Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 340 results
Active filter:✕ clear
Arista VeloCloud Orchestrator command injection under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator command injection under active exploitation

Arista VeloCloud Orchestrator (VCO) on-premises versions: 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. Hosted and dedicated VCO versions already patched.

CVE-2026-1681228 Jul · 02:43 UTC
FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firmscriticalbug_reportVulnerability
bug_reportVulnerability

FastJson RCE zero-day (CVE-2026-16723) actively exploited against US firms

FastJson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments (java -jar xxx.jar). FastJson 1.2.60 and earlier, fastjson2, and non-fat-JAR deployments are NOT affected.

Alibaba27 Jul · 21:49 UTC
Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)criticalbug_reportVulnerability
bug_reportVulnerability

Arista VeloCloud Orchestrator zero-day exploited in the wild (CVE-2026-16812)

Arista VeloCloud Orchestrator on-premises deployments: versions 5.2.x before 5.2.3.14, 6.1.x before 6.1.3.4, 6.4.x before 6.4.2.4, and 7.0.x before 7.0.0.1. Hosted and Dedicated VCO deployments already patched.

Arista27 Jul · 20:49 UTC
vBulletin pre-auth RCE exploit public; patch released 4 weeks priorcriticalbug_reportVulnerability
bug_reportVulnerability

vBulletin pre-auth RCE exploit public; patch released 4 weeks prior

vBulletin 6.2.1 and earlier, 6.1.6 and earlier. Fixed in version 6.2.2 (released July 1, 2026) and patches for 6.2.1, 6.2.0, 6.1.6. vBulletin Cloud already patched. CVE-2026-61511 assigned but no NVD record or CVSS score available yet.

vBulletin27 Jul · 12:40 UTC
Fastjson 1.x RCE under active attack; no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Fastjson 1.x RCE under active attack; no patch available

Alibaba Fastjson versions 1.2.68 through 1.2.83 in Spring Boot executable fat-JAR deployments. Requires network-reachable JSON parsing endpoint and default SafeMode disabled. Plain JARs, generic uber-JARs, and WAR deployments are not affected.

CVE-2026-1672325 Jul · 10:52 UTC
Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortioncriticalperson_alertThreat Actor
person_alertThreat Actor

Cl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortion

Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical…

PTC25 Jul · 08:14 UTC
ChatGPT Workspace Agents CSRF flaw enabled rogue AI agent deploymentcriticalbug_reportVulnerability
bug_reportVulnerability

ChatGPT Workspace Agents CSRF flaw enabled rogue AI agent deployment

OpenAI ChatGPT Workspace Agents (Agent Builder tool) used by organizations with authorized connectors (Outlook, Gmail, Google Drive, Slack, Teams, etc.). Patched as of June 8, 2026. Product being deprecated November 30, 2026.

OpenAI24 Jul · 09:53 UTC
Bing Images SVG flaw allowed unauthenticated RCE as SYSTEM on serverscriticalbug_reportVulnerability
bug_reportVulnerability

Bing Images SVG flaw allowed unauthenticated RCE as SYSTEM on servers

Microsoft Bing Images service (CVE-2026-32194, CVE-2026-32191). Both Windows Server 2022 and Linux image-processing workers. Vulnerability exploitable via public "Search by Image" upload and URL-based image crawler.

CVE-2026-3219424 Jul · 09:45 UTC
Redis patches authenticated RCE flaws in versions 6.2–8.8criticalbug_reportVulnerability
bug_reportVulnerability

Redis patches authenticated RCE flaws in versions 6.2–8.8

Redis versions 6.2.22, 7.2.14, 7.4.9, 8.2.7, 8.4.4, 8.6.4, and 8.8.0. Exploitation requires authenticated access and RESTORE command privileges. Streams-based chain also requires EVAL and XGROUP commands; RedisBloom chain (8.8.0) requires EVAL and bu…

Redis24 Jul · 04:58 UTC
Russian Espionage Group Exploited Zimbra Zero-Day for Email Theftcriticalperson_alertThreat Actor
person_alertThreat Actor

Russian Espionage Group Exploited Zimbra Zero-Day for Email Theft

A Russian state-sponsored espionage group conducted a sustained campaign exploiting a zero-day vulnerability in Zimbra's webmail client. The actor, tracked as TA488 by Proofpoint and CL-STA-1114 by Unit 42, operated undetected for at least five month…

Zimbra23 Jul · 16:36 UTC
Progress Telerik UI for AJAX RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Progress Telerik UI for AJAX RCE vulnerability requires immediate patching

Progress Telerik UI for AJAX - specific affected versions not disclosed in available information. Vulnerability enables remote code execution.

