Vulnerabilities
89 articles RSS
ShinyHunters Exploited an Oracle PeopleSoft Zero-Day for Two Weeks Before Disclosure as CVE-2026-35273 Lands on CISA's KEV Catalog
CVE-2026-35273, a CVSS 9.8 missing-authentication flaw in Oracle PeopleSoft PeopleTools, was exploited as a zero-day by UNC6240 before Oracle shipped mitigations and CISA set a June 15 federal deadline.
ServiceNow Patches an Unauthenticated API Endpoint That Let Customer Instance Tables Be Queried Without Credentials
ServiceNow fixed a REST API endpoint that shipped without authentication, after confirming a subset of customer instances were queried. It has not assigned a CVE.
Microsoft Ships Its Largest Patch Tuesday on Record, Led by a Wormable CVSS 9.8 Windows Kernel Flaw
June 2026's update tops the previous record of 177 CVEs and includes CVE-2026-45657, a wormable 9.8 kernel use-after-free.
Check Point Patches Critical VPN Zero-Day CVE-2026-50751 After a Month of Exploitation Tied to a Qilin Ransomware Affiliate
A logic flaw in Check Point's deprecated IKEv1 certificate validation let attackers bypass VPN authentication. CISA added it to KEV with a June 11 deadline.
Critical Everest Forms Pro WordPress Flaw CVE-2026-3300 Exploited for Two Months as Wordfence Blocks 29,300 Attacks
An unauthenticated PHP code-injection bug in the Everest Forms Pro plugin, patched in March, has been exploited since April 13 to plant rogue administrator accounts on WordPress sites.
Microsoft Discloses CVE-2026-45497, a Command-Injection RCE in 365 Copilot Already Fixed Server-Side With No Customer Action
Microsoft rated the Copilot command-injection flaw Critical, with a 7.7 CVSS base score. It was already mitigated in the cloud and not exploited.
Cisco Discloses Another Exploited SD-WAN Manager Zero-Day, CVE-2026-20245, With No Patch Yet and a Crafted File Path to Root
Cisco says CVE-2026-20245, a 7.8-rated command-injection flaw in Catalyst SD-WAN Manager, is being exploited to gain root. No patch or workaround is available; Mandiant reported it.
CISA Adds Four-Year-Old Linux Kernel cgroups Container-Escape Flaw CVE-2022-0492 to KEV Catalog Citing Active Exploitation
CISA added the 2022 Linux kernel cgroups release_agent flaw CVE-2022-0492 to its KEV catalog on June 2, 2026, with a June 5 federal patch deadline.
Google Confirms Limited Exploitation of an Android Framework Integer-Overflow Flaw, CVE-2025-48595, in June Security Bulletin
Google's June 2026 Android update patches a Framework privilege-escalation zero-day under limited, targeted exploitation. CISA added it to the KEV catalog with a June 5 federal deadline.
Belgium's Cyber Agency Says Critical Windows Netlogon Flaw CVE-2026-41089 Is Now Being Exploited — Microsoft Disputes It
Belgium's CCB warns the 9.8-rated Netlogon RCE is exploited in the wild, threatening domain controllers. Microsoft says it has no evidence.
Attackers Exploit CVE-2026-35616 in FortiClient EMS to Deploy EKZ Infostealer Disguised as a Fortinet Patch
Arctic Wolf found attackers abusing a critical 9.8-CVSS FortiClient EMS authentication bypass to silently push EKZ Infostealer to every managed endpoint via legitimate VPN scripting workflows.
Trend Micro Patches Apex One Zero-Day CVE-2026-34926 Exploited in the Wild, CISA Orders Federal Agencies to Patch by June 4
A directory traversal flaw in Trend Micro Apex One lets an attacker with admin server access inject malicious code into managed endpoints. CISA added it to KEV on May 21 with a June 4 federal deadline.