Archive
Every issue of the digest.
Newest first. Latest issue: Aug 4, 2026. Browse the archive or subscribe via RSS.
Products, platforms, vendors, and exploit signals.
More filters
70 issues shown · from Apr 21, 2026
August 2026
3 issues- Nº070 AUG 4
OpenEMR MFA bypass and an Excel RCE that only needs one click
A stolen password plus CVE-2026-67611 (CVSS 8.1) completely skips MFA in OpenEMR. CVE-2026-62870 (CVSS 8.8) is a use-after-free in Excel that gives attackers code execution when a user opens a malicious spreadsheet. Also: two Edge bugs and a GIMP heap overflow pair.
5 CVEs0 Crit0 KEV4 min - Nº069 AUG 3
pgAdmin scores a 9.9 again, FreeRDP clipboard overflow hits 9.6, and Ansible EDA auth is a joke
Two pgAdmin 4 command injection bugs (CVSS 9.9 and 7.5) keep the streak alive, a FreeRDP heap overflow lets a rogue RDP server own your client on paste, and Ansible's Event-Driven Automation lets anyone bypass mTLS with a forged header.
5 CVEs2 Crit0 KEV4 min - Nº068 AUG 1
ComfyUI unauthenticated RCE, pgAdmin popen breakout, and an Ansible auth bypass walk into a Friday
A pickle deserialization RCE in ComfyUI (CVSS 9.8, no auth needed), a CVSS 9.9 command injection in pgAdmin 4's Import/Export tool, and an mTLS bypass on Ansible EDA event streams. Plus DoS on RHEL's gnome-remote-desktop and a second pgAdmin shell injection via MASTER_PASSWORD_HOOK.
5 CVEs2 Crit0 KEV4 min
July 2026
17 issues- Nº067 JUL 31
vCenter auth bypass at 9.8 tops a rough day for directory servers
CVE-2026-59309 lets unauthenticated attackers take full control of on-prem vCenter. Also: Samba AD DC LDAP injection leaks gMSA passwords (8.8), two 389-ds bugs enable crashes and blind data extraction, and CentreStack's XXE hands over database creds from Web.config.
5 CVEs1 Crit0 KEV4 min - Nº066 JUL 30
ClickHouse SQLi hits 9.1, PCP ships four bugs including a root privesc chain
ClickHouse Server 26.3.9.8 and older have a remote code execution via SQL injection in dictionary creation (CVE-2026-51992, CVSS 9.1). Performance Co-Pilot (PCP) gets hit with four separate vulnerabilities: an unauthenticated metric overwrite to RCE chain, a shell injection in linux_sockets, and a local privesc to root.
5 CVEs1 Crit0 KEV4 min - Nº065 JUL 29
OpenShift oauth-proxy lets you impersonate any user with one header trick
CVE-2026-49332 (CVSS 8.5) abuses underscore/dash header normalization in WSGI and PHP backends. Also: CRIU checkpoint credential tampering, a binutils out-of-bounds write, PhpSpreadsheet SSRF via redirect, and a sg3_utils udev injection requiring physical access.
5 CVEs0 Crit0 KEV4 min - Nº064 JUL 28
A 9.1 SQLi-to-webshell in EasyAppointments and an Ansible auth bypass you can spoof with one header
EasyAppointments 1.5.1 lets attackers dump your database and drop a PHP webshell via blind SQLi (CVE-2025-50455, CVSS 9.1). Red Hat EDA trusts a spoofable HTTP header for mTLS auth (CVE-2026-12383, CVSS 7.5). Also: NitroShare path traversal, two GIMP image parser bugs.
5 CVEs1 Crit0 KEV4 min - Nº063 JUL 27
Three perfect 10s: Azure App Service, AKS, and Data Quality all wide open
Microsoft dropped CVSS 10.0 patches for Azure App Service, Azure Kubernetes Service, and Microsoft Data Quality, all unauthenticated privilege escalation with no user interaction. A Linux kernel use-after-free in traffic control (9.8) and an Azure Portal auth bypass (9.3) round out a heavy day.
5 CVEs5 Crit0 KEV4 min - Nº062 JUL 25
Three CVSS 10.0 Azure bugs in one day, plus AKS and App Service wide open
Azure App Service, Azure Kubernetes Service, and Microsoft Data Quality all have unauthenticated privilege escalation vulnerabilities scoring 10.0. A 9.3 Azure Portal auth bypass leaks data without credentials. Redis gets a double-free RCE fix in 8.8.0.