Progress23 Jul · 13:51 UTC
Check Point privilege escalation flaws under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point privilege escalation flaws under active exploitation

Check Point products (specific versions not disclosed in available data). Three privilege escalation vulnerabilities identified, including one actively exploited flaw enabling full admin authentication bypass.

Check Point23 Jul · 13:19 UTC
Check Point SmartConsole auth bypass zero-day exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass zero-day exploited in the wild

Check Point SmartConsole (GUI admin panel for Security Management Server and Multi-Domain Security Management Server). CVE-2026-16232. Vulnerable configurations: Management Server IP exposed to Internet without Trusted Client IP restrictions.

Check Point Software23 Jul · 06:13 UTC
RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linuxcriticalbug_reportVulnerability
bug_reportVulnerability

RefluXFS kernel flaw grants local root on default RHEL, Fedora, Amazon Linux

Linux kernel 4.11+ (2017–July 2026) on systems with XFS filesystems created with reflink=1. Default installations of RHEL/CentOS Stream/Oracle/Rocky/AlmaLinux/CloudLinux 8/9/10, Fedora Server 31+, Amazon Linux 2023, and Amazon Linux 2 (Dec 2022+) are…

CVE-2026-6460023 Jul · 06:04 UTC
Check Point SmartConsole auth bypass (CVE-2026-16232) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

Check Point SmartConsole auth bypass (CVE-2026-16232) exploited in wild

Check Point Security Management and Multi-Domain Management (MDSM) products: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10. Affects SmartConsole login process when Management Server is exposed to internet without IP restrictio…

CVE-2026-1623223 Jul · 04:34 UTC
WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploitcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit

WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.

CVE-2026-6013722 Jul · 14:09 UTC
Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical

Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.

Microsoft22 Jul · 12:32 UTC
CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)criticalbug_reportVulnerability
bug_reportVulnerability

CISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)

Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.

Langflow22 Jul · 09:43 UTC
Microsoft SharePoint RCE flaws actively exploited; immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaws actively exploited; immediate patching required

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…

Microsoft22 Jul · 08:39 UTC
Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistencecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistence

Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.

CVE-2026-5052221 Jul · 18:06 UTC
WordPress Core wp2shell flaws actively exploited for webshell deploymentcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core wp2shell flaws actively exploited for webshell deployment

WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.

CVE-2026-6013721 Jul · 14:41 UTC
Microsoft SharePoint RCE (CVE-2026-50522) actively exploited after PoCcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE (CVE-2026-50522) actively exploited after PoC

Microsoft SharePoint Server (all versions prior to July 2026 patches). Vulnerability involves deserialization of untrusted data leading to unauthenticated remote code execution. CVSS 9.8 (Critical).

CVE-2026-5052221 Jul · 12:57 UTC
Zimbra 10.1.20 patches critical SNMP command injection and 4 XSS flawscriticalbug_reportVulnerability
bug_reportVulnerability

Zimbra 10.1.20 patches critical SNMP command injection and 4 XSS flaws

Zimbra Collaboration Suite versions prior to 10.1.20. Critical impact: SNMP monitoring component when SNMP notifications are enabled. Additional impact: four XSS vulnerabilities affecting the web interface.

Zimbra21 Jul · 11:18 UTC
Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerabilitycriticalperson_alertThreat Actor
person_alertThreat Actor

Qilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability

Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…

Palo Alto Networks21 Jul · 08:12 UTC
WordPress wp2shell flaws enable unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

WordPress wp2shell flaws enable unauthenticated RCE, active exploitation

WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.

CVE-2026-6013721 Jul · 06:59 UTC
SonicWall SMA1000 VPN appliances exploited via two zero-day flawscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 VPN appliances exploited via two zero-day flaws

SonicWall SMA1000 series VPN appliances. Specific vulnerable versions not disclosed. Affects enterprise VPN infrastructure using these devices.

SonicWall20 Jul · 20:23 UTC
Critical NGINX heap overflow enables RCE via crafted HTTP requestscriticalbug_reportVulnerability
bug_reportVulnerability

Critical NGINX heap overflow enables RCE via crafted HTTP requests

NGINX open source versions prior to 1.30.4 and 1.31.3, and NGINX Plus versions prior to 37.0.3.1. All deployments accepting HTTP requests from untrusted networks are at risk.

CVE-2026-4253319 Jul · 18:42 UTC
SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root accesscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited by UTA0533 for root access

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Specific vulnerable versions not disclosed. All SMA 1000 deployments should be considered at risk until vendor guidance is available.

SonicWall19 Jul · 11:18 UTC
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".

WordPress18 Jul · 15:22 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress17 Jul · 19:20 UTC