Cybersecurity
204 articles RSS
Ivanti Patches CVE-2026-6973 Zero-Day in EPMM as CISA Adds Authenticated Admin RCE Bug to KEV
Ivanti disclosed an actively exploited authenticated RCE in Endpoint Manager Mobile alongside four other high-severity flaws. CISA added it to KEV on May 7 with a May 10 federal patch deadline.
Apache patches a double-free in HTTP/2 that crashes workers with two frames and one TCP connection
Apache HTTP Server 2.4.67 fixes CVE-2026-23918, a double-free in mod_http2 that triggers on early stream reset and may enable remote code execution on Debian-default builds.
Palo Alto Networks Discloses CVE-2026-0300, a 9.3 PAN-OS Captive Portal RCE Exploited Since April 9 With Patches Starting May 13
Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow in PAN-OS that grants unauthenticated root code execution and has been exploited in the wild since April 9. CISA added it to KEV on May 6 with a May 9 federal deadline; first fixes ship May 13.
Critical cPanel Authentication Bypass CVE-2026-41940 Exploited as Zero-Day for Two Months Before April 28 Patch
A CVSS 9.8 CRLF-injection bug in cPanel and WHM let unauthenticated attackers gain root, exploited since February 23 against roughly 1.5 million exposed servers and now weaponized against governments in Southeast Asia.
OpenSSH Patches a 15-Year-Old Comma-Parsing Bug That Could Promote Certificate Holders to Root
CVE-2026-35414 lets a comma in an SSH certificate principal slip past authorized_keys access controls, granting root on vulnerable servers. OpenSSH 10.3 ships the fix.
Instructure Confirms Canvas Data Breach as ShinyHunters Claims 275 Million Records From 9,000 Schools
Instructure says names, email addresses, student IDs and user messages were exposed in a breach disclosed May 1. ShinyHunters then listed the firm on its leak site, claiming 3.65 TB of data tied to 275 million people at close to 9,000 institutions.
PyTorch Lightning Compromised on PyPI as Attackers Push Two Malicious Versions Designed to Harvest Cloud Credentials
Attackers published lightning 2.6.2 and 2.6.3 to PyPI on April 30, executing an obfuscated JavaScript payload to harvest cloud credentials from anyone who imported the package. Maintainers quarantined the malicious builds within 42 minutes.
Copy Fail: A 732-Byte Python Script Gives Local Root on Every Major Linux Distro Since 2017, and CISA Orders Federal Agencies to Patch by May 15
CVE-2026-31431, discovered by Theori using its AI scanner Xint Code, lets unprivileged users root Ubuntu, Amazon Linux, RHEL, and SUSE through a logic flaw in the kernel's crypto subsystem.
GitHub Discloses Critical Git Push RCE That Could Have Exposed Millions of Private Repositories, With 88 Percent of Self-Hosted Servers Still Unpatched
CVE-2026-3854 let any authenticated user run code on GitHub's backend with a single git push. GitHub patched github.com in two hours on March 4; public disclosure on April 28 found most Enterprise Server instances still vulnerable.
CISA Adds SimpleHelp, Samsung MagicINFO, and End-of-Life D-Link Flaws to KEV Catalog as DragonForce Ransomware and Mirai Botnets Exploit Them in the Wild
CISA's April 24 KEV update flags four actively exploited vulnerabilities tied to ransomware against managed service providers and Mirai DDoS botnets, with a May 8 federal patching deadline.
CISA Adds Windows Shell and ConnectWise ScreenConnect Flaws to KEV After Microsoft's April Patch Failed to Mark Zero-Click Bug as Exploited
CISA added CVE-2026-32202 and CVE-2024-1708 to the Known Exploited Vulnerabilities catalog on April 28, giving federal agencies until May 12 to patch a zero-click NTLM coercion flaw whose Patch Tuesday entry carried no exploitation marker.
Marimo Python Notebook Pre-Auth RCE Weaponized 9 Hours After Disclosure as CISA Adds CVE to KEV Catalog
An unauthenticated WebSocket flaw in the popular Marimo notebook (CVE-2026-39987, CVSS 9.3) was weaponized within 9 hours 41 minutes of disclosure, with credential theft completed in under three minutes. CISA has since added the bug to its KEV catalog with a May 7 federal deadline.