5 CVEs4 Crit0 KEV4 min - Nº061 JUL 24
ManageEngine ADAudit Plus CVSS 10: unauth RCE through the agent API
A perfect-10 RCE in ADAudit Plus tops the list, followed by a 9.9 deserialization bug in M365 Copilot and a 9.8 auth bypass in Appriss VINE that dumps PII. OpenShift AI and a WordPress plugin round things out.
5 CVEs3 Crit0 KEV4 min - Nº060 JUL 23
Three command injections in Ansible Lightspeed, plus MongoDB RBAC bypass
CVE-2026-44189/44190/44191 all hit CVSS 7.8: opening a malicious project in VS Code gives an attacker shell access. MongoDB also has an 8.1 RBAC bypass (CVE-2026-13059) that lets low-privilege users read and write across tenant boundaries.
5 CVEs0 Crit0 KEV4 min - Nº059 JUL 22Exploited
FortiSandbox, SharePoint, and WordPress RCE all exploited in the wild
Five actively exploited bugs today. Unauthenticated command execution on FortiSandbox (EPSS 0.84), a CVSS 9.8 WordPress REST API chain hitting 6.9.x and 7.0.x, unauth deserialization RCE in on-prem SharePoint, a DD-WRT UPnP overflow, and remote code execution in Langflow.
5 CVEs1 Crit5 KEV4 min - Nº058 JUL 10
Langroid scores a perfect 10 RCE, plus two Juniper DoS bugs that crash your firewall
Langroid's broken eval() sandbox gives attackers full code execution (CVE-2026-54769, CVSS 10.0). A guardrails-detectors SSRF can steal cloud credentials (CVSS 9.3). Two Juniper SRX/MX flaws let a single packet crash flowd if SIP ALG or TCP proxy is active.
5 CVEs2 Crit0 KEV4 min - Nº057 JUL 9
CoreWCF auth bypass scores a perfect 10, Chrome sandbox escape close behind
A broken SAML token check in CoreWCF (CVE-2026-54782, CVSS 10.0) lets anyone forge tokens and impersonate users. Chrome on Android has a 9.6 use-after-free sandbox escape via Autofill, plus a NATS Server auth skip (8.8), a GStreamer DTLS stack overflow (7.5), and a Dynamics 365 XSS (9.3).
5 CVEs3 Crit0 KEV4 min - Nº056 JUL 8
Portal for ArcGIS wide open at CVSS 9.8, plus Coder's broken Azure auth
Esri's Portal for ArcGIS has an unauth API bypass (CVE-2026-13019, 9.8) and a password recovery takeover (8.1). Coder skips PKCS#7 signature checks on Azure identity tokens (9.1). Rancher Fleet and OpenSSH client patches round it out.
5 CVEs2 Crit0 KEV4 min - Nº055 JUL 7
CVSS 10 in Crawl4AI: one HTTP request, full container takeover
Crawl4AI's unauthenticated Docker API lets attackers inject Chromium flags for instant RCE (CVE-2026-57572, CVSS 10.0). Also: Coolify cross-tenant clone bypass at CVSS 9.9, two SSSD bugs that chain LDAP/GPO access into fleet-wide root, and a 13-year-old heap overflow in 389 Directory Server.
5 CVEs2 Crit0 KEV4 min - Nº054 JUL 6
Edge type confusion at CVSS 9.0 and a one-variable path to SYSTEM via Parsec
Two Chromium/Edge RCEs (CVE-2026-58289, CVE-2026-58299), a clean local privesc in Parsec's parsecd.exe service (CVE-2026-54424, CVSS 8.4), and a GraphQL resource exhaustion bug in Red Hat ACS Central.
5 CVEs1 Crit0 KEV4 min - Nº053 JUL 4
Edge type confusion hits CVSS 9.0, Parsec hands out SYSTEM for free
Two Chromium-based Edge RCEs (CVE-2026-58289, CVE-2026-58299), a local-to-SYSTEM privesc in Unity Parsec's parsecd.exe, and a heap overflow in GIMP's PSP file parser. Nothing exploited in the wild yet, but that Edge 9.0 needs your attention.
