A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit.
Tracked as CVE-2026-20817, this security flaw resides within the Windows Error Reporting (WER) service.
The vulnerability allows...
U.S. authorities have confirmed that threat actors are actively exploiting a critical vulnerability in FileZen by Soliton Systems K.K..
Due to the high risk associated with this flaw, CISA has officially added it to the Known Exploited Vulnerabilities (KEV) Catalog.
This...
A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems.
Threat actors are leveraging this flaw to execute operating system commands remotely without authentication.
The flaw, discovered in self-hosted BeyondTrust deployments,...
Over 6,000 SmarterMail servers exposed on the internet are running vulnerable versions that are at risk of active remote code execution (RCE) attacks.
Security researchers identified the flaws through daily HTTP vulnerability scans, and exploitation attempts have already been observed...
A critical authentication bypass vulnerability in SmarterTools SmarterMail is actively being exploited in the wild by attackers, according to security researchers at watchTowr Labs.
The vulnerability, tracked as WT-2026-0001, allows unauthenticated attackers to reset the system administrator password without any...
A critical code injection flaw in Hewlett Packard Enterprise OneView, tracked as CVE-2025-37164, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability has been confirmed to be actively exploited by threat actors, triggering urgent remediation timelines for...
Security researchers have released a Proof-of-Concept (PoC) exploit for a critical vulnerability in HPE OneView, a popular IT infrastructure management platform.
The flaw, tracked as CVE-2025-37164, carries a maximum CVSS score of 10.0, indicating immediate danger to enterprise environments.
The vulnerability allows remote...
A proof-of-concept (PoC) exploit has been publicly released for CVE-2025-38352, a race condition vulnerability affecting the Linux kernel's POSIX CPU timer implementation.
The flaw enables attackers to trigger use-after-free conditions in kernel memory, potentially leading to privilege escalation and system...
CISA issued a critical warning regarding a hardcoded cryptographic key vulnerability affecting Gladinet CentreStack and Triofox file management solutions.
The vulnerability, tracked as CVE-2025-14611, poses significant risks to organizations using these widely deployed enterprise file-sharing platforms.
The flaw lies in how...
An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet's FortiGate appliances and related products.
Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated single sign-on (SSO) logins via malicious SAML messages, granting attackers administrative access.
Fortinet disclosed the...