Blog
CVE-2026-19478 (CVSS 9.4): GitLab Critical GraphQL Flaw Lets Unauthenticated Attackers Delete Your Entire DevOps Pipeline — Emergency Patch Now
CVE-2026-19478 (CVSS 9.4): An unauthenticated attacker can remotely modify or delete public GitLab CE/EE projects via a malicious GraphQL directive. Emergency patch released 17 Aug 2026.
Read More →CVE-2026-59310 (CVSS 9.8): APT Actors Exploit VMware vCenter Syslog Flaw to Root 361 Servers Across 47 Countries — Patch VMSA-2026-0006 Now
CVE-2026-59310 (CVSS 9.8) in VMware vCenter's Syslog server lets unauthenticated attackers execute code remotely. A China-nexus APT rooted 361 servers across 47 countries within 5 days of Broadcom's patch.
Read More →CVE-2026-58231 (CVSS 10.0): SAP Commerce Cloud Zero-Auth RCE Exploited Within 72 Hours of Patch — 4,200+ Exposed Instances Globally
CVE-2026-58231, a CVSS 10.0 unauthenticated RCE in SAP Commerce Cloud’s Data Hub Adapter, is actively exploited — just 72 hours after SAP’s patch. 4,200+ internet-exposed instances remain at risk.
Read More →CVE-2026-65400 (CVSS 9.8): macOS Screen Sharing Zero-Auth Bypass Hands Attackers Root Access — CISA Rescores After Active Monero Mining Rampage
CVE-2026-65400 lets unauthenticated network attackers bypass macOS Screen Sharing to gain root access. CISA rescored from 7.1 to 9.8 after confirmed Monero cryptominer deployments on ~40,000 exposed hosts. Patch now.
Read More →CVE-2026-53413 ‘ZOOMSDAY’: Any Zoom Meeting Participant Can Zero-Click Seize Every Device — AI Built the Working Exploit in 24 Hours
ZOOMSDAY (CVE-2026-53413, CVSS 8.3) lets any Zoom meeting participant silently execute code on every other device — zero click, all platforms. Patch to Zoom 7.1.5 now. Expert defensive guide for…
Read More →GHSA-mqjf-5f49-2fjh (CVSS 9.8): GeoServer PostGIS jsonArrayContains SQL Injection Enables Unauthenticated RCE — Hundreds of Exploitation Attempts Within Hours of Disclosure
An unpatched CVSS 9.8 SQL injection in GeoServer's PostGIS jsonArrayContains OGC filter enables unauthenticated remote code execution. Active exploitation began within hours of public disclosure.
Read More →CVE-2026-42897 (CVSS 8.1): Laundry Bear’s OWAReaper Lives Inside Your Mailbox — Survives Password Reset and Complete Device Rebuild
Laundry Bear’s OWAReaper backdoor exploits CVE-2026-42897 in Microsoft Exchange OWA to steal credentials and persist inside your mailbox, surviving password resets and device rebuilds. Patch and hunt for IOCs now.
Read More →CVE-2026-62878 (CVSS 9.8): Windows DNS Server’s Wormable Stack Overflow Can Detonate Across Your Entire Active Directory Forest — No Password Required
CVE-2026-62878 is a CVSS 9.8 wormable stack overflow in Windows DNS Server requiring no authentication. One crafted packet can lead to full Active Directory domain compromise. Patch immediately.
Read More →CVE-2026-33634: The LiteLLM Supply Chain Attack That Compromised 2,500+ Organisations and 434,000 CI/CD Pipelines
TeamPCP backdoored LiteLLM PyPI packages via a Trivy GitHub Actions exploit, exposing 2,500+ organisations and 434,000 CI/CD pipelines to credential theft and Kubernetes compromise.
Read More →CVE-2026-48362 (CVSS 10.0): Adobe ColdFusion’s Unauthenticated OS Command Injection — 72-Hour Patch Window Closes Today
Adobe APSB26-90 patches CVE-2026-48362, a CVSS 10.0 unauthenticated OS command injection in ColdFusion giving attackers full server control with no credentials required.
Read More →