5 CVEs1 Crit0 KEV4 min - Nº052 JUL 3Exploited
SharePoint RCE exploited in the wild, plus a 9.9 in Entra Provisioning
A deserialization bug in SharePoint Server is already being hit by attackers with basic user access. Microsoft Entra Provisioning (SyncFabric) also has a CVSS 9.9 SSRF, and Keycloak's SAML validation is broken at 7.7.
5 CVEs1 Crit1 KEV4 min - Nº051 JUL 1
IBM Langflow SSRF bypass, Woodpecker CI approval spoofing, and a 64-bit DH key in UltraVNC
Five CVEs today, none exploited in the wild yet. The headliners: an SSRF pair in Langflow that lets authenticated users (or prompt injections) steal cloud IAM creds (CVSS 8.2), a commit-author spoofing bug in Woodpecker CI's GitLab driver that skips pipeline approval gates (CVSS 8.1), and UltraVNC's MS-Logon II auth using a DH prime crackable in under a second (CVSS 7.4). Also on the list: a circular-reference DoS in Microsoft's OpenAPI.NET SDK and a GLib D-Bus XML parser crash.
5 CVEs0 Crit0 KEV4 min
June 2026
23 issues- Nº050 JUN 30
A SUID root dlopen, a VS Code JavaDoc trap, and a Coolify tenant escape
LinuxCNC's rtapi_app hands local users root via path traversal (CVSS 8.4), vscode-java lets crafted JavaDoc popups run arbitrary VS Code commands (CVSS 8.8), and Coolify leaks cross-tenant servers and projects to any authenticated user (CVSS 7.7). Plus a fast-uri parsing mismatch that enables SSRF and a batman-adv use-after-free.
5 CVEs0 Crit0 KEV4 min - Nº049 JUN 29
A 9.8 ksmbd auth bypass headlines a messy Linux Monday
Unauthenticated file attribute takeover in the kernel SMB server (CVE-2026-52944, CVSS 9.8), a path traversal in libzypp that hands root to rogue repos (CVE-2026-25707, CVSS 8.8), and a libssh2 memory corruption bug during SSH auth (CVE-2026-58050, CVSS 7.0). None exploited in the wild yet, but public exploit code exists for the ruoyi-vue-pro upload flaw.
5 CVEs1 Crit0 KEV4 min - Nº048 JUN 28
A 9.8 kernel memory corruption, a libssh2 buffer overwrite, and broken TLS in Node.js undici
batman-adv mesh networking has a remotely exploitable fragment-nesting bug (CVE-2026-52916, CVSS 9.8). libssh2 and Node.js undici also need patches, plus a Vim code execution trick and a QEMU guest escape retry.
5 CVEs1 Crit0 KEV4 min - Nº047 JUN 27
KubeVirt live migration opens an unauth backdoor, plus plaintext OAuth tokens in OpenProject
A disabled-TLS footgun in KubeVirt (CVSS 8.5) lets any pod on the cluster network send raw libvirt commands to another tenant's VM. OpenProject stores SharePoint/OneDrive OAuth tokens in plaintext in Rails.cache (CVSS 8.2). Also: a GPU shader compiler OOB write, an Envoy zstd decompression bomb, and a Budibase account-linking CSRF.
5 CVEs0 Crit0 KEV4 min - Nº046 JUN 26
Keycloak token forgery, KubeVirt auth bypass, and a 9.1 Perl heap read
Keycloak's JWT algorithm confusion lets attackers impersonate any federated user (CVE-2026-11800, CVSS 8.1). KubeVirt's disableTLS flag silently strips all migration auth, exposing raw libvirt RPC to the pod network (CVE-2026-13325, CVSS 8.5). Apicurio Registry has two SSRF bugs, and Perl's Socket module has a 9.1 heap read with near-zero exploit probability.
5 CVEs1 Crit0 KEV4 min - Nº045 JUN 25
Flowise leaks your OAuth secrets unauthenticated, n8n hides SQL injection in column names
5 CVEs today. Flowise exposes SSO client secrets (including Azure and GitHub) to any anonymous GET request (CVSS 7.5). n8n's database nodes let authenticated users inject SQL through table and column identifiers (CVSS 8.2). Also: a Keras path traversal at CVSS 8.1, a Warp terminal command injection under WSL, and a Linux kernel nftables offset bug.
