Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept (PoC) has been released for CVE-2026-55200, a critical vulnerability in the libssh2 client-side SSH library. The flaw, with a…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
A public proof-of-concept (PoC) has been released for CVE-2026-55200, a critical vulnerability in the libssh2 client-side SSH library. The flaw, with a…
SimpleHelp Authentication Bypass Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on…
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed…
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the…
CVE-2021-26855 is a critical vulnerability in Microsoft Exchange Server that allows remote code execution. It was exploited in the StrikeShark campaign to…
CVE-2023-32315 is a path traversal vulnerability in Openfire, an XMPP server. It was exploited in the StrikeShark campaign to target Taiwanese software…
CVE-2024-36401 is a critical remote code execution vulnerability in GeoServer. It was used in the StrikeShark campaign to target a Colombian organization.
CVE-2016-4437 is a vulnerability in Apache Shiro that allows remote code execution. It was listed among the flaws exploited in the StrikeShark…
CVE-2021-27076 is a remote code execution vulnerability in Microsoft SharePoint. In StrikeShark, it was used to trigger a DLL side-loading chain to…
CVE-2022-27925 is a vulnerability in Zimbra Collaboration Suite that allows remote code execution. It was used in the StrikeShark campaign.