Blog / tag

A critical RCE in Ray AI compute engine lets malicious ads or sites execute code on developers' machines via Firefox and Safari. CISA KEV, active exploitation; fixed in 2.52.0.

CVE-2026-21962, a CVSS 10.0 flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, went from a quiet January patch line item to a confirmed, actively exploited threat when CISA added it to the Known Exploited Vulnerabilities catalog on August 24, 2026. Patch now.

A critical deserialization flaw in Microsoft SharePoint (CVSS 9.8) is being actively exploited in the wild, and its patch quietly shipped in June before public disclosure on July 14. Organizations that skipped a monthly update may already be compromised.

A critical CVSS 9.8 vulnerability in Splunk Enterprise's PostgreSQL sidecar allows unauthenticated attackers to achieve remote code execution. CISA has added it to the KEV catalog amid confirmed in-the-wild exploitation.

A maximum-severity, no-authentication-required remote code execution vulnerability in Oracle PeopleSoft PeopleTools 8.61 and 8.62 is being actively exploited, giving attackers full control over ERP systems holding sensitive HR, financial, and operational data.

A trivially exploited authentication bypass in ConnectWise ScreenConnect — requiring nothing more than appending a slash to a URL — hands attackers SYSTEM-level control over entire managed IT networks, and ransomware crews are already cashing in.

Cisco discloses CVE-2026-20131, a maximum-severity unauthenticated remote code execution vulnerability in its Secure Firewall Management Center. Attackers can gain root access by sending a single crafted request — no credentials required.

A critical OS command injection vulnerability in Soliton's FileZen file-sharing appliance is being actively exploited in the wild, giving attackers full remote code execution. A patch has been available since January — but many systems remain exposed.

CISA added CVE-2008-0015 to its Known Exploited Vulnerabilities catalog on February 17, 2026, confirming active exploitation of a critical stack-based buffer overflow in Microsoft's Video ActiveX control that allows complete system takeover via a malicious webpage.

A trivially exploitable command-injection vulnerability in the React Native CLI's Metro development server is being actively exploited in the wild. CISA has added CVE-2025-11953 to its Known Exploited Vulnerabilities catalog — here's what every React Native team needs to know right now.