5 CVEs0 Crit0 KEV4 min - Nº044 JUN 24
OpenSSL CMS forgery bug scores 9.1, plus a buffer overflow in Apache mod_proxy_html
CVE-2026-34182 lets attackers forge S/MIME and CMS-signed messages that pass validation. Apache's mod_proxy_html has a remotely exploitable buffer overflow (CVSS 7.5), and there's a Linux kernel privesc in the Topcliff SPI driver. Nothing exploited in the wild yet, but that OpenSSL one needs patching fast.
5 CVEs1 Crit0 KEV4 min - Nº043 JUN 23Exploited
UniFi OS command injection exploited in the wild, Exchange SSRF and ManageEngine SSO bypass waiting in the wings
Two actively exploited command injection bugs (UniFi OS and Lantronix EDS5000) plus a CVSS 8.8 Exchange SSRF and a CVSS 9.0 ManageEngine session prediction flaw that let unauthenticated attackers take over admin accounts.
5 CVEs1 Crit2 KEV4 min - Nº042 JUN 22
Two 9.8s in WordPress plugins, a libaom encoder bug, and two dusty unquoted paths
Unauthenticated RCE in WooCommerce 7.1.0 and full admin takeover via Ultimate Addons for Beaver Builder top the list. If you host WordPress, read this one now.
5 CVEs2 Crit0 KEV4 min - Nº041 JUN 20Exploited
Splunk zero-day: unauthenticated file writes via PostgreSQL sidecar, already exploited
CVE-2026-20253 is being exploited in the wild against Splunk Enterprise with no login required. Also: a CVSS 9.1 OpenSSL signature forgery, two Office RCE bugs at 8.4, and a Linux kernel io_uring privesc.
5 CVEs1 Crit1 KEV4 min - Nº040 JUN 17
Firefox sandbox escape, a Dell RCE, and a Pacemaker crasher walk into your queue
CVE-2026-12289 lets attackers break out of Firefox/Thunderbird's WebRender sandbox (CVSS 8.8). Dell OpenManage and Pacemaker CIB also carry 8.6+ bugs, plus a command injection in Galaxy NG and a TLS bypass between Harvester and Rancher.
5 CVEs0 Crit0 KEV4 min - Nº039 JUN 16
WordPress RCE at 9.8 unauthed, Defender privesc unpatched, OpenSSL nonce fail
A PHP Object Injection in a Salesforce/CF7 WordPress plugin needs no login and scores CVSS 9.8. Microsoft Defender's Malware Protection Engine has a local-to-SYSTEM escalation (CVSS 7.8) with no fix shipped yet. OpenSSL silently ignores IVs in AES-OCB mode, breaking encryption guarantees.
5 CVEs1 Crit0 KEV4 min - Nº038 JUN 15Exploited
PeopleSoft takeover exploited in the wild, plus a 9.1 CMS forgery bug in OpenSSL
An unauthenticated PeopleSoft PeopleTools compromise (CVE-2026-35273) is already being exploited. Also: a CVSS 9.1 CMS AuthEnvelopedData forgery affecting OpenSSL, Node.js, and QEMU (CVE-2026-34182), a Zoom mobile privilege escalation, a public exploit for a Revo Uninstaller kernel driver, and a SQLite FTS5 heap overflow.
5 CVEs1 Crit1 KEV4 min - Nº037 JUN 12
MariaDB Galera hits CVSS 10.0: unauthenticated RCE through a clustering feature
A shell injection in wsrep_notify_cmd gives attackers full code execution on MariaDB Galera clusters with no auth required. Also: a Chrome macOS use-after-free (8.8), a 389 Directory Server heap smash reachable by any domain user (7.6), and a MongoDB server-side JS memory leak (8.8).
5 CVEs1 Crit0 KEV4 min - Nº036 JUN 11
Splunk's 9.8 file-write bug steals the show, plus SQL injection via spreadsheet
Unauthenticated arbitrary file creation in Splunk's PostgreSQL sidecar (CVE-2026-20253, CVSS 9.8), a CVSS 9.6 SQL injection through RVTools .xlsx imports in migration-planner, and an Apache mod_ldap use-after-free at CVSS 8.6. Dulwich on Windows and SQLite FTS5 round out the set.
