The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability affecting Progress Kemp LoadMaster to its Known…
active exploitationBOD 26-04CISA KEVcommand injection
N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed…
Metabase has disclosed a maximum-severity zero-day vulnerability in its business intelligence and data visualization software that is being actively exploited in the…
CVE-2023-38646 is a critical vulnerability in Metabase that allows pre-authenticated remote code execution on affected installations. With a CVSS score of 9.8,…
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting vulnerability in WordPress's login screen. It allows unauthenticated attackers to execute arbitrary JavaScript in…
A use-after-free vulnerability in Linux's SCTP networking code, tracked as CVE-2026-64564 and named SCTPhantom, could allow local users to gain root privileges…
A use-after-free vulnerability in Linux's SCTP networking code, present since 2008, allows local users to gain root and potentially escape containers. Patched…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack…
Black Hat USA 2026CVE-2026-50522CVE-2026-56181CVE-2026-63913
PortSwigger's AI-assisted research system, HTTP Terminator, has generated and proven new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The system,…