LIVE THREAT FEED

Threat Intelligence

CISA Known Exploited Vulnerabilities + real-time security news. Updated every 30 minutes.

Last refreshed: May 25, 2026, 5:23 p.m. PT

CISA KEVKnown Exploited Vulnerabilities
cisa.gov ↗
CVE-2026-9082
Added May 22, 2026

Drupal Core SQL Injection Vulnerability

DrupalCore

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 27, 2026
CVE-2025-34291
Added May 21, 2026

Langflow Origin Validation Error Vulnerability

LangflowLangflow

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 4, 2026
CVE-2026-34926
Added May 21, 2026

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend MicroApex One

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 4, 2026
CVE-2008-4250
Added May 20, 2026

Microsoft Windows Buffer Overflow Vulnerability

MicrosoftWindows

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2009-1537
Added May 20, 2026

Microsoft DirectX NULL Byte Overwrite Vulnerability

MicrosoftDirectX

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2009-3459
Added May 20, 2026

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

AdobeAcrobat and Reader

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2010-0249
Added May 20, 2026

Microsoft Internet Explorer Use-After-Free Vulnerability

MicrosoftInternet Explorer

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2010-0806
Added May 20, 2026

Microsoft Internet Explorer Use-After-Free Vulnerability

MicrosoftInternet Explorer

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2026-41091
Added May 20, 2026

Microsoft Defender Link Following Vulnerability

MicrosoftDefender

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2026-45498
Added May 20, 2026

Microsoft Defender Denial of Service Vulnerability

MicrosoftDefender

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Jun 3, 2026
CVE-2026-42897
Added May 15, 2026

Microsoft Exchange Server Cross-Site Scripting Vulnerability

MicrosoftMicrosoft

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 29, 2026
CVE-2026-20182
Added May 14, 2026

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

CiscoCatalyst SD-WAN

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Remediation due: May 17, 2026
CVE-2026-42208
Added May 8, 2026

BerriAI LiteLLM SQL Injection Vulnerability

BerriAILiteLLM

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 11, 2026
CVE-2026-6973
Added May 7, 2026

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

IvantiEndpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 10, 2026
CVE-2026-0300
Added May 6, 2026

Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability

Palo Alto NetworksPAN-OS

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: - Restrict User-ID Authentication Portal access to only trusted zones. - Disable User-ID Authentication Portal if not required. 5/13/2026: Palo Alto has released a variety of patches. If these are relevant to your environment, please apply the designated patch.
Remediation due: May 9, 2026
CVE-2026-31431
Added May 1, 2026

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

LinuxKernel

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

Required Action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 15, 2026
CVE-2026-41940
🔴 RansomwareAdded Apr 30, 2026

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebProscPanel & WHM and WP2 (WordPress Squared)

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 3, 2026
CVE-2024-1708
🔴 RansomwareAdded Apr 28, 2026

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWiseScreenConnect

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 12, 2026
CVE-2026-32202
Added Apr 28, 2026

Microsoft Windows Protection Mechanism Failure Vulnerability

MicrosoftWindows

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 12, 2026
CVE-2025-29635
Added Apr 24, 2026

D-Link DIR-823X Command Injection Vulnerability

D-LinkDIR-823X

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 8, 2026
CVE-2024-7399
Added Apr 24, 2026

Samsung MagicINFO 9 Server Path Traversal Vulnerability

SamsungMagicINFO 9 Server

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 8, 2026
CVE-2024-57728
🔴 RansomwareAdded Apr 24, 2026

SimpleHelp Path Traversal Vulnerability

SimpleHelp SimpleHelp

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 8, 2026
CVE-2024-57726
🔴 RansomwareAdded Apr 24, 2026

SimpleHelp Missing Authorization Vulnerability

SimpleHelp SimpleHelp

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 8, 2026
CVE-2026-39987
Added Apr 23, 2026

Marimo Remote Code Execution Vulnerability

MarimoMarimo

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 7, 2026
CVE-2026-33825
Added Apr 22, 2026

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

MicrosoftDefender

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 6, 2026
CVE-2026-20122
Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

CiscoCatalyst SD-WAN Manger

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Remediation due: Apr 23, 2026
CVE-2026-20133
Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CiscoCatalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Remediation due: Apr 23, 2026
CVE-2025-2749
Added Apr 20, 2026

Kentico Xperience Path Traversal Vulnerability

KenticoKentico Xperience

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 4, 2026
CVE-2023-27351
🔴 RansomwareAdded Apr 20, 2026

PaperCut NG/MF Improper Authentication Vulnerability

PaperCutNG/MF

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 4, 2026
CVE-2025-48700
Added Apr 20, 2026

Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability

SynacorZimbra Collaboration Suite (ZCS)

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 23, 2026
CVE-2026-20128
Added Apr 20, 2026

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

CiscoCatalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

Required Action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Remediation due: Apr 23, 2026
CVE-2025-32975
Added Apr 20, 2026

Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

QuestKACE Systems Management Appliance (SMA)

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 4, 2026
CVE-2024-27199
🔴 RansomwareAdded Apr 20, 2026

JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrainsTeamCity

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: May 4, 2026
CVE-2026-34197
Added Apr 16, 2026

Apache ActiveMQ Improper Input Validation Vulnerability

ApacheActiveMQ

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 30, 2026
CVE-2009-0238
Added Apr 14, 2026

Microsoft Office Remote Code Execution

MicrosoftOffice

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 28, 2026
CVE-2026-32201
Added Apr 14, 2026

Microsoft SharePoint Server Improper Input Validation Vulnerability

MicrosoftSharePoint Server

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 28, 2026
CVE-2012-1854
Added Apr 13, 2026

Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

MicrosoftVisual Basic for Applications (VBA)

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 27, 2026
CVE-2025-60710
Added Apr 13, 2026

Microsoft Windows Link Following Vulnerability

MicrosoftWindows

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 27, 2026
CVE-2023-21529
🔴 RansomwareAdded Apr 13, 2026

Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

MicrosoftExchange Server

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 27, 2026
CVE-2023-36424
Added Apr 13, 2026

Microsoft Windows Out-of-Bounds Read Vulnerability

MicrosoftWindows

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 27, 2026
CVE-2020-9715
Added Apr 13, 2026

Adobe Acrobat Use-After-Free Vulnerability

AdobeAcrobat

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 27, 2026
CVE-2026-21643
Added Apr 13, 2026

Fortinet FortiClient EMS SQL Injection Vulnerability

FortinetFortiClient EMS

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 16, 2026
CVE-2026-34621
Added Apr 13, 2026

Adobe Acrobat and Reader Prototype Pollution Vulnerability

AdobeAcrobat and Reader

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 27, 2026
CVE-2026-1340
Added Apr 8, 2026

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

IvantiEndpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 11, 2026
CVE-2026-35616
Added Apr 6, 2026

Fortinet FortiClient EMS Improper Access Control Vulnerability

FortinetFortiClient EMS

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 9, 2026
CVE-2026-3502
Added Apr 2, 2026

TrueConf Client Download of Code Without Integrity Check Vulnerability

TrueConfClient

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 16, 2026
CVE-2026-5281
Added Apr 1, 2026

Google Dawn Use-After-Free Vulnerability

GoogleDawn

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 15, 2026
CVE-2026-3055
Added Mar 30, 2026

Citrix NetScaler Out-of-Bounds Read Vulnerability

CitrixNetScaler

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 2, 2026
CVE-2025-53521
Added Mar 27, 2026

F5 BIG-IP Stack-Based Buffer Overflow Vulnerability

F5BIG-IP

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Mar 30, 2026
CVE-2026-33634
Added Mar 26, 2026

Aquasecurity Trivy Embedded Malicious Code Vulnerability

AquasecurityTrivy

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any sensitive configuration in memory.

Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation due: Apr 9, 2026
LIVEVulnerability News
SANS ISCMay 26, 2026

Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)

Introduction
…

BleepingComputerMay 25, 2026

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. [...]…

SANS ISCMay 25, 2026

Microsoft Access VBA, (Mon, May 25th)

Microsoft Access files (Microsoft Office&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s Database) can contain VBA code.
…

The Hacker NewsMay 25, 2026

⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old …

SANS ISCMay 25, 2026

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appea…

SANS ISCMay 25, 2026

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appea…

Krebs on SecurityMay 25, 2026

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campa…

BleepingComputerMay 25, 2026

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authen…

The Hacker NewsMay 25, 2026

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploit…

The Hacker NewsMay 25, 2026

The Alert Firehose Finally Meets Its Match

Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually u…

The Hacker NewsMay 25, 2026

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. Remo…

The Hacker NewsMay 25, 2026

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious pack…

SANS ISCMay 24, 2026

Wireshark 4.6.6 Released, (Sun, May 24th)

Wireshark release 4.6.6 fixes 1 vulnerability and 11 bugs.
…

BleepingComputerMay 24, 2026

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]…

BleepingComputerMay 23, 2026

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious cod…

The Hacker NewsMay 23, 2026

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for instal…

The Hacker NewsMay 23, 2026

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were…

BleepingComputerMay 23, 2026

Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. [...]…

The Hacker NewsMay 23, 2026

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cyb…

SANS ISCMay 23, 2026

An Example of Stack String in High Level Language, (Sat, May 23rd)

This week, I&#x27m attending the SEC670[1] training (“Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control”). From my point of view, this training fi…

BleepingComputerMay 22, 2026

Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. [...]…

Krebs on SecurityMay 22, 2026

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published …

BleepingComputerMay 22, 2026

Former US execs plead guilty to aiding tech support scammers

Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]…

BleepingComputerMay 22, 2026

Trend Micro warns of Apex One zero-day exploited in the wild

Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. [...]…

Krebs on SecurityMay 21, 2026

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of mass…

Krebs on SecurityMay 18, 2026

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts a…

Krebs on SecurityMay 12, 2026

Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on…

Krebs on SecurityMay 8, 2026

Canvas Breach Disrupts Schools & Colleges Nationwide

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime gro…