RadicalNotion.AIRadicalNotion.AIRadicalNotion.AI

We do not sell or share your personal information

© 2026 RadicalNotion.AI

Security Data

  • CWE Directory
  • CAPEC Directory
  • CNA Directory
  • CNA Leaderboard
  • CNA Report Cards
  • Vendor Directory
  • Data Sources

Calculators

  • CVSS Calculator
  • CVSS 4.0
  • CVSS 3.1
  • CVSS 3.0
  • CVSS 2.0
  • Badge Builder

Platform

  • My Vulnerabilities
  • Insights
  • Notifications
  • Pricing

Learn

  • All guides
  • What is a CVE?
  • What is CVSS?
  • The CISA KEV catalog
  • What is EPSS?

Company

  • About us
  • Blog
  • Careers
  • Contact
  • Book a demo

Get Started

  • Sign up
  • Log in

Legal

  • Security
  • Privacy
  • Terms
RadicalNotion.AIRadicalNotion.AIRadicalNotion.AI

Security data

  • Weaknesses (CWE)The MITRE CWE weakness catalog
  • Attack Patterns (CAPEC)MITRE CAPEC attack patterns
  • CNAsNumbering authorities + report cards
  • VendorsVulnerabilities by vendor

Tools

  • CVSS CalculatorScore CVSS 4.0, 3.1, 3.0 & 2.0
  • Badge BuilderEmbeddable SVG badges for READMEs

Resources

  • LearnPlain-English security guides
  • Data SourcesHow we source CVE data
About UsBlogPricingBook a Demo
  1. Home
  2. Blog

Blog

Log inStart free
RAY

Ray AI Dashboard RCE Exploited via DNS Rebinding: Patch Now (CVE-2025-62593)

A critical RCE in Ray AI compute engine lets malicious ads or sites execute code on developers' machines via Firefox and Safari. CISA KEV, active exploitation; fixed in 2.52.0.

Radical Notion Team4 weeks ago
oracle

Oracle's Perfect 10: CVSS 10.0 WebLogic Proxy Bug Lands in CISA KEV

CVE-2026-21962, a CVSS 10.0 flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, went from a quiet January patch line item to a confirmed, actively exploited threat when CISA added it to the Known Exploited Vulnerabilities catalog on August 24, 2026. Patch now.

Radical Notion Team4 weeks ago
MS Sharepoint

Critical SharePoint RCE (CVE-2026-58644) Under Active Attack After Patch Sat Hidden for a Month

A critical deserialization flaw in Microsoft SharePoint (CVSS 9.8) is being actively exploited in the wild, and its patch quietly shipped in June before public disclosure on July 14. Organizations that skipped a monthly update may already be compromised.

Radical Notion Team2 months ago
splunk

Critical Splunk Enterprise Flaw (CVE-2026-20253) Under Active Exploitation: Pre-Auth RCE via PostgreSQL Sidecar

A critical CVSS 9.8 vulnerability in Splunk Enterprise's PostgreSQL sidecar allows unauthenticated attackers to achieve remote code execution. CISA has added it to the KEV catalog amid confirmed in-the-wild exploitation.

Radical Notion Team3 months ago
OraclePeopleSoft

Critical Oracle PeopleSoft RCE Flaw Actively Exploited in the Wild

A maximum-severity, no-authentication-required remote code execution vulnerability in Oracle PeopleSoft PeopleTools 8.61 and 8.62 is being actively exploited, giving attackers full control over ERP systems holding sensitive HR, financial, and operational data.

Radical Notion Team3 months ago
arista

CVE-2026-7473: Arista EOS Tunnel Bypass Flaw Exploited in the Wild, No Patch Planned

A critical flaw in Arista EOS allows unauthenticated attackers to inject traffic into internal network segments by abusing tunnel decapsulation endpoints — and Arista says no software patch is coming. The vulnerability is actively being exploited and has been added to CISA's Known Exploited Vulne...

Radical Notion Team3 months ago
linux

'Copy Fail': Linux Kernel Flaw Lets Any Local User Become Root

A publicly exploitable Linux kernel vulnerability dubbed 'Copy Fail' allows any unprivileged local user to silently overwrite root-owned binaries and seize full system control. Kernels from version 4.14 through 6.18.21 are affected, and a working Python exploit is already public.

Radical Notion Team4 months ago
ConnectWise

SlashAndGrab: The ScreenConnect Flaw Ransomware Gangs Love

A trivially exploited authentication bypass in ConnectWise ScreenConnect — requiring nothing more than appending a slash to a URL — hands attackers SYSTEM-level control over entire managed IT networks, and ransomware crews are already cashing in.

Radical Notion Team4 months ago
Patterns of Activity in the CVE Ecosystem

April 2026 CNA Anomalous Behavior

Patterns of CNA behavior for April 2026 worth noting

RadicalNotion Team5 months ago
Atlassian

CVE-2023-22515: The Confluence Flaw That Hands Attackers the Keys to Your Kingdom

A perfect CVSS 10.0 vulnerability in Atlassian Confluence lets anyone on the internet create an admin account with a single HTTP request. Nation-state actors and ransomware gangs are already exploiting it.

Radical Notion Team6 months ago
CISCO

Cisco Firewall Management Center Hit with Perfect 10.0 Critical RCE Flaw

Cisco discloses CVE-2026-20131, a maximum-severity unauthenticated remote code execution vulnerability in its Secure Firewall Management Center. Attackers can gain root access by sending a single crafted request — no credentials required.

Radical Notion Team6 months ago
CISCO

CVSS 10.0: Cisco SD-WAN Auth Bypass Exploited in the Wild

A perfect-10 authentication bypass in Cisco's SD-WAN Controller and Manager lets unauthenticated attackers seize control of enterprise wide-area networks. Cisco confirms active exploitation, CISA issues Emergency Directive 26-03.

Radical Notion Team6 months ago
Previous

Page 1 of 2

Next