CISA has added the actively exploited Microsoft SharePoint vulnerability CVE 2026 58644 to its Known Exploited Vulnerabilities catalog and urged organizations to apply security updates immediately.
Cybersecurity researchers have identified six vulnerabilities in protobuf.js that could expose Node.js applications to remote code execution and denial of service attacks, impacting cloud services, AI systems, and CI/CD pipelines.
Microsoft has released patches for a record 206 security vulnerabilities, including three publicly disclosed zero day flaws and several critical remote code execution risks affecting Windows systems.
Cybersecurity researchers disclose a critical 18 year old NGINX vulnerability, CVE-2026-42945, enabling unauthenticated remote code execution through crafted HTTP requests.
Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.
A critical Weaver E-cology vulnerability CVE 2026 22679 is being actively exploited, enabling unauthenticated remote code execution through debug API endpoints affecting enterprise systems globally.
A critical Marimo RCE flaw CVE-2026-39987 was exploited within hours of disclosure, enabling unauthenticated shell access and rapid credential theft activity.
A zero day vulnerability in Adobe Reader has been actively exploited via malicious PDF files since December 2025, enabling data theft, payload delivery, and potential remote execution.
Flowise AI platform suffers a critical CVSS 10.0 code injection vulnerability, exposing over 12,000 instances to remote code execution and full system compromise.
A critical Magento vulnerability named PolyShell exposes stores to unauthenticated file uploads, remote code execution, and account takeover risks, with active exploitation now observed.