Microsoft says CVE-2026-69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no ...
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing ...
The type confusion vulnerability allows a guest-to-host sandbox escape which can lead to remote code execution ...
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote ...
The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. A critical-severity type ...
CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical ...
A critical zero-day vulnerability in Microsoft SharePoint is being exploited in the wild right now, and more than 1,300 servers remain exposed to the public internet with no patch applied. The flaw, ...
Microsoft’s SharePoint Server Remote Code Execution has been identified as containing a zero-day vulnerability. A zero-day is a vulnerability or security hole in a computer system unknown to its ...
A critical Telnet vulnerability with a CVSS rating of 9.8 enables attackers to take full control of affected systems before authentication even kicks in, security researchers at Dream Security have ...
WordPress has patched CVE-2026-65640, a high-severity vulnerability that allows authenticated attackers to execute arbitrary code.
Developers of the popular Exim email server software released an emergency update on Friday to address a critical vulnerability that could allow attackers to execute malicious code on the underlying ...
A flaw in Hugging Face Transformers could allow malicious AI models to execute code, exposing credentials and highlighting AI supply chain risks. Organizations using vulnerable versions of the Hugging ...