.

Check Point10:15 UTC
Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Chrome V8 zero-day CVE-2026-11645 exploited in wild, patch immediately

Google Chrome versions prior to 149.0.7827.103 on all platforms. The vulnerability resides in the V8 JavaScript engine, affecting out-of-bounds memory access.

CVE-2026-1164509:58 UTC
Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)criticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel nf_tables use-after-free enables root escalation (CVE-2026-23111)

Linux kernel nf_tables subsystem. All distributions using vulnerable kernel versions prior to the February 5, 2026 patch. Affects systems where unprivileged users have local access or container environments.

CVE-2026-2311118:17 UTC
Gogs patches critical RCE zero-day affecting Internet-facing instancescriticalbug_reportVulnerability
bug_reportVulnerability

Gogs patches critical RCE zero-day affecting Internet-facing instances

Gogs Git service, Internet-facing instances (specific vulnerable versions not disclosed). All repositories including private repos accessible post-exploitation.

Gogs14:18 UTC
Ubiquiti UniFi OS vulnerable to RCE via chained patched vulnerabilitiescriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti UniFi OS vulnerable to RCE via chained patched vulnerabilities

Ubiquiti UniFi OS server (specific versions not provided). Vulnerability chain affects systems running outdated UniFi OS versions containing three previously patched flaws.

Ubiquiti13:51 UTC
SolarWinds Serv-U actively exploited for resource exhaustion attackscriticalbug_reportVulnerability
bug_reportVulnerability

SolarWinds Serv-U actively exploited for resource exhaustion attacks

SolarWinds Serv-U file transfer software, unpatched versions. Specific vulnerable version range not disclosed in summary. CVE identifier not yet assigned.

SolarWinds13:04 UTC
Check Point VPN auth bypass under active exploit via IKEv1 flawcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point VPN auth bypass under active exploit via IKEv1 flaw

Check Point Remote Access VPN and Mobile Access deployments using deprecated IKEv1 protocol. Specific product versions not disclosed. Does not affect IKEv2 configurations.

CVE-2026-5075112:17 UTC
Check Point patches zero-day in VPN/Mobile Access exploited by Qilincriticalbug_reportVulnerability
bug_reportVulnerability

Check Point patches zero-day in VPN/Mobile Access exploited by Qilin

Check Point Remote Access VPN and Mobile Access deployments. Specific product versions not disclosed in summary; refer to vendor advisory for affected releases and patched versions.

Check Point11:05 UTC
Critical vulnerability in MISP requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerability in MISP requires immediate patching

MISP (Malware Information Sharing Platform) - specific versions not disclosed in advisory. All unpatched instances potentially affected.

MISP06:28 UTC
Everest Forms Pro WordPress plugin under active exploit for site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

Everest Forms Pro WordPress plugin under active exploit for site takeover

Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.

CVE-2026-330012:09 UTC
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm16:05 UTC
Active exploitation of RCE flaw in Everest Forms Pro WordPress plugincriticalbug_reportVulnerability
bug_reportVulnerability

Active exploitation of RCE flaw in Everest Forms Pro WordPress plugin

Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.

CVE-2026-330006:38 UTC
Cisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access

Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.

CVE-2026-2024504:24 UTC
Critical vulnerabilities in Gladinet Triofox require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in Gladinet Triofox require immediate patching

Gladinet Triofox file sharing and collaboration platform. Specific affected versions not disclosed in available data. All unpatched instances should be considered at risk.

Gladinet03:54 UTC
Miasma supply chain attack compromises Red Hat npm packagescriticalbug_reportVulnerability
bug_reportVulnerability

Miasma supply chain attack compromises Red Hat npm packages

Red Hat Cloud Services npm packages (@redhat-cloud-services scope). Affects developers and CI/CD pipelines using these packages. Scope includes any environment where compromised packages were installed.

Red Hat15:40 UTC
Windows Netlogon RCE under active exploitation after patch releasecriticalbug_reportVulnerability
bug_reportVulnerability

Windows Netlogon RCE under active exploitation after patch release

Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.

Microsoft10:30 UTC
WP Maps Pro plugin exploited to create rogue admin accounts on WordPresscriticalbug_reportVulnerability
bug_reportVulnerability

WP Maps Pro plugin exploited to create rogue admin accounts on WordPress

WP Maps Pro WordPress plugin (all versions prior to patch). Over 15,000 installations via Envato Market. Affects WordPress sites using this plugin for Google Maps integration.

WP Maps Pro06:45 UTC
PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

PAN-OS GlobalProtect auth bypass CVE-2026-0257 under active exploit

Palo Alto Networks PAN-OS GlobalProtect VPN. Specific affected versions not disclosed in provided data. Impacts corporate networks using GlobalProtect for remote access.

CVE-2026-025716:02 UTC
Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical

Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft14:06 UTC
Critical RCE in Gogs Git service allows authenticated users to execute codecriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE in Gogs Git service allows authenticated users to execute code

Gogs self-hosted Git service. Specific affected versions not disclosed. All authenticated users can exploit the vulnerability.

Gogs15:24 UTC
Starlette and FastAPI authentication bypass flaw affects millions of serverscriticalbug_reportVulnerability
bug_reportVulnerability

Starlette and FastAPI authentication bypass flaw affects millions of servers

Starlette web framework and dependent frameworks including FastAPI. Specific vulnerable versions not provided in source data. Affects authentication mechanisms in applications built with these frameworks.

Starlette12:32 UTC
Unpatched RCE zero-day in Gogs Git service actively threatens exposed instancescriticalbug_reportVulnerability
bug_reportVulnerability

Unpatched RCE zero-day in Gogs Git service actively threatens exposed instances

Gogs self-hosted Git service, all Internet-facing instances. Specific affected versions not disclosed. No patch currently available.

Gogs12:25 UTC
Critical RCE vulnerability in LiquidJS requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical RCE vulnerability in LiquidJS requires immediate patching

LiquidJS templating engine, all versions prior to patched release. Specific vulnerable version range not provided in available data.

LiquidJS12:20 UTC
Dell Container Storage Modules info disclosure enables data exfiltrationcriticalbug_reportVulnerability
bug_reportVulnerability

Dell Container Storage Modules info disclosure enables data exfiltration

Dell Container Storage Modules (specific versions not disclosed in summary). Vulnerability allows information disclosure that can lead to data exfiltration and lateral movement within containerized environments.

Dell11:55 UTC
Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Apache ActiveMQ NMS AMQP Client deserialization flaw enables RCE

Apache ActiveMQ NMS AMQP Client - specific vulnerable versions not provided. Affects .NET/C# applications using the NMS AMQP client library for message queue operations.

Apache14:59 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft14:23 UTC