← All articles

CVE

28 articles

CVEweb securitysupply chainremediationdevelopment

CVE-2026-45618: Your Template Engine Runs Arbitrary Code. CVSS 10.

LiquidJS, a templating library with 7 million monthly downloads, lets attackers run any code on your server through a crafted template string. No login required. Public exploit available.

Jun 4, 2026
TeamPCPsupply chainCVEsmall business

TeamPCP: The Supply Chain Attackers Who Won't Stop

7 waves. 170+ packages. VS Code extensions. Jenkins plugins. A self-propagating worm. And they breached GitHub itself. Here's the full timeline of the most prolific supply chain campaign of 2026.

Jun 1, 2026
CVEinfrastructureremediationSMBfile shares

CIFSwitch: Your Network File Shares Just Gave Someone Root

A 19-year-old flaw in how Linux handles SMB/CIFS file shares lets any local user become root. If your office uses shared drives on a Linux server, you need to patch today.

May 31, 2026
CVEweb securitysmall businessremediation

CVE-2026-41940: Two Characters Give an Attacker Root on Your Hosting Panel

An unauthenticated CRLF injection in cPanel gives full root control. If your website runs on shared hosting, your host might already be compromised. CVSS 9.8.

May 31, 2026
CVEAIremediationinfrastructureCISA KEV

CVE-2026-42208: Your AI Gateway Has a SQL Injection. On the Auth Path.

LiteLLM, the proxy that manages your AI API keys, has a pre-auth SQL injection. CVSS 9.8. On CISA KEV. Exploited 36 hours after disclosure. Every API key it stores is compromised.

May 31, 2026
CVEinfrastructureremediation

Redis Has a 13-Year-Old RCE Bug. CVSS 10. You're Probably Running It.

A use-after-free in Redis's Lua engine has been there since 2012. CVSS 10.0. Demonstrated at Pwn2Own. If your app uses Redis for caching or sessions, you need to check your version.

May 31, 2026
CVEsupply chainremediationsmall businessFortinet

CVE-2026-35616: Your Security Tool Just Installed Malware on Every Device

Attackers exploited FortiClient EMS to push a credential stealer disguised as a Fortinet firmware update. Your endpoint management system delivered the malware for them. You can't make this up.

May 29, 2026
CVEAILLMpost-exploitation

CVE-2026-39987: An AI Agent Hacked a Database in Under an Hour

An attacker exploited a Marimo notebook, let an LLM agent do the post-exploitation, and it dumped an entire PostgreSQL database in 4 pivots. This is the first documented LLM-agent intrusion in the wild.

May 29, 2026
CVEzero-dayremediationinfrastructure

Gogs Has a CVSS 9.4 Zero-Day With No Patch. A Metasploit Module Is Out.

Any user can get remote code execution on a Gogs server through a malicious branch name. The maintainer was told in March. It's still not fixed. There's a public exploit. Self-hosters, good luck.

May 29, 2026
CVEPalo AltoVPNCISA KEV

CVE-2026-0257: Palo Alto GlobalProtect Auth Bypass Now on CISA's Hit List

CISA just added this Palo Alto GlobalProtect vulnerability to the Known Exploited Vulnerabilities catalog. If your VPN runs on PAN-OS, your remote workers might not be the only ones connecting.

May 28, 2026
CVEGitHubSSRFinfrastructure

CVE-2026-9312: GitHub Enterprise Server Has an SSRF. Yes, That GitHub.

An unauthenticated attacker can reach internal services and steal credentials through GitHub Enterprise Server. If GitHub can ship an SSRF, what's hiding in your infrastructure?

May 28, 2026
supply chainCVEsecurity operationsTeamPCP

Stop Auto-Updating Everything. Seriously.

The biggest supply chain attack in npm history just happened. 160+ packages compromised. If you had auto-updates on, you swallowed the poison automatically. Here's what to do instead.

May 28, 2026
CVEGiteacontainersaccess control

CVE-2026-27771: Your 'Private' Container Images Were Never Private. For Four Years.

Gitea's container registry had a critical access control flaw that let anyone pull 'private' images without authentication. It went undetected for nearly four years. 30,000 deployments affected.

May 27, 2026
CVEAIFastAPIauthentication bypass

CVE-2026-48710 (BadHost): One Character Breaks Your Entire AI Stack

A single slash in the HTTP Host header bypasses authentication on FastAPI, vLLM, MCP servers, and basically every Python AI service. 325 million downloads per week affected.