5 CVEs2 Crit0 KEV4 min - Nº035 JUN 10Patch Tuesday Exploited
Patch Tuesday June 2026: Ivanti Sentry scores a perfect 10, Chrome V8 already under attack
3 bugs exploited in the wild (Chrome V8, Cisco SD-WAN Manager, Arista EOS), plus a CVSS 10.0 unauthenticated RCE in Ivanti Sentry, a 9.3 Windows kernel privesc, and a 9.8 deserialization RCE in Nuance PowerScribe.
6 CVEs3 Crit3 KEV5 min - Nº034 JUN 9
Chrome sandbox escape at 9.6, a VPN auth bypass at 9.3, and Apache httpd going down easy
Google Chrome has a click-to-own sandbox escape (CVE-2026-11697, CVSS 9.6), a VPN auth bypass lets unauthenticated attackers tunnel in via deprecated IKEv1 (CVE-2026-50751, CVSS 9.3), and Apache mod_http2 has a no-auth DoS that can knock your web server offline (CVE-2026-49975, CVSS 7.5). Perl DBI and the Cereal C++ library round out the list.
5 CVEs2 Crit0 KEV4 min - Nº033 JUN 8Exploited
SolarWinds Serv-U DoS exploited in the wild, plus a one-packet Comodo BSOD
CVE-2026-28318 lets unauthenticated attackers crash Serv-U with a single POST request, and attackers are already doing it. Also: a crafted IPv6 packet blue-screens any Windows host running Comodo Internet Security, a Go MIME parsing CPU bomb, and FRRouting BGP crash bugs.
5 CVEs0 Crit1 KEV4 min - Nº032 JUN 5
A perfect 10 in Azure HorizonDB and a Copilot RCE you shouldn't ignore
CVE-2026-48567 is a CVSS 10.0 unauthenticated auth bypass in Azure HorizonDB. Also today: authenticated RCE in Microsoft Copilot (7.7), a Chrome sandbox escape via ImageCapture (7.5), a WordPress site-takeover in Hybrid Composer (9.8), and a DLL-loading trick in SQLite's sqldiff on Windows (9.8).
5 CVEs3 Crit0 KEV4 min - Nº031 JUN 4
OpenShift ClusterRole blows wide open, Cisco UCM goes from SSRF to root
A CVSS 9.6 privilege escalation in OpenShift Pipelines hands any authenticated user write access to Kueue and cert-manager secrets. Plus a Cisco Unified Communications Manager SSRF-to-root chain (CVSS 8.6) and an overprivileged AWS IAM issue in OpenShift Cloud Credential Operator.
5 CVEs1 Crit0 KEV4 min - Nº030 JUN 3
A 9.8 WordPress site takeover, a healthcare RCE, and two NI driver bugs
ARMember Premium lets unauthenticated attackers reset any admin password (CVSS 9.8). Spacelabs Sentinel has a file-write-to-webshell path on port 8989 (CVSS 9.8). NI-PAL driver flaws give local users a privesc and a blue-screen. LibreChat lets any logged-in user hijack another user's API keys.
5 CVEs2 Crit0 KEV4 min - Nº029 JUN 2
SharePoint deser RCE, OpenShift HAProxy injection, and a WordPress SQLi from 2018
CVE-2026-47294 lets any authenticated SharePoint user run code on your server (CVSS 8.0). CVE-2026-1784 turns OpenShift Route objects into HAProxy config injection (CVSS 8.8). Plus an ancient unauthenticated SQLi in WP AutoSuggest finally gets a CVE.
5 CVEs0 Crit0 KEV4 min - Nº028 JUN 1Exploited
PAN-OS auth bypass exploited in the wild, plus a 9.8 in Redshift and a Chrome sandbox escape
Attackers are tunneling through Palo Alto firewalls without credentials right now. Also: Amazon's Redshift Python driver has a CVSS 9.8 RCE via eval(), Chrome's WebGPU layer has a 9.6 sandbox escape, and GitHub CLI is leaking auth tokens to external hosts.
5 CVEs2 Crit1 KEV4 min
May 2026
19 issues- Nº027 MAY 29
Go SSH silently trusts revoked host keys, NGINX rewrite bypass, and an Oracle DB takeover path
CVE-2026-42508 (CVSS 9.1) means your Go SSH tooling ignores @revoked markers in known_hosts. Also: an NGINX rewrite module access-control bypass at CVSS 8.1, a Perl Archive::Tar symlink path traversal at 9.1, and an unauthenticated Oracle Database Net listener takeover at 9.0. None exploited in the wild yet.
