Latest Briefings
Unauthenticated RCE Flaw in WordPress Core Patched via Forced Updates
A critical WordPress core vulnerability, dubbed wp2shell, allowed unauthenticated attackers to execute code on any 6.9 or 7.0 site with a single…
CISA Adds Actively Exploited SharePoint RCE Flaw CVE-2026-58644 to KEV Catalog
A critical deserialization bug in on-premises SharePoint Server has joined at least three other actively exploited flaws under active attack, with CISA…
F5 Issues Emergency Patches for Critical NGINX Flaw, Seven Other Bugs
F5 has released an out-of-band update fixing eight vulnerabilities across NGINX and BIG-IP, including a critical, unauthenticated heap buffer overflow rated 9.2…
Zoom Patches Critical Windows Flaw That Allows Unauthenticated Account Takeover
Zoom has disclosed a critical, internally discovered vulnerability in its Windows desktop client, VDI client, and Meeting SDK that could let an…
ICS Patch Tuesday: Siemens, Schneider, Rockwell Fix Critical Flaws in July 2026
Siemens leads July's ICS Patch Tuesday with a maximum-severity authentication bypass in Opencenter X, while Rockwell and Schneider Electric address critical and…
SAP Patches Critical CVSS 9.9 NetWeaver Flaw Among 16 July Fixes
SAP's July 2026 patch batch closes three critical vulnerabilities in NetWeaver, Approuter, and Commerce Cloud, headlined by a near-maximum-severity memory corruption bug…
SonicWall SMA1000 Zero-Days Under Active Attack, CISA Sets Federal Patch Deadline
SonicWall confirms two SMA1000 vulnerabilities, including a maximum-severity SSRF flaw, are being exploited in the wild. CISA has added both to its…
Microsoft’s July Patch Tuesday Sets Record With 622 Fixes, Two Zero-Days Under Attack
Microsoft's largest security update on record addresses 622 vulnerabilities this month, including actively exploited flaws in Active Directory Federation Services and SharePoint…
Critical Joomla Extension Flaws Under Active Exploitation, CISA Adds to KEV
Unauthenticated file upload vulnerabilities in the Balbooa Forms and iCagenda Joomla extensions, both scoring a maximum CVSS of 10, are being exploited…
Attackers Exploit Critical Auth Bypass in Gitea’s Official Docker Image
A misconfigured default in Gitea's Docker image lets unauthenticated attackers impersonate any user, including admins, and exploitation began before public disclosure.
Critical Zimbra Classic Web Client Flaw Lets Emails Execute Malicious Code
Zimbra is pushing urgent updates for a critical stored XSS vulnerability in its Classic Web Client that lets specially crafted emails run…
Zimbra Patches Critical XSS Flaw in Classic Web Client After Google TAG Report
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, flagged by Google's Threat Analysis…