Category: Vulnerabilities
Critical libssh2 Flaw Gets Public PoC, Clients at Risk of Code Execution
A proof-of-concept exploit is now public for CVE-2026-55200, a critical memory corruption bug in libssh2 that allows a malicious SSH server to…
DirtyClone Linux Kernel Flaw Enables Root Access via Socket Buffer Corruption
JFrog has released technical details and a proof-of-concept for DirtyClone, a high-severity Linux kernel privilege escalation vulnerability that extends a broader family…
Microsoft Extends Windows Server 2022 Hotpatching Support to October 2027
Microsoft has pushed the hotpatch support window for Windows Server 2022 Datacenter: Azure Edition one year past mainstream end-of-support, giving enrolled organizations…
May 2026 Patch Tuesday: 118 Microsoft Fixes, No Zero-Days, AI Finds Bugs
Microsoft's May 2026 Patch Tuesday addresses 118 vulnerabilities with no actively exploited zero-days, while AI-assisted bug discovery is driving record patch volumes…
Smarter Vulnerability Triage: Pairing CVSS With EPSS and GCVE
Cisco Talos argues that severity scores alone make poor prioritization tools, and outlines a practical triage stack combining CVSS, EPSS, and the…
Active Exploitation of PAN-OS GlobalProtect Auth Bypass CVE-2026-0257
Unit 42 has confirmed active in-the-wild exploitation of a PAN-OS authentication bypass affecting GlobalProtect portals and gateways, with the flaw added to…
Horner Automation Cscape Flaw Enables Code Execution via Malicious Files
An out-of-bounds read vulnerability in Horner Automation Cscape prior to version 10.2 SP3 allows a local attacker to disclose information and execute…
CISA Warns of Two High-Severity Flaws in AzeoTech DAQFactory
CISA has published an updated advisory detailing two memory-corruption vulnerabilities in AzeoTech DAQFactory that allow arbitrary code execution via malicious control files.
Critical Path Traversal Flaw in pynetdicom Threatens Healthcare Systems
A critical path traversal vulnerability in the pynetdicom library allows unauthenticated attackers to write files to arbitrary locations, affecting all versions from…
Mitsubishi MELSEC iQ-F EtherNet/IP Module Vulnerable to Remote DoS
An integer overflow flaw in the FX5-EIP module allows unauthenticated remote attackers to crash the device by flooding it with TCP connections.…
CISA Flags Two High-Severity Flaws in H.VIEW HV-500S6 IP Camera
A pair of vulnerabilities in H.VIEW's HV-500S6 IP camera allow authenticated attackers to execute arbitrary commands and upload malicious files. The vendor…
Bucket Squatting Flaw in Vertex AI Python SDK Enabled Cross-Tenant RCE
A now-patched vulnerability in Google Cloud's Vertex AI Python SDK allowed an attacker with no access to a victim's project to hijack…