Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 307 results
Active filter:tag: #critical✕ clear
Siemens ROX II OT switches vulnerable to chained zero-day privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Siemens ROX II OT switches vulnerable to chained zero-day privilege escalation

Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.

Siemens17 Jul · 08:00 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet17 Jul · 05:03 UTC
CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited

Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.

CVE-2026-5864417 Jul · 04:42 UTC
CISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalogcriticalbug_reportVulnerability
bug_reportVulnerability

CISA adds CVE-2023-4346 KNX Protocol flaw to KEV catalog

KNX Protocol implementations used in building automation and smart home systems. Specific affected products and versions not disclosed in available information.

CVE-2023-434616 Jul · 13:26 UTC
Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0criticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0

Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).

CVE-2026-507468 Jul · 12:38 UTC
CISA orders federal patch for exploited Langflow auth bypass by Fridaycriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Langflow auth bypass by Friday

Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.

Langflow8 Jul · 07:58 UTC
Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE

Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.

Ubiquiti8 Jul · 06:15 UTC
CISA orders patching of actively exploited Adobe ColdFusion flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Adobe ColdFusion flaw

Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.

Adobe8 Jul · 05:16 UTC
15-year-old Linux kernel flaw allows local privilege escalation to rootcriticalbug_reportVulnerability
bug_reportVulnerability

15-year-old Linux kernel flaw allows local privilege escalation to root

Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.

CVE-2026-434998 Jul · 04:16 UTC
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google7 Jul · 14:37 UTC
Writer AI platform session isolation flaw enables cross-tenant accesscriticalbug_reportVulnerability
bug_reportVulnerability

Writer AI platform session isolation flaw enables cross-tenant access

Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.

Writer7 Jul · 11:27 UTC
BeyondTrust RS and PRA authentication bypass flaws require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust RS and PRA authentication bypass flaws require patching

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.

BeyondTrust7 Jul · 06:12 UTC
Tenda router backdoor allows admin access bypass (CVE-2026-11405)criticalbug_reportVulnerability
bug_reportVulnerability

Tenda router backdoor allows admin access bypass (CVE-2026-11405)

Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.

CVE-2026-114057 Jul · 04:40 UTC
BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)criticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)

BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.

CVE-2026-401387 Jul · 03:16 UTC
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-533596 Jul · 15:37 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-208966 Jul · 14:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-482826 Jul · 11:18 UTC
Linux kernel "Bad Epoll" flaw grants unprivileged root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel "Bad Epoll" flaw grants unprivileged root access

Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.

CVE-2026-462423 Jul · 17:40 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow2 Jul · 07:13 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-456592 Jul · 03:46 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD1 Jul · 17:40 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe1 Jul · 13:25 UTC
Cursor AI editor vulnerable to sandbox escape via prompt injectioncriticalbug_reportVulnerability
bug_reportVulnerability

Cursor AI editor vulnerable to sandbox escape via prompt injection

Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.

CVE-2026-505481 Jul · 12:42 UTC
Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)criticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)

Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.

CVE-2026-80371 Jul · 11:56 UTC
900+ Oracle E-Business Suite instances exposed, under active attackcriticalbug_reportVulnerability
bug_reportVulnerability

900+ Oracle E-Business Suite instances exposed, under active attack

Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.

Oracle1 Jul · 10:30 UTC
Langflow RCE (CVE-2026-33017) actively exploited for cryptominingcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE (CVE-2026-33017) actively exploited for cryptomining

Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.

CVE-2026-3301730 Jun · 13:47 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855830 Jun · 09:18 UTC
Dell Wyse RCE flaw exploitable by low-privileged attackerscriticalbug_reportVulnerability
bug_reportVulnerability

Dell Wyse RCE flaw exploitable by low-privileged attackers

Dell Wyse thin client products. Specific affected models and firmware versions not disclosed in summary. Vulnerability enables remote code execution with low privilege requirements.

Dell29 Jun · 13:04 UTC
SimpleHelp CVE-2026-48558 exploited to deploy Djinn Stealer malwarecriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp CVE-2026-48558 exploited to deploy Djinn Stealer malware

SimpleHelp remote support software (specific versions not disclosed). Affects organizations using SimpleHelp for remote access and support operations across Windows, macOS, and Linux environments.

CVE-2026-4855829 Jun · 12:00 UTC
Oracle E-Business Suite under active exploit via CVE-2026-46817criticalbug_reportVulnerability
bug_reportVulnerability

Oracle E-Business Suite under active exploit via CVE-2026-46817

Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.

CVE-2026-4681729 Jun · 11:46 UTC