Unpatched GeoServer Zero-Day Actively Exploited, Could Lead to Remote Code Execution
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
CVE-2026-33634 is a critical vulnerability in the Trivy scanner ecosystem, exploited in a supply-chain attack that also affected LiteLLM. Added to CISA's…
Cisco has disclosed that a high-severity vulnerability in its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD)…
Security researcher Chaotic Eclipse (also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day…
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04…
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability Apply mitigations in accordance with vendor…
Metabase SQL Injection Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability affecting Progress Kemp LoadMaster to its Known…
Progress LoadMaster Command Injection Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…