A critical authentication bypass vulnerability in Nginx UI, tracked as CVE-2026-33032 with a maximum CVSS score of 9.8, is currently being actively exploited in the wild.
This flaw allows unauthenticated remote attackers to gain complete control over affected Nginx web...
A highly sophisticated, unpatched zero-day exploit is actively targeting users of Adobe Reader. Detected by the EXPMON threat-hunting system, this malicious PDF file is designed to steal sensitive local data and perform advanced system fingerprinting.
The exploit functions flawlessly on...
A critical security flaw has been disclosed in the Nginx-UI backup restore mechanism, tracked as CVE-2026-33026.
This vulnerability allows threat actors to tamper with encrypted backup archives and inject malicious configurations during the restoration process.
With a public Proof-of-Concept (PoC) exploit...
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the Langflow platform to its Known Exploited Vulnerabilities (KEV) catalog on March 25, 2026.
The vulnerability, tracked as CVE-2026-33017, involves a highly dangerous code injection...
A critical vulnerability in Craft CMS (CVE-2025-32432) has been added to the Known Exploited Vulnerabilities catalog following confirmed active exploitation in the wild.
Security teams and system administrators are advised to address this issue immediately to prevent severe network compromises.
The...
An urgent warning regarding three critical Apple vulnerabilities that threat actors are actively exploiting in the wild.
These security flaws, officially tracked as CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520, were recently added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
Security researchers have linked...
An urgent warning highlights a critical zero-day in Cisco products, now added to the CISA Known Exploited Vulnerabilities Catalog after active exploitation in ransomware campaigns.Network defenders and security administrators are urged to take immediate action.
The rapid exploitation of this...
CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog.
Tracked as CVE-2025-66376, this security flaw is currently facing active exploitation in the wild. Organizations utilizing Zimbra must urgently prioritize remediation...
An urgent warning regarding two highly critical zero-day vulnerabilities affecting Google Chrome and related products.
These flaws have been officially added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating that malicious hackers are actively exploiting them in the wild.
With the...
The Google Threat Intelligence Group (GTIG) released its annual analysis, confirming that 90 zero-day vulnerabilities were actively exploited in the wild throughout 2025.
While this marks a slight decrease from the record 100 zero-days in 2023, it represents a noticeable...