Latest Briefings
Critical ServiceNow RCE Flaw (CVE-2026-6875) Now Under Active Exploitation
Threat intelligence firm Defused says attackers are exploiting a critical unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform, days after patches were…
Critical NGINX Flaw Lets Attackers Crash Worker Processes, Possibly Worse
F5 has patched a critical heap buffer overflow in nginx that lets unauthenticated attackers crash worker processes with crafted HTTP requests, with…
WordPress Core wp2shell RCE Chain Gets Public Exploits, Patch Immediately
Two chained flaws in WordPress Core allow unauthenticated remote code execution against stock installs, and public proof-of-concept exploits are now circulating with…
Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
The Inc ransomware group is exploiting two previously unknown vulnerabilities in SonicWall's Secure Mobile Access appliances, chaining the flaws to achieve root-level…
Unauthenticated RCE Flaw in WordPress Core Patched via Forced Updates
A critical WordPress core vulnerability, dubbed wp2shell, allowed unauthenticated attackers to execute code on any 6.9 or 7.0 site with a single…
CISA Adds Actively Exploited SharePoint RCE Flaw CVE-2026-58644 to KEV Catalog
A critical deserialization bug in on-premises SharePoint Server has joined at least three other actively exploited flaws under active attack, with CISA…
F5 Issues Emergency Patches for Critical NGINX Flaw, Seven Other Bugs
F5 has released an out-of-band update fixing eight vulnerabilities across NGINX and BIG-IP, including a critical, unauthenticated heap buffer overflow rated 9.2…
Zoom Patches Critical Windows Flaw That Allows Unauthenticated Account Takeover
Zoom has disclosed a critical, internally discovered vulnerability in its Windows desktop client, VDI client, and Meeting SDK that could let an…
ICS Patch Tuesday: Siemens, Schneider, Rockwell Fix Critical Flaws in July 2026
Siemens leads July's ICS Patch Tuesday with a maximum-severity authentication bypass in Opencenter X, while Rockwell and Schneider Electric address critical and…
SAP Patches Critical CVSS 9.9 NetWeaver Flaw Among 16 July Fixes
SAP's July 2026 patch batch closes three critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud, headlined by a near-maximum-severity memory corruption bug…
SonicWall SMA1000 Zero-Days Under Active Attack, CISA Sets Federal Patch Deadline
SonicWall confirms two SMA1000 vulnerabilities, including a maximum-severity SSRF flaw, are being exploited in the wild. CISA has added both to its…
Microsoft’s July Patch Tuesday Sets Record With 622 Fixes, Two Zero-Days Under Attack
Microsoft's largest security update on record addresses 622 vulnerabilities this month, including actively exploited flaws in Active Directory Federation Services and SharePoint…