Exploited

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

Ravie LakshmananMay 17, 2026Server Security / Vulnerability A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come…

9 heures ago

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

Ravie LakshmananMay 15, 2026Microsoft / Vulnerability Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that…

3 jours ago

Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access

Ravie LakshmananMay 14, 2026Vulnerability / Network Security Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst…

3 jours ago

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

Ravie LakshmananMay 05, 2026Vulnerability / Network Security A critical security vulnerability in Weaver (Fanwei) E-cologyan enterprise office automation (OA) and…

2 semaines ago

CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

Ravie LakshmananMay 03, 2026Vulnerability / Container Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently…

2 semaines ago

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

Ravie LakshmananApr 29, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security…

3 semaines ago

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

Ravie LakshmananApr 25, 2026Network Security / Infrastructure Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four…

3 semaines ago

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

A high-severity security flaw in LMDeployan open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in…

3 semaines ago

CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

Ravie LakshmananApr 21, 2026Network Security / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight…

4 semaines ago

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Ravie LakshmananApr 17, 2026Vulnerability / Endpoint Security Huntress is warning that threat actors are exploiting three recently disclosed security flaws…

1 mois ago