May 26, 2026
CVEUniFinetwork security

CVE-2026-34908: Your UniFi Router Is Wide Open

Three CVSS 10.0 vulnerabilities in Ubiquiti UniFi OS. 100,000 exposed devices. No authentication required. If you run UniFi gear, patch right now.

May 23, 2026
CVEweb securityremediationsmall businessCISA KEVDrupal

CVE-2026-9082: If Your Website Runs Drupal on PostgreSQL, It's Leaking Data

Anonymous SQL injection in Drupal core. No login required. On CISA KEV. Mass scanning started within days. If you run Drupal on PostgreSQL, patch right now or take it offline.

May 21, 2026
supply chainVSCodeCVETeamPCP

Your Code Editor Just Became a Backdoor. Here's What Happened.

A poisoned VS Code extension breached GitHub's internal repos. 3,800 repositories. 18 minutes. If you install extensions without thinking, you need to read this.

May 21, 2026
CVEinfrastructureremediationLinux

CopyFail 3: Linux Root Through a Race Condition (Yes, Again)

The third Linux kernel privilege escalation in six weeks. This one steals your passwords and SSH keys on the way up. Working exploits are public. Patch now.

May 20, 2026
CVEweb securitysmall businessCISA KEV

Your Next.js Auth Middleware Was Decorative This Whole Time

Set one HTTP header and skip all middleware. Authentication, authorization, rate limiting, all of it. CVE-2025-29927. Confirmed exploitation in the wild. If you run Next.js, update now.

May 20, 2026
CVEAIinfrastructureremediation

vm2 Sandbox Escape: Your AI Agent's Code Runner Just Got Owned

Three CVEs. CVSS 10.0. The Node.js sandbox library used by AI agents, online code runners, and plugin engines can be escaped with a WebAssembly trick. The sandbox was never safe.

May 17, 2026
CVEMicrosoftExchangezero-dayCISA KEV

CVE-2026-42897: Microsoft Exchange Zero-Day Is Being Exploited Right Now

A crafted email is all it takes. Open it in Outlook Web Access and an attacker runs JavaScript in your browser. No patch yet. Here's what to do if you run Exchange on-prem.

May 15, 2026
CVETeamPCPsupply chainremediation

TeamPCP Backdoored a Security Scanner. Your Security Tools Are the Target.

The Checkmarx Jenkins plugin, installed to find vulnerabilities in your code, was itself compromised with an infostealer. CVE-2026-33634. CVSS 9.4. Every secret in your CI/CD pipeline was exfiltrated.

May 10, 2026
CVEinfrastructureremediationCISA KEV

Dirty Frag: The Second Linux Root Exploit in Two Weeks

Two new kernel vulnerabilities chain together for race-free root on every major distro. Exploited within 24 hours of disclosure. Same primitive class as Dirty Pipe and CopyFail. Patch your servers.

May 8, 2026
CVEfirewallPalo Altonetwork securityFortinetSonicWall

CVE-2026-0300: Your Firewall Is the Vulnerability

Palo Alto firewalls are being exploited for root-level code execution. SonicWall and Fortinet are getting hit too. 56% of compromised networks trace back to a firewall. The irony is painful.

May 7, 2026
CVEinfrastructureremediationCISA KEV

CVE-2026-31431: 732 Bytes Gets You Root on Every Linux Distro

A 9-year-old kernel bug. 732-byte exploit. Works identically on Ubuntu, RHEL, Debian, Fedora, Amazon Linux. No race condition needed. On CISA KEV. Patch your servers.

May 1, 2026
CVECiscoWebex

CVE-2026-20184: Anyone Can Impersonate Anyone on Cisco Webex

CVSS 9.8. No authentication required. An attacker can impersonate any user in your Webex org, access meetings, files, and conversations. Here's what you need to know.

Apr 19, 2026
CVEZoomRCEcollaboration

CVE-2026-22844: Zoom Has a CVSS 9.9 and Nobody's Talking About It

A meeting participant can execute code on your Zoom infrastructure. CVSS 9.9. If you self-host Zoom rooms or use on-prem Zoom infrastructure, this is an emergency.

Mar 11, 2026
CVEzero-dayinfrastructureCISA KEV

Ivanti Zero-Days Breached Four Governments Before Anyone Got a Patch

The Dutch data authority. The European Commission. Finland. The Council for the Judiciary. All breached through Ivanti EPMM zero-days. CVSS 9.8. If you manage mobile devices with Ivanti, check your version now.

Feb 3, 2026