Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 340 results
Active filter:tag: #critical✕ clear
HPE patches critical RCE in ArubaOS-CX network switches (CVE-2026-73749)criticalbug_reportVulnerability
bug_reportVulnerability

HPE patches critical RCE in ArubaOS-CX network switches (CVE-2026-73749)

ArubaOS-CX network operating system on HPE Aruba enterprise switches. Affected versions: 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, 10.10.1180 and earlier.

Hewlett Packard Enterprise3 Sep · 16:28 UTC
Cisco patches critical RCE in Nexus 9000 and 7 IOS XR umbrella CVEscriticalbug_reportVulnerability
bug_reportVulnerability

Cisco patches critical RCE in Nexus 9000 and 7 IOS XR umbrella CVEs

Cisco Silicon One-based Nexus 9000 switches (10 models, NX-OS 10.3(1) through 10.6(3s)) via CVE-2026-20212. All Cisco IOS XR releases across all platforms via 7 umbrella CVEs (CVE-2026-20274 through 20280), including XR7 (LNT) platforms: Cisco 8000 S…

CVE-2026-202123 Sep · 13:52 UTC
Elementor Pro CVE-2026-32475 actively exploited for webshell uploadscriticalbug_reportVulnerability
bug_reportVulnerability

Elementor Pro CVE-2026-32475 actively exploited for webshell uploads

Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.

CVE-2026-324753 Sep · 12:52 UTC
SonicWall SMA 1000 SSRF flaw (CVE-2026-83548) exploited in the wildcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 SSRF flaw (CVE-2026-83548) exploited in the wild

SonicWall SMA 1000 Appliances. CVE-2026-83548 is a server-side request forgery (SSRF) vulnerability with CVSS 10.0, allowing remote unauthenticated attackers to gain unauthorized access. Specific affected versions not disclosed.

CVE-2026-835483 Sep · 03:19 UTC
Sangoma Switchvox SQL injection exploited for remote code executioncriticalbug_reportVulnerability
bug_reportVulnerability

Sangoma Switchvox SQL injection exploited for remote code execution

Sangoma Switchvox VoIP platform versions prior to 8.4.0.2. Approximately 4,000 internet-exposed instances globally, primarily in the United States. Vulnerability CVE-2026-9586 affects the unauthenticated /pa HTTP endpoint.

CVE-2026-95862 Sep · 19:00 UTC
All-in-One WP Migration plugin SQL injection enables site takeovercriticalbug_reportVulnerability
bug_reportVulnerability

All-in-One WP Migration plugin SQL injection enables site takeover

All-in-One WP Migration and Backup plugin for WordPress, versions through 7.109. Over 5 million active installations, with approximately 3.25 million sites (65%) still running vulnerable versions. Fixed in version 7.110.

All-in-One WP Migration and Backup2 Sep · 17:28 UTC
JFrog Artifactory auth bypass exploited to forge admin tokenscriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass exploited to forge admin tokens

JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.

CVE-2026-823292 Sep · 13:47 UTC
SonicWall SMA1000 RCE vulnerabilities under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 RCE vulnerabilities under active exploitation

SonicWall SMA1000 series appliances. Specific vulnerable versions not disclosed in available information. Vulnerabilities enable remote code execution.

SonicWall2 Sep · 13:39 UTC
Langflow RCE vulnerability under active exploitation, patch immediatelycriticalbug_reportVulnerability
bug_reportVulnerability

Langflow RCE vulnerability under active exploitation, patch immediately

Langflow (specific versions not disclosed in available data). The vulnerability affects Langflow installations exposed to network access. No CVE assigned yet.

Langflow2 Sep · 13:35 UTC
BGP hijack delivers malicious Virtualizor update with root backdoorcriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor update with root backdoor

Virtualizor hypervisor management software (all versions) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC. Any installation that checked for updates during this period may be compromised.

Virtualizor2 Sep · 11:12 UTC
SonicWall SMA 1000 VPN zero-days exploited in chained attackscriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA 1000 VPN zero-days exploited in chained attacks

SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances: models 6210, 7210, and 8200v running versions 12.4.3-03453 and older, or 12.5.0-02835 and older.

