Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
Security researchers are warning of widespread exploitation of two critical WordPress vulnerabilities that allow unauthenticated remote code execution and complete website compromise.
CISA has added the actively exploited Microsoft SharePoint vulnerability CVE 2026 58644 to its Known Exploited Vulnerabilities catalog and urged organizations to apply security updates immediately.
Cybersecurity researchers have identified six vulnerabilities in protobuf.js that could expose Node.js applications to remote code execution and denial of service attacks, impacting cloud services, AI systems, and CI/CD pipelines.
Microsoft has released patches for a record 206 security vulnerabilities, including three publicly disclosed zero day flaws and several critical remote code execution risks affecting Windows systems.
Cybersecurity researchers disclose a critical 18 year old NGINX vulnerability, CVE-2026-42945, enabling unauthenticated remote code execution through crafted HTTP requests.
Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.
A critical Weaver E-cology vulnerability CVE 2026 22679 is being actively exploited, enabling unauthenticated remote code execution through debug API endpoints affecting enterprise systems globally.
A critical Marimo RCE flaw CVE-2026-39987 was exploited within hours of disclosure, enabling unauthenticated shell access and rapid credential theft activity.
A zero day vulnerability in Adobe Reader has been actively exploited via malicious PDF files since December 2025, enabling data theft, payload delivery, and potential remote execution.
Flowise AI platform suffers a critical CVSS 10.0 code injection vulnerability, exposing over 12,000 instances to remote code execution and full system compromise.