CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability affecting PTC Windchill PDMlink and PTC…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability affecting PTC Windchill PDMlink and PTC…
A now-patched flaw in WinRAR (CVE-2025-8088) was weaponized by Gamaredon to place malicious HTA downloaders into the Windows Startup folder, enabling automatic…
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in…
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can…
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers…
A 17-year-old remote code execution vulnerability in FreeBSD's NFS server, discovered and exploited by Anthropic's Mythos AI model. Demonstrates AI's capability to…
CVE-2026-45657 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-47291 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-44815 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-45655 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…