CVE-2026-835482 Sep · 08:53 UTC
GeoNetwork RCE chain exploitable without authentication on gov geoportalscriticalbug_reportVulnerability
bug_reportVulnerability

GeoNetwork RCE chain exploitable without authentication on gov geoportals

GeoNetwork open-source geospatial metadata catalog: all 4.4.x versions up to 4.4.11 and all 4.2.x versions up to 4.2.16. Widely deployed in government, military, and national agency Spatial Data Infrastructure backends across 39 countries, including…

GeoNetwork2 Sep · 07:18 UTC
SonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCEcriticalbug_reportVulnerability
bug_reportVulnerability

SonicWall SMA1000 zero-days CVE-2026-83548/83549 chained for RCE

SonicWall SMA1000 appliances (models 6210, 7210, 8200v). Does not affect SSL-VPN on SonicWall firewalls or SMA 100 Series. Approximately 400+ appliances exposed online per Shadowserver tracking.

SonicWall2 Sep · 04:39 UTC
Dark Web Service Sells 153M+ Driver Licenses from Identity Verification Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

Dark Web Service Sells 153M+ Driver Licenses from Identity Verification Breach

The threat actor operates "Nexus," a dark web identity theft service launched on the Russian cybercrime forum Exploit in August 2025. The operator claims to have continuously exfiltrated data for over a year from an alleged breach at a major Louisian…

identity verification company based in Louisiana1 Sep · 20:40 UTC
Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentialscriticalbug_reportVulnerability
bug_reportVulnerability

Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentials

Langflow versions 1.4.2 and earlier. The vulnerability exists in the code validator of the custom component editor's validate endpoint. Patched in version 1.11.6.

CVE-2026-07681 Sep · 15:54 UTC
JFrog Artifactory auth bypass CVE-2026-82329 under active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory auth bypass CVE-2026-82329 under active exploitation

JFrog Artifactory versions 7.161.0-7.161.19, 7.146.0-7.146.36, 7.133.0-7.133.28, 7.125.0-7.125.19, 7.117.0-7.117.27, and 7.111.4-7.111.21. Affects default configurations of self-managed instances. JFrog Access component specifically vulnerable.

CVE-2026-823291 Sep · 15:53 UTC
JFrog Artifactory authentication bypass requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

JFrog Artifactory authentication bypass requires immediate patching

JFrog Artifactory - specific affected versions not disclosed in advisory. Authentication bypass vulnerability allows unauthorized access to artifact repository.

JFrog1 Sep · 13:13 UTC
BGP hijack delivers malicious Virtualizor updates to VPS management systemscriticalbug_reportVulnerability
bug_reportVulnerability

BGP hijack delivers malicious Virtualizor updates to VPS management systems

Virtualizor VPS management software (all versions prior to 3.2.9.9) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC.

Virtualizor1 Sep · 12:45 UTC
Langflow and Ruby on Rails flaws actively exploited for RCE and C2criticalbug_reportVulnerability
bug_reportVulnerability

Langflow and Ruby on Rails flaws actively exploited for RCE and C2

Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…

CVE-2026-07681 Sep · 05:22 UTC
Critical WordPress plugin flaws enable auth bypass and RCE on popular sitescriticalbug_reportVulnerability
bug_reportVulnerability

Critical WordPress plugin flaws enable auth bypass and RCE on popular sites

WPMU DEV Dashboard plugin ≤5.0.1 (CVE-2026-76581), Avada theme ≤7.16 with Fusion Builder ≤3.16 (CVE-2026-18431), TranslatePress ≤3.3.1 with specific config (CVE-2026-19632), Pods plugin ≤3.3.9 (CVE-2026-19598), GiveWP plugin ≤4.16.7.1 (CVE-2026-82222…

CVE-2026-7658129 Aug · 14:25 UTC
ShinyHunters Claims 284M Patient Records from McKesson Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

ShinyHunters Claims 284M Patient Records from McKesson Breach

ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations targeting organizations with valuable databases.

