RadicalNotion.AIRadicalNotion.AIRadicalNotion.AI

We do not sell or share your personal information

© 2026 RadicalNotion.AI

Security Data

  • CWE Directory
  • CAPEC Directory
  • CNA Directory
  • CNA Report Cards
  • Data Sources

Calculators

  • CVSS Calculator
  • CVSS 4.0
  • CVSS 3.1
  • CVSS 3.0
  • CVSS 2.0

Platform

  • My Vulnerabilities
  • Insights
  • Notifications
  • Account
  • Pricing

Learn

  • All guides
  • What is a CVE?
  • What is CVSS?
  • The CISA KEV catalog
  • What is EPSS?

Company

  • About us
  • Blog
  • Book a demo

Get Started

  • Sign up
  • Log in

Legal

  • Privacy
  • Terms
RadicalNotion.AIRadicalNotion.AI

Security data

  • Weaknesses (CWE)The MITRE CWE weakness catalog
  • Attack Patterns (CAPEC)MITRE CAPEC attack patterns
  • CNAsNumbering authorities + report cards
  • VendorsVulnerabilities by vendor

Tools

  • CVSS CalculatorScore CVSS 4.0, 3.1, 3.0 & 2.0

Resources

  • LearnPlain-English security guides
  • Data SourcesHow we source CVE data
About UsBlogPricingBook a Demo
Log in
  1. Home
  2. Blog

Blog

Log in
splunk

Critical Splunk Enterprise Flaw (CVE-2026-20253) Under Active Exploitation: Pre-Auth RCE via PostgreSQL Sidecar

A critical CVSS 9.8 vulnerability in Splunk Enterprise's PostgreSQL sidecar allows unauthenticated attackers to achieve remote code execution. CISA has added it to the KEV catalog amid confirmed in-the-wild exploitation.

Radical Notion Team4 days ago
OraclePeopleSoft

Critical Oracle PeopleSoft RCE Flaw Actively Exploited in the Wild

A maximum-severity, no-authentication-required remote code execution vulnerability in Oracle PeopleSoft PeopleTools 8.61 and 8.62 is being actively exploited, giving attackers full control over ERP systems holding sensitive HR, financial, and operational data.

Radical Notion Team1 week ago
arista

CVE-2026-7473: Arista EOS Tunnel Bypass Flaw Exploited in the Wild, No Patch Planned

A critical flaw in Arista EOS allows unauthenticated attackers to inject traffic into internal network segments by abusing tunnel decapsulation endpoints — and Arista says no software patch is coming. The vulnerability is actively being exploited and has been added to CISA's Known Exploited Vulne...

Radical Notion Team1 week ago
linux

'Copy Fail': Linux Kernel Flaw Lets Any Local User Become Root

A publicly exploitable Linux kernel vulnerability dubbed 'Copy Fail' allows any unprivileged local user to silently overwrite root-owned binaries and seize full system control. Kernels from version 4.14 through 6.18.21 are affected, and a working Python exploit is already public.

Radical Notion Team1 month ago
ConnectWise

SlashAndGrab: The ScreenConnect Flaw Ransomware Gangs Love

A trivially exploited authentication bypass in ConnectWise ScreenConnect — requiring nothing more than appending a slash to a URL — hands attackers SYSTEM-level control over entire managed IT networks, and ransomware crews are already cashing in.

Radical Notion Team1 month ago
Patterns of Activity in the CVE Ecosystem

April 2026 CNA Anomalous Behavior

Patterns of CNA behavior for April 2026 worth noting

RadicalNotion Team2 months ago
Atlassian

CVE-2023-22515: The Confluence Flaw That Hands Attackers the Keys to Your Kingdom

A perfect CVSS 10.0 vulnerability in Atlassian Confluence lets anyone on the internet create an admin account with a single HTTP request. Nation-state actors and ransomware gangs are already exploiting it.

Radical Notion Team3 months ago
CISCO

Cisco Firewall Management Center Hit with Perfect 10.0 Critical RCE Flaw

Cisco discloses CVE-2026-20131, a maximum-severity unauthenticated remote code execution vulnerability in its Secure Firewall Management Center. Attackers can gain root access by sending a single crafted request — no credentials required.

Radical Notion Team3 months ago
CISCO

CVSS 10.0: Cisco SD-WAN Auth Bypass Exploited in the Wild

A perfect-10 authentication bypass in Cisco's SD-WAN Controller and Manager lets unauthenticated attackers seize control of enterprise wide-area networks. Cisco confirms active exploitation, CISA issues Emergency Directive 26-03.

Radical Notion Team3 months ago
CISCO

Old Cisco SD-WAN Flaw Now Under Active Attack — Patch Immediately

A 2022 privilege escalation vulnerability in Cisco SD-WAN software is now being actively exploited in the wild, four years after patches were released. Attackers with any valid local credential can chain two path traversal bugs to seize complete root control of routers, controllers, and orchestra...

Radical Notion Team3 months ago
FileZen

FileZen Under Active Attack: Command Injection Flaw Gives Hackers Full System Control

A critical OS command injection vulnerability in Soliton's FileZen file-sharing appliance is being actively exploited in the wild, giving attackers full remote code execution. A patch has been available since January — but many systems remain exposed.

Radical Notion Team3 months ago
Dell Recovery Point

Chinese Hackers Exploited Dell Backup Flaw for Months Using Hard-Coded Password

A perfect CVSS 10.0 vulnerability in Dell RecoverPoint for Virtual Machines ships with hard-coded Tomcat credentials that a Chinese-linked threat group has been exploiting since mid-2024 to deploy backdoors and ransomware.

Radical Notion Team4 months ago
Previous

Page 1 of 2

Next