Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-20 · 02:03 UTC
articleTotal: 593 reports

Filtered Reports

30 / 160 results
Active filter:✕ clear
WordPress Core RCE "wp2shell" exploits now public, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

WordPress Core RCE "wp2shell" exploits now public, patch immediately

WordPress Core (specific versions not disclosed in provided data). Scope appears to be remote code execution vulnerabilities in core WordPress installation.

WordPress15:22 UTC
WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update activecriticalbug_reportVulnerability
bug_reportVulnerability

WordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active

WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.

WordPress19:20 UTC
DigiCert breach linked to Chinese APT; code-signing certs stolencriticalbug_reportVulnerability
bug_reportVulnerability

DigiCert breach linked to Chinese APT; code-signing certs stolen

DigiCert certificate authority infrastructure compromised in April 2026. Code-signing certificates stolen by CylindricalCanine (GoldenEyeDog/APT-Q-27 subgroup).

DigiCert14:39 UTC
Windows zero-day LegacyHive enables privilege escalation on patched systemscriticalbug_reportVulnerability
bug_reportVulnerability

Windows zero-day LegacyHive enables privilege escalation on patched systems

All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.

Microsoft09:05 UTC
Siemens ROX II OT switches vulnerable to chained zero-day privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Siemens ROX II OT switches vulnerable to chained zero-day privilege escalation

Siemens ROX II industrial switches used in operational technology (OT) environments. Specific affected firmware versions not disclosed in summary. Vulnerability chain enables privilege escalation to persistent root access.

Siemens08:00 UTC
CISA orders patching of actively exploited Fortinet FortiSandbox flawscriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Fortinet FortiSandbox flaws

Fortinet FortiSandbox threat detection platform. Specific versions not provided in available data. Two vulnerabilities confirmed, CVE identifiers not yet disclosed.

Fortinet05:03 UTC
CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited

Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.

CVE-2026-5864404:42 UTC
Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0criticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches critical flaws in UniFi products, CVE-2026-50746 CVSS 10.0

Ubiquiti UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. Specific vulnerable versions not provided in available data. CVE-2026-50746 rated CVSS 10.0 (critical).

CVE-2026-5074612:38 UTC
CISA orders federal patch for exploited Langflow auth bypass by Fridaycriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders federal patch for exploited Langflow auth bypass by Friday

Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.

Langflow07:58 UTC
Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCEcriticalbug_reportVulnerability
bug_reportVulnerability

Ubiquiti patches 7 critical flaws in UniFi OS, including max-severity RCE

Ubiquiti UniFi OS - specific vulnerable versions not disclosed. Seven critical vulnerabilities patched, including one maximum-severity (CVSS 10.0) command injection flaw enabling remote code execution.

Ubiquiti06:15 UTC
CISA orders patching of actively exploited Adobe ColdFusion flawcriticalbug_reportVulnerability
bug_reportVulnerability

CISA orders patching of actively exploited Adobe ColdFusion flaw

Adobe ColdFusion commercial web application development platform. Specific affected versions not disclosed in summary, but CISA mandatory patching order indicates government-facing installations are priority targets.

Adobe05:16 UTC
15-year-old Linux kernel flaw allows local privilege escalation to rootcriticalbug_reportVulnerability
bug_reportVulnerability

15-year-old Linux kernel flaw allows local privilege escalation to root

Linux kernel versions since 2011 across all mainstream distributions (Ubuntu, RHEL, Debian, SUSE, etc.). Any system running an unpatched kernel containing CVE-2026-43499 is vulnerable. Requires local authenticated access to exploit.

CVE-2026-4349904:16 UTC
Google Dialogflow CX flaw lets attackers hijack agents in same GCP projectcriticalbug_reportVulnerability
bug_reportVulnerability

Google Dialogflow CX flaw lets attackers hijack agents in same GCP project

Google Dialogflow CX agents with Code Block feature enabled, within shared Google Cloud projects. Requires attacker to have edit rights on at least one agent in the project.

Google14:37 UTC
Writer AI platform session isolation flaw enables cross-tenant accesscriticalbug_reportVulnerability
bug_reportVulnerability

Writer AI platform session isolation flaw enables cross-tenant access

Writer enterprise AI platform. Specific affected versions not disclosed. Vulnerability impacts agent preview functionality allowing cross-tenant session token leakage and unauthorized access.

Writer11:27 UTC
BeyondTrust RS and PRA authentication bypass flaws require patchingcriticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust RS and PRA authentication bypass flaws require patching

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software. Specific affected versions not provided in available data.