McKesson28 Aug · 20:40 UTC
Cosmos EVM balance flaw exploited on six chains after delayed patchcriticalbug_reportVulnerability
bug_reportVulnerability

Cosmos EVM balance flaw exploited on six chains after delayed patch

Cosmos EVM module versions < 0.6.2 and >= 0.7.0 < 0.7.2. All blockchains running Cosmos EVM with permissionless vesting account creation are vulnerable. Six chains were exploited August 20–25, 2026. Fixed in v0.6.2 and v0.7.2 (released August 19).

Cosmos Labs28 Aug · 18:38 UTC
PaperCut NG/MF actively exploited; second emergency patch releasedcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF actively exploited; second emergency patch released

PaperCut NG and MF print management software versions 24, 25, and 26 on Windows, Linux, and macOS. CVE-2026-81578 (CVSS 8.8) authentication bypass and CVE-2026-82078 (CVSS 9.4) unsafe class-loading vulnerability can be chained for pre-auth RCE.

PaperCut28 Aug · 17:08 UTC
GiveWP WordPress plugin RCE allows unauthenticated server takeovercriticalbug_reportVulnerability
bug_reportVulnerability

GiveWP WordPress plugin RCE allows unauthenticated server takeover

GiveWP WordPress donation plugin versions 4.16.6 through 4.16.7.1. Over 100,000 active installations. Exploitation requires legacy donation forms without 'formBuilderSettings' (common in upgraded sites or when using option-based form editor).

GiveWP28 Aug · 16:18 UTC
PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitationcriticalbug_reportVulnerability
bug_reportVulnerability

PaperCut NG/MF flaws chained for unauthenticated RCE, active exploitation

PaperCut NG and PaperCut MF (all unpatched versions). CVE-2026-81578 (CVSS 8.8, improper access control) and CVE-2026-82078 (CVSS 9.4, unsafe dynamic class loading) are chained to bypass authentication and execute arbitrary Java code.

PaperCut28 Aug · 15:12 UTC
ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippinescriticalbug_reportVulnerability
bug_reportVulnerability

ownCloud CVE-2023-49105 exploited to steal nuclear records from Philippines

ownCloud core versions 10.6.0 through 10.13.0. The vulnerability is a WebDAV API authentication bypass allowing unauthenticated file access when usernames are known and no signing-key is configured (default state). Fixed in version 10.13.1.

CVE-2023-4910528 Aug · 13:56 UTC
Critical vulnerabilities in PaperCut software require immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Critical vulnerabilities in PaperCut software require immediate patching

PaperCut software (specific versions not disclosed in advisory). Affects organizations using PaperCut print management solutions.

PaperCut28 Aug · 13:03 UTC
ServiceNow platforms face critical vulnerabilities requiring urgent patchingcriticalbug_reportVulnerability
bug_reportVulnerability

ServiceNow platforms face critical vulnerabilities requiring urgent patching

ServiceNow platforms (specific versions not disclosed in advisory). Scope and affected components not detailed in available information.

ServiceNow28 Aug · 12:09 UTC
8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004criticalbug_reportVulnerability
bug_reportVulnerability

8,300+ Gitea servers unpatched against exploited RCE flaw CVE-2026-60004

Gitea versions prior to 1.27.1. Over 8,300 Internet-exposed instances remain vulnerable. Affects self-hosted Gitea installations with default open registration enabled.

Gitea28 Aug · 10:58 UTC
Unitree G1 EDU robot vulnerable to dual root RCE via network and BLEcriticalbug_reportVulnerability
bug_reportVulnerability

Unitree G1 EDU robot vulnerable to dual root RCE via network and BLE

Unitree G1 EDU humanoid robot. Firmware versions not definitively confirmed; researcher tested V1.5.2. G1 (non-EDU) and other Unitree robot models have unconfirmed applicability. Both vulnerabilities grant root access on the Locomotion PC.

CVE-2026-7663928 Aug · 10:07 UTC