Blog
CVE-2026-16812 (CVSS 10.0): Arista VeloCloud Zero-Day Hands Attackers Root Access to Your Entire SD-WAN Fabric — Patch Now
CVE-2026-16812 is a CVSS 10.0 zero-day in Arista VeloCloud Orchestrator. Actively exploited, CISA KEV. Patch to 5.2.3.14, 6.1.3.4, 6.4.2.4 or 7.0.0.1 now to protect your SD-WAN.
Read More →Storm-2603’s SharePoint Killchain: CVE-2026-55040 + CVE-2026-56164 Turn a Single HTTP Request Into Full Domain Compromise — Patch Before Tomorrow
Storm-2603 is weaponising a two-CVE SharePoint exploit chain — CVE-2026-55040 (CVSS 9.1) and CVE-2026-56164 (CVSS 9.8) — for unauthenticated domain takeover. The RCE patch lands on August Patch Tuesday tomorrow.…
Read More →CVE-2026-20272 (CVSS 9.8) + Three CVSS 9.9 Bugs: Cisco’s August 2026 Hardening Drop Puts Every IOS XE and SD-WAN Deployment at Risk
Cisco's August 2026 hardening release patches 12 flaws across IOS XE and Catalyst SD-WAN, including CVE-2026-20272 (CVSS 9.8) unauthenticated command injection and three CVSS 9.9 SD-WAN Manager bugs. No workarounds…
Read More →CVE-2026-8037 (CVSS 9.6): Pre-Auth Root RCE Hits Kemp LoadMaster — 792 Active Attacks as CISA Deadline Lands Tomorrow
CVE-2026-8037: Pre-auth CVSS 9.6 command injection in Progress Kemp LoadMaster enables root RCE. 792 active attacks from 65 IPs across 18 countries. CISA KEV added August 7. Patch by August…
Read More →Metabase CVSS 10.0: One Unauthenticated API Call Hands Attackers Admin Keys to Your Entire Analytics Stack
A CVSS 10.0 SQL injection zero-day in Metabase's password-reset API grants unauthenticated admin access — no credentials required. Framework, Tally, and LexisNexis confirm data-theft breaches. Patch immediately or block the…
Read More →RovoBlast: Atlassian’s AI Agent Can Be Weaponised to Drain Every Jira Ticket, Confluence Page and SharePoint File You Own
Two prompt-injection flaws in Atlassian Rovo let attackers exfiltrate all your Jira, Confluence and SharePoint data. One attack path remains unpatched after 74 days.
Read More →CVE-2026-64638 (CVSS 8.9): WordPress XSS2Shell Turns a Failed Login Into Full PHP Code Execution — Patch to 7.0.3 Now
CVE-2026-64638 (CVSS 8.9) turns any WordPress login attempt into full PHP remote code execution. Learn how XSS2Shell works and why all sites must patch to WordPress 7.0.3 immediately.
Read More →TONTOU Attack (AMD-SB-7061): MIT Breaks Every Spectre v2 Mitigation on Linux — Unprivileged Code Steals Root Password Hashes in 18 Minutes
MIT CSAIL researchers demonstrated TONTOU at Black Hat USA 2026 — a new Interrupt Injection attack that bypasses all AMD Safe RET (Spectre v2) mitigations on Linux. Patch Linux kernels…
Read More →CVE-2026-63077 (CVSS 9.8): JetBrains TeamCity’s Unauthenticated RCE Hits Active Exploitation — CISA Patch Deadline August 8
CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity, is under active exploitation. CISA patch deadline is August 8, 2026. Patch now.
Read More →CVE-2025-68686: The “Double Slash” That Revives Your Patched FortiOS SSL-VPN Backdoor — CISA Deadline August 10
CVE-2025-68686 bypasses Fortinet’s own patch for FortiOS SSL-VPN symlink persistence attacks — a doubled slash in an HTTP request defeats the filter. CISA deadline: August 10, 2026.
Read More →