LIVE FEED
Subscribe
//

Category: Vulnerabilities

Vulnerabilities BeyondTrust Patches Critical Auth Bypass Flaws in RS and PRA Software
CRITICAL Vulnerabilities

BeyondTrust Patches Critical Auth Bypass Flaws in RS and PRA Software

BeyondTrust has disclosed two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products, urging self-hosted customers to apply…

by Robbie · 3 months ago
Vulnerabilities PoC Exploit Released for Linux ‘Bad Epoll’ Root Privilege Escalation Bug
HIGH Vulnerabilities

PoC Exploit Released for Linux ‘Bad Epoll’ Root Privilege Escalation Bug

A public proof-of-concept exploit now targets a race-condition use-after-free flaw in the Linux kernel's epoll subsystem, enabling unprivileged local attackers to gain…

by Robbie · 3 months ago
Vulnerabilities Exploit Attempts Hit Gitea Docker Flaw CVE-2026-20896 Within Two Weeks of Patch
CRITICAL Vulnerabilities

Exploit Attempts Hit Gitea Docker Flaw CVE-2026-20896 Within Two Weeks of Patch

Threat actors are actively probing a critical Gitea Docker vulnerability that allows unauthenticated clients to gain elevated access by spoofing a trusted…

by Robbie · 3 months ago
Vulnerabilities 16-Year-Old Linux KVM Flaw Allows Guest VMs to Escape to Host
CRITICAL Vulnerabilities

16-Year-Old Linux KVM Flaw Allows Guest VMs to Escape to Host

A use-after-free vulnerability in Linux's KVM hypervisor, present in shared shadow MMU code for both Intel and AMD x86 systems, can be…

by Robbie · 3 months ago
Vulnerabilities Opera GX Flaw Allowed Malicious Sites to Silently Install Data-Stealing Mods
HIGH Vulnerabilities

Opera GX Flaw Allowed Malicious Sites to Silently Install Data-Stealing Mods

A vulnerability in the gaming-focused Opera GX browser let attacker-controlled websites auto-install a browser add-on and extract data from pages the victim…

by Robbie · 3 months ago
Vulnerabilities Google Project Zero Found Nine Bypasses in Windows Administrator Protection
HIGH Vulnerabilities

Google Project Zero Found Nine Bypasses in Windows Administrator Protection

A Google Project Zero researcher identified nine separate vulnerabilities in Windows 11's new Administrator Protection feature before its release, all of which…

by Robbie · 3 months ago
Vulnerabilities ABB Freelance Security Lock Flaw Lets Attackers Bypass ICS User Management
MEDIUM Vulnerabilities

ABB Freelance Security Lock Flaw Lets Attackers Bypass ICS User Management

A keyboard shortcut weakness in ABB Freelance Security Lock allows local attackers to sidestep the Freelance Operations kiosk layer and reach underlying…

by Robbie · 3 months ago
Vulnerabilities Delta Electronics DTM Soft Flaw Allows Arbitrary Code Execution
HIGH Vulnerabilities

Delta Electronics DTM Soft Flaw Allows Arbitrary Code Execution

A deserialization vulnerability in all versions of Delta Electronics DTM Soft carries a CVSS v3.1 score of 7.8 and can be exploited…

by Robbie · 3 months ago
Vulnerabilities Siemens Patches OpenSSL Stack Overflow Across Dozens of Industrial Products
HIGH Vulnerabilities

Siemens Patches OpenSSL Stack Overflow Across Dozens of Industrial Products

A stack-based buffer overflow in OpenSSL tracked as CVE-2025-15467 affects a broad range of Siemens networking, routing, and industrial products, with fixes…

by Robbie · 3 months ago
Vulnerabilities Siemens SIPROTEC 5 Flaw Allows Malicious File Uploads via DIGSI 5
MEDIUM Vulnerabilities

Siemens SIPROTEC 5 Flaw Allows Malicious File Uploads via DIGSI 5

A newly disclosed vulnerability in Siemens SIPROTEC 5 protective relays permits authenticated users to upload arbitrary files through the DIGSI 5 protocol,…

by Robbie · 3 months ago
Vulnerabilities B&R Products Affected by Linux Kernel Privilege Escalation Flaws
HIGH Vulnerabilities

B&R Products Affected by Linux Kernel Privilege Escalation Flaws

CISA has published an advisory detailing Linux kernel vulnerabilities affecting multiple B&R Industrial Automation products, with public proof-of-concept exploits already available for…

by Robbie · 3 months ago
Vulnerabilities CISA Warns of Critical Auth Flaws in EVoke EV Charging Management System
CRITICAL Vulnerabilities

CISA Warns of Critical Auth Flaws in EVoke EV Charging Management System

CISA has published an advisory detailing multiple vulnerabilities in EVoke Systems' Charging Station Management System, with the most severe carrying a CVSS…

by Robbie · 3 months ago
1 … 13 14 15 … 19

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.