5 CVEs4 Crit0 KEV4 min - Nº026 MAY 28Exploited
Two supply chain poisonings, a cPanel root escalation, and a 9.3 XWiki RCE
Nx Console and TanStack were both hijacked briefly on public registries. Any cPanel user can escalate to root via LiteSpeed plugin. XWiki's REST API lets unauthenticated attackers import executable packages (CVSS 9.3). Four of today's five are exploited in the wild.
5 CVEs2 Crit4 KEV4 min - Nº025 MAY 27
Go SSH host key bypass scores 9.1, NGINX rewrite bug close behind at 8.1
A Go knownhosts library flaw lets revoked SSH keys pass verification unchecked. Also: NGINX rewrite module exploit (8.1), Linux kernel privesc via skbuff corruption (7.8), dnsmasq DNS poisoning risk (7.5), and curl cookie leaks hitting Azure Linux packages.
5 CVEs1 Crit0 KEV4 min - Nº024 MAY 26Exploited
Drupal SQLi exploited in the wild, plus a perfect-10 DNS poisoning bug in Unbound
CVE-2026-9082 is an unauth SQLi in Drupal Core already being exploited. CVE-2026-42960 scores CVSS 10.0 for DNS cache poisoning in Unbound on Azure Linux. Also: rsync memory leak (8.1), Memcached SASL timing side channel (8.1), and a Windows DWM privesc (7.8).
5 CVEs1 Crit1 KEV4 min - Nº023 MAY 22
UniFi OS scores a perfect 10.0 RCE, ConnectWise Automate agents can't verify their own updates
Unauthenticated command injection on UniFi OS devices, a supply-chain plugin verification bypass in ConnectWise Automate (CVSS 8.8), a privilege escalation in LiteLLM, and RCE in three ManageEngine products.
5 CVEs1 Crit0 KEV4 min - Nº022 MAY 21
Cisco Secure Workload scores a perfect 10.0: unauth cross-tenant takeover
Also: a use-after-free in Chrome's DOM engine (CVSS 8.8), a no-click heap overflow in Microsoft Defender's scan engine (CVSS 8.1), an Azure privesc via symlink, and a Splunk session cookie leak.
5 CVEs1 Crit0 KEV4 min - Nº021 MAY 20
Keycloak session fixation, a DoS-in-a-packet for 389 DS, and a chroot that does nothing
Five fixes today: Keycloak SSO hijack (CVE-2026-7507, CVSS 7.5), 389 Directory Server DoS via oversized LDAP controls (CVE-2026-9064, CVSS 7.5), Firefox/Thunderbird privesc (CVE-2026-8970, CVSS 7.3), and two local privilege bugs in PluginScript and haveged where security checks exist but never enforce. None exploited in the wild yet.
5 CVEs0 Crit0 KEV4 min - Nº020 MAY 19
Apache Thrift 9.4 RCE headlines a quiet five-patch day
A critical unauthenticated bug in Thrift's Node.js server, a Linux kernel USB gadget privesc, curl SMB connection reuse, a Go panic-crash on Windows, and an FRRouting BGP daemon crasher. Nothing exploited in the wild yet.
5 CVEs1 Crit0 KEV4 min - Nº019 MAY 18
PostgreSQL buffer overflow, NGINX rewrite bypass, and a ksmbd file handle hijack
Three 8.0+ CVSS bugs across PostgreSQL's refint module, NGINX's rewrite engine, and Linux's in-kernel SMB server. None exploited in the wild yet, but the PostgreSQL and ksmbd bugs let authenticated attackers run arbitrary SQL or steal other users' files. GnuTLS DTLS crash and an APM symlink leak round out the set.
5 CVEs0 Crit0 KEV4 min - Nº018 MAY 15
Cisco SD-WAN scores a perfect 10.0, plus dnsmasq and Go HTTP/2 DoS bugs
CVE-2026-20182 lets unauthenticated attackers hijack your entire SD-WAN fabric through vSmart/vManage. Also on the list: a CVSS 8.4 dnsmasq bug with sparse details, a Go net/http2 infinite loop, a GnuTLS auth bypass, and a Twisted DNS crash.
