Series

Look Backs

Retrospective writeups on CVEs from 6 to 12 months ago. Each entry revisits a vulnerability with hindsight — what we now know about the bug, the vendor response, and what teams should take away.

9 entries to date

  1. #9 CVE-2025-20337 A critical vulnerability has been identified in Cisco Identity Services Engine (ISE) and related products, assigned a maximum severity score of 10.0. This flaw allows a remote attacker, without any au 2026-07-16
  2. #8 CVE-2024-58311 A critical vulnerability exists in multiple Dormakaba Saflok System products that allows an attacker to create their own valid access keys. The system uses a predictable method to generate keys from a 2026-07-14
  3. #7 CVE-2025-49844 A critical vulnerability has been identified in multiple Redis products, assigned CVE-2025-49844 with a CVSS score of 9.9. This flaw allows an authenticated attacker to execute a specially crafted Lua 2026-07-09
  4. #6 CVE-2025-10585 A high-severity type confusion vulnerability, CVE-2025-10585, has been identified in Google's V8 JavaScript engine, affecting Google Chrome and other Chromium-based products. Successful exploitation a 2026-07-07
  5. #5 CVE-2024-0769 A critical path traversal vulnerability, identified as CVE-2024-0769, exists in the D-Link DIR-859 router. This flaw allows an unauthenticated attacker with network access to read sensitive files on t 2026-06-14
  6. #4 CVE-2025-8047 A critical vulnerability has been identified in two WordPress plugins, `disable-right-click-powered-by-pixterme` and `pixter-image-digital-license`. The plugins load a compromised JavaScript file from 2026-06-07
  7. #3 CVE-2025-56267 A critical remote code execution vulnerability, identified as CVE-2025-56267, has been discovered in Avigilon Access Control Manager (ACM). An attacker can exploit this flaw by uploading a specially c 2026-05-23
  8. #2 CVE-2025-41672 A critical vulnerability has been identified in multiple JSON Web Token (JWT) authentication systems that allows a remote, unauthenticated attacker to gain complete administrative access. This issue s 2026-05-22
  9. #1 CVE-2025-24990 A high-severity vulnerability has been identified in a third-party modem driver that is included with Microsoft Windows operating systems. This flaw is being actively exploited by attackers and could 2026-05-21