TL;DR SonicWall published advisory SNWLID-2026-0016 on September 1, 2026. It confirms active exploitation of two SMA1000 flaws....
exploited in the wild
TL;DR Proxmox published advisory PSA-2026-00043-1 on September 1, 2026. It warns of a critical Proxmox VE authentication...
TL;DR Attackers are exploiting CVE-2026-9586 in the wild. This critical Sangoma Switchvox vulnerability turns an unauthenticated SQL...
Attackers are actively targeting JetBrains TeamCity servers in the wild. The TeamCity CVE-2026-63077 vulnerability allows unauthenticated remote...
GitLab has patched a critical flaw that lets unauthenticated attackers delete public projects and user data. The...
TL;DR CVE-2026-77806 is a CVSS 9.8 unauthenticated RCE in the SPIP CMS. It affects all versions before...
TL;DR CVE-2026-19598 is a CVSS 9.8 privilege escalation flaw in the Pods WordPress plugin. It lets unauthenticated...
TL;DR CVE-2026-77647 is a CVSS 9.8 unauthenticated remote code execution flaw in the SPIP CMS. It affects...
Update: Microsoft updated its safety alert on August 21, 2026. Initially, the report marked the bug as...
TL;DR CISA added two TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-72529 and...
TL;DR CERT Polska reports active exploitation of a Zimbra unauthenticated remote code execution flaw, tracked as CVE-2026-73570....
TL;DR A GeoServer unauthenticated SQL injection flaw is under active attack. It lives in the jsonArrayContains filter...
TL;DR A billing flaw in New API, a popular open-source AI API gateway, is under active attack....
TL;DR CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog. The flaw is a code injection bug...
TL;DR Cisco disclosed a Cisco ASA and FTD VPN vulnerability on August 11, 2026. Tracked as CVE-2026-20349...
TL;DR CVE-2026-63077 is a critical unauthenticated remote code execution flaw in JetBrains TeamCity. An attacker who reaches...
TL;DR Metabase disclosed a critical SQL injection zero-day rated CVSS 10. An unauthenticated remote attacker can gain...
TL;DR CISA added three actively exploited flaws to its Known Exploited Vulnerabilities catalog on August 4, 2026....
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete...
TL;DR: Arista confirmed that CVE-2026-16812, a VeloCloud command injection flaw, is under active attack. The bug scores...
TL;DR A critical FastJson RCE vulnerability, CVE-2026-16723, carries a CVSS score of 9.0. Full technical details and...
TL;DR Check Point disclosed a SmartConsole authentication bypass on July 22, 2026. The flaw, CVE-2026-16232, is already...