Series

Deep Dives

Operational writeups on CVEs disclosed in the past week. Each entry shows how to check if you're vulnerable, the threat model, and starter detection rules.

30 entries to date

  1. #30 CVE-2026-75874 Mozilla — Firefox, Thunderbird A critical sandbox escape vulnerability in Mozilla Firefox and Thunderbird, rated 10.0, allows unauthenticated remote attackers to achieve full system compromise. 2026-08-19
  2. #29 CVE-2026-68820 Microsoft — Windows Ancillary Function Driver for WinSock A critical use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock is under active exploitation, presenting a severe risk to Windows systems. 2026-08-17
  3. #28 CVE-2026-20349 Cisco — Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) This critical heap inspection vulnerability in Cisco Secure Firewall ASA and FTD is being actively exploited in the wild and poses a significant risk to network infrastructure. 2026-08-14
  4. #27 CVE-2026-72898 Metabase — Metabase A critical SQL injection vulnerability in Metabase allows unauthenticated remote attackers to achieve full system compromise, necessitating an immediate update to patched versions. 2026-08-12
  5. #26 CVE-2026-18556 N-able — N-central An authentication bypass vulnerability in N-able N-central exposes the platform to unauthorized access by remote, unauthenticated attackers. 2026-08-10
  6. #25 CVE-2026-63077 JetBrains — TeamCity A critical vulnerability in JetBrains TeamCity allows unauthenticated remote attackers to execute arbitrary code via the agent polling protocol. 2026-08-07
  7. #24 CVE-2026-9198 IBM — Langflow OSS IBM Langflow OSS is vulnerable to an unauthenticated code injection attack that allows attackers to escalate privileges to superuser and execute arbitrary commands. 2026-08-05
  8. #23 CVE-2025-68686 Fortinet — FortiOS This critical vulnerability in Fortinet FortiOS is currently being exploited in the wild and poses a significant risk of unauthorized information disclosure. 2026-08-03
  9. #22 CVE-2026-20316 Cisco — Secure Firewall Management Center (FMC) This vulnerability involves a hard-coded password in Cisco Secure Firewall Management Center and is currently being actively exploited in the wild. 2026-07-31
  10. #21 CVE-2026-16812 Arista Networks — VeloCloud Orchestrator On-Prem This critical command injection vulnerability in Arista VeloCloud Orchestrator is being actively exploited in the wild and enables full system compromise. 2026-07-29
  11. #20 CVE-2026-50522 Microsoft — SharePoint An unauthenticated remote code execution vulnerability exists in Microsoft SharePoint due to improper deserialization of untrusted data. 2026-07-27
  12. #19 CVE-2026-6516 Zohocorp — ManageEngine ADAudit Plus A critical unauthenticated remote code execution vulnerability in ManageEngine ADAudit Plus enables attackers to execute arbitrary system commands. 2026-07-24
  13. #18 CVE-2026-25089 Fortinet — FortiSandbox A critical OS command injection vulnerability in Fortinet FortiSandbox allows unauthenticated remote attackers to execute arbitrary system commands. 2026-07-22
  14. #17 CVE-2026-15409 SonicWall — SMA1000 This critical SSRF vulnerability in SonicWall SMA1000 appliances is confirmed to be under active exploitation in the wild and poses a severe risk of unauthorized internal network access. 2026-07-20
  15. #16 CVE-2026-43499 Linux — kernel A high-severity use-after-free vulnerability in the Linux kernel's real-time mutex subsystem could allow a local attacker to gain elevated privileges. 2026-07-17
  16. #15 CVE-2026-40887 Vendure — Vendure An unauthenticated SQL injection vulnerability in the Vendure Shop API permits remote attackers to execute arbitrary database queries, leading to potential unauthorized data access or modification. 2026-07-17
  17. #14 CVE-2025-48595 Android — Framework A local privilege-escalation flaw in the Android Framework (CVSS 8.4, integer overflow) is under limited, targeted exploitation in the wild and is in CISA KEV. It lets an unprivileged on-device app ga 2026-07-17
  18. #13 CVE-2026-58644 Microsoft — SharePoint A critical remote code execution vulnerability exists in Microsoft SharePoint that allows unauthenticated attackers to compromise affected servers. 2026-07-17
  19. #12 CVE-2026-56164 Microsoft — SharePoint Server This critical vulnerability in Microsoft SharePoint Server is currently being exploited in the wild and poses a severe risk of unauthorized access to critical functions. 2026-07-15
  20. #11 CVE-2026-30893 Wazuh — Wazuh An authenticated path traversal vulnerability in Wazuh allows cluster peers to perform arbitrary file writes, potentially leading to full system-level compromise. 2026-07-14
  21. #10 CVE-2026-5027 Langflow — Langflow An unauthenticated path traversal vulnerability in the /api/v2/files endpoint allows attackers to write files to arbitrary locations on the filesystem, potentially leading to system takeover. 2026-07-14
  22. #9 CVE-2026-56291 Balbooa — Balbooa Forms extension for Joomla A critical unauthenticated file upload vulnerability in the Balbooa Forms extension for Joomla permits full remote code execution on the underlying server. 2026-07-13
  23. #8 CVE-2026-48908 JoomShaper — SP Page Builder This critical vulnerability in JoomShaper SP Page Builder is currently being actively exploited in the wild, posing an immediate risk of full system compromise. 2026-07-10
  24. #7 CVE-2026-48282 Adobe — ColdFusion A critical path traversal vulnerability in Adobe ColdFusion allows unauthenticated remote attackers to achieve arbitrary code execution, endangering the entire host environment. 2026-07-08
  25. #6 CVE-2026-45659 Microsoft — Office SharePoint An insecure deserialization flaw in Microsoft Office SharePoint allows authorized attackers to achieve remote code execution. 2026-07-06
  26. #5 CVE-2026-45247 Mirasvit — Full Page Cache Warmer for Magento 2 An unauthenticated PHP object injection vulnerability in Mirasvit Full Page Cache Warmer for Magento 2 enables remote attackers to achieve arbitrary code execution. 2026-06-08
  27. #4 CVE-2026-10910 Google — Chrome A critical type confusion flaw in the V8 JavaScript engine of Google Chrome exposes users to potential remote code execution and system compromise. 2026-06-05
  28. #3 CVE-2026-43898 SandboxJS — SandboxJS A critical sandbox escape vulnerability in the SandboxJS library allows unauthenticated remote attackers to achieve full code execution on the underlying host system. 2026-05-29
  29. #2 CVE-2026-44329 free5GC — SMF (Session Management Function) A critical authentication bypass in the free5GC SMF component allows an unauthenticated network attacker to perform unauthorized management operations on the 5G core network. 2026-05-28
  30. #1 CVE-2026-42945 F5 — NGINX The "NGINX Rift" heap buffer overflow vulnerability in NGINX Open Source and NGINX Plus poses a significant risk of service disruption and potential remote code execution. 2026-05-22