Blog / tag

A maximum-severity, no-authentication-required remote code execution vulnerability in Oracle PeopleSoft PeopleTools 8.61 and 8.62 is being actively exploited, giving attackers full control over ERP systems holding sensitive HR, financial, and operational data.

A critical flaw in Arista EOS allows unauthenticated attackers to inject traffic into internal network segments by abusing tunnel decapsulation endpoints — and Arista says no software patch is coming. The vulnerability is actively being exploited and has been added to CISA's Known Exploited Vulne...

A perfect-10 authentication bypass in Cisco's SD-WAN Controller and Manager lets unauthenticated attackers seize control of enterprise wide-area networks. Cisco confirms active exploitation, CISA issues Emergency Directive 26-03.

CISA added CVE-2008-0015 to its Known Exploited Vulnerabilities catalog on February 17, 2026, confirming active exploitation of a critical stack-based buffer overflow in Microsoft's Video ActiveX control that allows complete system takeover via a malicious webpage.