Vulnerabilities PaperCut NG/MF Unsafe Reflection Vulnerability Added to CISA’s Known Exploited Vulnerabilities Catalogue August 31, 2026 CVE-2026-82078 allows arbitrary Java bytecode execution under the PaperCut server process and can be chained… Read More
Vulnerabilities ZBT Routers Shipped With Two Factory-Installed Implants Granting Root Access Without Authentication August 28, 2026 VulnCheck has identified two undocumented backdoors embedded in firmware from Chinese router manufacturer Shenzhen Zhibotong… Read More
Vulnerabilities CISA Adds Six-Year-Old Microsoft SQL Server RCE Flaw to Known Exploited Vulnerabilities Catalogue August 26, 2026 CVE-2019-1068 carries a CISA-mandated remediation deadline of 29 August 2026, giving organisations a finite window… Read More
Vulnerabilities CISA Adds Gitea Code Injection Flaw to Known Exploited Vulnerabilities Catalog August 26, 2026 CVE-2026-60004 is now confirmed as actively exploited, placing Gitea installations on the radar for immediate… Read More
Vulnerabilities CISA Adds Perfect-10 Oracle WebLogic and HTTP Server Flaw to Known Exploited Vulnerabilities Catalogue August 25, 2026 A maximum-severity improper access control vulnerability affecting Oracle HTTP Server and WebLogic Server Proxy Plug-in… Read More
Government AdvisoryVulnerabilities Joint Advisory Warns of AI-Assisted Attacks Targeting Siemens S7 PLCs Across Critical Infrastructure August 20, 2026August 20, 2026 US and partner agencies have flagged an active threat campaign using AI-generated exploit scripts to… Read More
Vulnerabilities Clop’s PTC Zero-Day Campaign Expands as Victim List and Tooling Details Emerge August 20, 2026 A custom web shell purpose-built for PTC's Windchill platform is enabling rapid credential theft and… Read More
Vulnerabilities CISA Adds Four Critical Vulnerabilities to KEV Catalog as Active Exploitation Confirmed August 19, 2026 Flaws affecting Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE have been confirmed as… Read More
Vulnerabilities CISA imposes three-day fix deadline on actively exploited Ray framework RCE flaw August 19, 2026 A critical remote code execution vulnerability in the Ray distributed computing framework is under active… Read More
Vulnerabilities CISA Adds Ray Framework Code Injection Flaw to Known Exploited Vulnerabilities Catalogue August 18, 2026 CVE-2025-62593 affects the Ray distributed computing framework and can be triggered through Firefox and Safari,… Read More