5 CVEs1 Crit0 KEV4 min - Nº017 MAY 14
OpenTelemetry's Azure auth extension doesn't actually check your tokens
A CVSS 8.1 bypass in azureauthextension lets any valid Azure token past your OTel collector. Also: two SOGo SQL injection bugs (PostgreSQL, MariaDB), a busted IPv6 allow-list in Auth Proxy, and a Zoom Rooms installer DLL hijack on Windows.
5 CVEs0 Crit0 KEV4 min - Nº016 MAY 13Patch Tuesday
Patch Tuesday May 2026: DNS and Netlogon RCEs hit 9.8, Hyper-V guest escape, plus 2 Dynamics 9.9s
Two unauthenticated Windows server bugs (DNS heap overflow, Netlogon stack overflow) top the list at CVSS 9.8. A Hyper-V use-after-free scores 9.3 and likely enables guest-to-host escape. Dynamics 365 on-prem has a pair of critical RCEs (9.9 and 9.1), Azure Entra ID leaks tokens at 9.3, and FortiSandbox takes unauthenticated code execution at 9.8. Nothing exploited in the wild yet, but the DNS and Netlogon bugs won't stay quiet long.
20 CVEs11 Crit0 KEV16 min - Nº015 MAY 12
A 9.9 SSRF-to-cred-theft in FireFighter's Jira bot, plus PgBouncer pre-auth overflow
FireFighter's unauthenticated Jira bot endpoint hands attackers your AWS IAM creds on IMDSv1 clusters (CVE-2026-42864, CVSS 9.9). Also: a pre-auth buffer overflow in PgBouncer SCRAM handling (CVE-2026-6665, CVSS 8.1), a Go checksum bypass that poisons builds (CVE-2026-42501, CVSS 7.5), and a Linux kernel rxrpc privesc (CVE-2026-43500, CVSS 7.8).
5 CVEs1 Crit0 KEV4 min - Nº014 MAY 8
Linux ksmbd RCE at 9.8, Azure Cloud Shell injection at 9.6, and a Thrift TLS bypass
Two critical, no-auth bugs top the list: a use-after-free in Linux's in-kernel SMB server (CVE-2026-31718, CVSS 9.8) and command injection in Azure Cloud Shell (CVE-2026-35428, CVSS 9.6). Also covers a hostname verification skip in Apache Thrift's Java TLS transport and an info leak in Edge Copilot Chat.
5 CVEs2 Crit0 KEV4 min - Nº013 MAY 7
Gotenberg SSRF scores 9.4, Apache httpd double-free enables RCE
A deny-list bypass in Gotenberg lets unauthenticated attackers hit your internal APIs (CVE-2026-42596, CVSS 9.4). Apache HTTP Server's mod_http2 has a double-free that could mean remote code execution on any internet-facing instance (CVE-2026-23918, CVSS 8.8). Bandit WebSocket OOM, Kiota credential leaks, and a Linux vidtv kernel bug round it out.
5 CVEs1 Crit0 KEV4 min - Nº012 MAY 6
CVSS 10 in Eclipse BaSyx, unauthenticated admin in OpenCTI, and a no-auth RCE in MeiG IoT
Five CVEs today, none exploited yet but three are unauthenticated and critical. Eclipse BaSyx Java Server SDK scores a perfect 10 via path traversal to RCE, OpenCTI 6.6-6.9.12 hands out admin API access with no credentials, and MeiG FORGE_SLT711 devices allow OS command injection over HTTP. Also: a libssh2 integer overflow (CVSS 7.3) and a Realtek Wi-Fi kernel driver that ships debug ioctls with zero access control (CVSS 7.7).
5 CVEs3 Crit0 KEV4 min - Nº011 MAY 5
A 9.8 kernel-level RCE in Linux ksmbd and 4 more you should know about
Unauthenticated remote code execution in the Linux in-kernel SMB server (CVE-2026-31705, CVSS 9.8), plus an Axios DoS, a Norton Secure VPN privesc, an Amazon WorkSpaces local-to-SYSTEM bug, and a FRR routing daemon flaw on Azure Linux.
5 CVEs1 Crit0 KEV4 min - Nº010 MAY 4
GoBGP double-tap: two 7.3 parser bugs that can kill your BGP sessions
Two unauthenticated crashes in GoBGP's MRT and AIGP parsers, plus unpatched auth bypasses in MindsDB and yudao-cloud with public exploits already circulating. Prefect's WebSocket endpoint is wide open too.