BeyondTrust06:12 UTC
Tenda router backdoor allows admin access bypass (CVE-2026-11405)criticalbug_reportVulnerability
bug_reportVulnerability

Tenda router backdoor allows admin access bypass (CVE-2026-11405)

Tenda routers running vulnerable firmware versions. Specific models and version ranges not disclosed in available data. Affects web management interface authentication mechanism.

CVE-2026-1140504:40 UTC
BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)criticalbug_reportVulnerability
bug_reportVulnerability

BeyondTrust Remote Support/PRA critical auth bypass (CVE-2026-40138)

BeyondTrust Remote Support and Privileged Remote Access (PRA) products. Specific affected versions not provided in available data. CVE-2026-40138 is a pre-authentication vulnerability with CVSS 9.2.

CVE-2026-4013803:16 UTC
16-year KVM hypervisor flaw enables guest-to-host kernel corruptioncriticalbug_reportVulnerability
bug_reportVulnerability

16-year KVM hypervisor flaw enables guest-to-host kernel corruption

Linux KVM hypervisor on Intel and AMD x86 systems. All Linux kernel versions containing the vulnerable shadow MMU code (approximately 16 years of releases).

CVE-2026-5335915:37 UTC
Gitea Docker auth bypass under active probing (CVE-2026-20896)criticalbug_reportVulnerability
bug_reportVulnerability

Gitea Docker auth bypass under active probing (CVE-2026-20896)

Gitea Docker images with improper X-WEBAUTH-USER header validation. Specific vulnerable versions not provided; affects deployments trusting reverse proxy authentication headers without IP restrictions.

CVE-2026-2089614:28 UTC
Adobe ColdFusion CVE-2026-48282 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

Adobe ColdFusion CVE-2026-48282 under active exploitation

Adobe ColdFusion (specific versions not disclosed). Maximum severity vulnerability actively exploited in the wild.

CVE-2026-4828211:18 UTC
Linux kernel "Bad Epoll" flaw grants unprivileged root accesscriticalbug_reportVulnerability
bug_reportVulnerability

Linux kernel "Bad Epoll" flaw grants unprivileged root access

Linux kernel (version range not specified) on desktops, servers, and Android devices. Affects both traditional Linux distributions and Android-based systems. Exploitable by unprivileged local users.

CVE-2026-4624217:40 UTC
JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attackcriticalperson_alertThreat Actor
person_alertThreat Actor

JADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack

JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…

Langflow07:13 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-4565903:46 UTC
Argo CD repo-server RCE enables cluster takeover, no patch availablecriticalbug_reportVulnerability
bug_reportVulnerability

Argo CD repo-server RCE enables cluster takeover, no patch available

Argo CD repo-server component, all versions (specific affected versions not disclosed). Exploitation requires access to internal network port where repo-server listens.

Argo CD17:40 UTC
Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classiccriticalbug_reportVulnerability
bug_reportVulnerability

Adobe patches CVSS 10.0 flaws in ColdFusion and Campaign Classic

Adobe ColdFusion and Adobe Campaign Classic (specific versions not provided). Vulnerabilities include arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass.

Adobe13:25 UTC
Cursor AI editor vulnerable to sandbox escape via prompt injectioncriticalbug_reportVulnerability
bug_reportVulnerability

Cursor AI editor vulnerable to sandbox escape via prompt injection

Cursor AI code editor, all versions prior to patch. Both CVE-2026-50548 (CVSS 9.8) and CVE-2026-50549 (CVSS 9.3) enable sandbox escape and arbitrary command execution via prompt injection without user interaction.

CVE-2026-5054812:42 UTC
Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)criticalbug_reportVulnerability
bug_reportVulnerability

Progress Kemp LoadMaster RCE under active exploitation (CVE-2026-8037)

Progress Kemp LoadMaster load balancers. Specific affected versions not disclosed. Pre-authentication vulnerability allows unauthenticated remote attackers to execute OS commands.

CVE-2026-803711:56 UTC
900+ Oracle E-Business Suite instances exposed, under active attackcriticalbug_reportVulnerability
bug_reportVulnerability

900+ Oracle E-Business Suite instances exposed, under active attack

Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.

Oracle10:30 UTC
Langflow RCE (CVE-2026-33017) actively exploited for cryptominingcriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE (CVE-2026-33017) actively exploited for cryptomining

Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.

CVE-2026-3301713:47 UTC
SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wildcriticalbug_reportVulnerability
bug_reportVulnerability

SimpleHelp OpenID auth bypass (CVE-2026-48558) exploited in wild

SimpleHelp remote support software, all versions using OpenID Connect authentication. CVE-2026-48558 is a critical authentication bypass (CVSS 10.0) in the OpenID Connect flow.

CVE-2026-4855809:18 UTC