Series

Look Backs

Retrospective writeups on CVEs from 6 to 12 months ago. Each entry revisits a vulnerability with hindsight — what we now know about the bug, the vendor response, and what teams should take away.

19 entries to date

  1. #19 CVE-2025-41244 A high-severity vulnerability has been discovered in VMware Aria Operations and VMware Tools, which could allow a local attacker to gain full administrative control of an affected system. An attacker 2026-08-20
  2. #18 CVE-2025-43300 A high-severity vulnerability, identified as CVE-2025-43300, has been discovered in multiple products from the vendor 'An'. This flaw allows an attacker to write data outside of intended memory bounda 2026-08-18
  3. #17 CVE-2025-59719 A critical vulnerability has been identified in multiple versions of Fortinet FortiWeb that allows an unauthenticated attacker to bypass the FortiCloud Single Sign-On (SSO) authentication. Successful 2026-08-13
  4. #16 CVE-2025-64484 A high-severity vulnerability has been identified in OAuth2-Proxy, a widely used open-source authentication tool. This flaw could allow an unauthenticated attacker to bypass security controls and gain 2026-08-11
  5. #15 CVE-2025-54236 A critical vulnerability has been discovered in multiple versions of Adobe Commerce that could allow an unauthenticated remote attacker to take complete control of an affected e-commerce site. This fl 2026-08-06
  6. #14 CVE-2025-11001 A high-severity vulnerability has been discovered in the 7-Zip library, which is used by numerous software products to process ZIP files. This flaw could allow a remote attacker to execute malicious c 2026-08-04
  7. #13 CVE-2025-61882 A critical vulnerability has been identified in the Oracle E-Business Suite's Concurrent Processing product, specifically within the BI Publisher Integration component. This flaw is easily exploitable 2026-07-30
  8. #12 CVE-2025-59287 A critical vulnerability has been discovered in Windows Server Update Service (WSUS) that allows an unauthenticated attacker to execute arbitrary code remotely. Successful exploitation could lead to a 2026-07-28
  9. #11 CVE-2025-54419 A critical authentication bypass vulnerability exists in a widely used Node.js SAML library. This flaw allows an unauthenticated attacker to tamper with SAML assertions to impersonate any user, includ 2026-07-23
  10. #10 CVE-2025-10035 A critical vulnerability has been identified in Fortra's GoAnywhere MFT software, which could allow an unauthenticated remote attacker to take complete control of the affected system. Successful explo 2026-07-21
  11. #9 CVE-2025-20337 A critical vulnerability has been identified in Cisco Identity Services Engine (ISE) and related products, assigned a maximum severity score of 10.0. This flaw allows a remote attacker, without any au 2026-07-16
  12. #8 CVE-2024-58311 A critical vulnerability exists in multiple Dormakaba Saflok System products that allows an attacker to create their own valid access keys. The system uses a predictable method to generate keys from a 2026-07-14
  13. #7 CVE-2025-49844 A critical vulnerability has been identified in multiple Redis products, assigned CVE-2025-49844 with a CVSS score of 9.9. This flaw allows an authenticated attacker to execute a specially crafted Lua 2026-07-09
  14. #6 CVE-2025-10585 A high-severity type confusion vulnerability, CVE-2025-10585, has been identified in Google's V8 JavaScript engine, affecting Google Chrome and other Chromium-based products. Successful exploitation a 2026-07-07
  15. #5 CVE-2024-0769 A critical path traversal vulnerability, identified as CVE-2024-0769, exists in the D-Link DIR-859 router. This flaw allows an unauthenticated attacker with network access to read sensitive files on t 2026-06-14
  16. #4 CVE-2025-8047 A critical vulnerability has been identified in two WordPress plugins, `disable-right-click-powered-by-pixterme` and `pixter-image-digital-license`. The plugins load a compromised JavaScript file from 2026-06-07
  17. #3 CVE-2025-56267 A critical remote code execution vulnerability, identified as CVE-2025-56267, has been discovered in Avigilon Access Control Manager (ACM). An attacker can exploit this flaw by uploading a specially c 2026-05-23
  18. #2 CVE-2025-41672 A critical vulnerability has been identified in multiple JSON Web Token (JWT) authentication systems that allows a remote, unauthenticated attacker to gain complete administrative access. This issue s 2026-05-22
  19. #1 CVE-2025-24990 A high-severity vulnerability has been identified in a third-party modem driver that is included with Microsoft Windows operating systems. This flaw is being actively exploited by attackers and could 2026-05-21