5 CVEs0 Crit0 KEV4 min - Nº009 MAY 1
WordPress auth bypass in one GET request, plus RCE in Krayin CRM
CVE-2026-7567 (CVSS 9.8) lets anyone log into WordPress as a temporary user with a single crafted request. Krayin CRM's compose email function has RCE (CVSS 8.1), and the Pallets Click library has a command injection bug worth checking your Python tooling for.
5 CVEs1 Crit0 KEV4 min
April 2026
8 issues- Nº008 APR 30
ksmbd RCE, a Wazuh cluster takeover, and an OpenSSL use-after-free
Linux's in-kernel SMB server has a CVSS 9.8 buffer bug that looks like unauthenticated RCE. Wazuh cluster sync has a 9.0 path traversal to code execution. OpenSSL's DANE verification has a use-after-free (CVSS 8.1, EPSS near zero) worth watching but not panicking over.
5 CVEs4 Crit0 KEV4 min - Nº007 APR 29ChromeMicrosoftApache Pony Mail
Chrome sandbox escape chain, a WattBox sticker-to-root bug, and a dead Apache project
Two Chrome use-after-free bugs (CVE-2026-7343 + CVE-2026-7341, both CVSS 9.8) chain renderer compromise to full sandbox escape on Windows. Snap One WattBox 800/820 PDUs authenticate diagnostics endpoints with the MAC address printed on the label. Apache Pony Mail (Lua) has a 9.8 account takeover with no fix coming because the project is retired.
5 CVEs5 Crit0 KEV4 min - Nº006 APR 28RouterVPNNetwork Appliance
Five 9.8s on SOHO routers: Totolink and D-Link firmware is Swiss cheese
Four public command injection exploits hit the Totolink A8000RU and one buffer overflow nails the D-Link DI-8100. All CVSS 9.8, all pre-auth, all with public exploit code. If either device is in your stack, pull it off the internet now.
5 CVEs5 Crit0 KEV4 min - Nº005 APR 27RouterWordPressApache MINA
5 bugs at CVSS 9.8: Apache MINA's filter bypassed twice, WordPress plugin to admin in one click
Two deserialization bypasses in Apache MINA let attackers slip past the allowlist for RCE, a WordPress privilege escalation hands out admin roles, and a pair of Totolink router command injections have public exploits. All 9.8, none exploited in the wild yet.
5 CVEs5 Crit0 KEV4 min - Nº004 APR 24MicrosoftWindows
Two perfect 10s: Entra ID SSRF and Bing RCE, both unauth, both wide open
Microsoft Entra ID Entitlement Management has a CVSS 10.0 SSRF that needs no login, and Bing has a CVSS 10.0 deserialization RCE in the same boat. Hackage-server adds two 9.9 stored XSS bugs, plus a 9.8 crasher in Delta Electronics NAS gear.
5 CVEs5 Crit0 KEV4 min - Nº003 APR 23WordPressCMS
Paperclip CVSS 10.0 unauth RCE, plus a 9.9 in FunnelFormsPro and Froxlor
Six API calls and no credentials give attackers full control of default Paperclip installs. FunnelFormsPro (WordPress) and Froxlor both carry 9.9 code execution bugs, and Borg SPM 2007 has two 9.8s that will never be patched.
5 CVEs5 Crit0 KEV4 min - Nº002 APR 22WordPressCMS
AVideo CVSS 10: one WebSocket message owns every viewer, no click needed
A perfect-score stored XSS in AVideo's YPTSocket hits all connected browsers instantly. Also: Flowise command injection (9.9), ElectricSQL SQL injection that gives full PostgreSQL read/write (9.9), an unauth WordPress SMTP hijack via Sendmachine (9.8), and a Firefox DOM security bypass (9.8).
5 CVEs5 Crit0 KEV4 min - Nº001 APR 21ExchangeSpinnakerMicrosoft
Four perfect 10s and a 9.9 sandbox escape: Spinnaker, Perl, and OpenClaw all need attention
Two Spinnaker RCEs (CVE-2026-32613, CVE-2026-32604) let attackers run code through pipeline expressions and gitrepo artifact injection. A 9.9 OpenClaw sandbox escape (CVE-2026-41329) bypasses privilege boundaries. Perl's Storable and Net::Dropbear round out the list with legacy crypto and deserialization bugs, both CVSS 10.0. None are exploited in the wild yet.
5 CVEs5 Crit0 KEV4 min