CVE analysis & vulnerability intelligence
Long-form threat intelligence on specific CVEs: technical context, PoC and exploit discussion, and remediation priorities.
102 posts
- CVE-2026-104286: fortimail path traversal
- CVE-2026-76460: cisco ise authentication bypass
- CVE-2026-88771: citrix netscaler rce
- CVE-2026-65660: microsoft sharepoint code injection rce
- CVE-2026-87902: wordpress rce
- CVE-2025-39964: linux kernel af alg race condition
- CVE-2025-39682: linux kernel tls improper check
- CVE-2026-20079: cisco secure fmc authentication bypass
- CVE-2025-25249: critical fortinet fortios heap overflow
- CVE-2019-1068: microsoft sql server rce
- CVE-2026-19478: gitlab graphql code injection
- CVE-2026-15748: forminator wordpress rce
- CVE-2025-62593: ray rce
- CVE-2013-4786: ipmi bmc authentication flaw
- CVE-2026-18577: n able n central authentication bypass
- CVE-2026-50522: sharepoint rce
- CVE-2026-16232: check point smartconsole auth bypass
- CVE-2026-15410: sonicwall sma1000 code injection
- CVE-2026-14266: 7 zip xz rce
- CVE-2026-60137: wordpress sql injection rce
- CVE-2026-63030: wordpress pre auth rce
- CVE-2026-46817: oracle ebs payments remote takeover
- CVE-2026-15409: sonicwall sma1000 ssrf
- CVE-2026-55200: libssh2 out of bounds write
- CVE-2026-53359: januscape kvm escape
- CVE-2026-50656: rogueplanet defender lpe
- CVE-2026-48282: adobe coldfusion rce
- CVE-2026-45659: sharepoint rce
- CVE-2026-48558: simplehelp authentication bypass
- CVE-2026-12569: ptc windchill flexplm rce
- CVE-2025-3248: langflow rce
- CVE-2025-67038: lantronix eds5000 rce
- CVE-2026-41089: windows netlogon rce
- CVE-2026-8732: wp maps pro admin takeover
- CVE-2026-11645: chrome v8 zero day
- CVE-2026-20230: cisco unified cm ssrf rce
- CVE-2026-10520: ivanti sentry os command injection
- CVE-2026-20253: splunk enterprise postgresql sidecar rce
- CVE-2026-20262: cisco catalyst sd wan manager file write
- CVE-2026-50751: checkpoint vpn auth bypass
- CVE-2026-35273: oracle peoplesoft zero day rce
- CVE-2025-8088: winrar path traversal
- CVE-2026-9082: drupal sql injection
- CVE-2026-20245: cisco catalyst sd wan manager
- CVE-2022-0492: linux kernel privilege escalation container escape
- CVE-2026-42897: microsoft exchange xss
- CVE-2025-48595: android framework integer overflow
- CVE-2018-17144: bitcoin core dos
- CVE-2026-42945: nginx rce
- CVE-2024-21182: oracle weblogic active exploitation
- CVE-2026-0257: palo alto globalprotect auth bypass
- CVE-2026-41940: cpanel whm auth bypass
- CVE-2025-34291: langflow cors rce
- CVE-2026-23918: apache httpd modhttp2 double free
- CVE-2024-12802: sonicwall gen6 mfa bypass
- CVE-2026-20182: cisco sd wan auth bypass
- CVE-2024-57726: simplehelp privilege escalation
- CVE-2020-17103: mini plasma windows lpe
- CVE-2025-48700: zimbra collaboration suite xss
- CVE-2024-52911: bitcoin core memory bug
- CVE-2026-0300: palo alto pan os captive portal rce
- CVE-2024-1708: connectwise screenconnect path traversal
- CVE-2026-0073: android adb zero click rce
- CVE-2025-20333: cisco asa ftd rce
- CVE-2025-59528: flowise critical rce
- CVE-2026-31431: copy fail linux kernel
- CVE-2023-50224: tp link auth bypass
- CVE-2025-29635: dlink dir823x command injection
- CVE-2026-34197: apache activemq rce
- CVE-2009-0238: microsoft excel rce
- CVE-2023-33538: tp link command injection
- CVE-2026-33017: langflow rce
- CVE-2024-3721: tbk dvr mirai botnet
- CVE-2026-34621: adobe acrobat reader prototype pollution
- CVE-2025-0520: showdoc unauthenticated file upload rce
- CVE-2026-21643: forticlient ems sql injection
- CVE-2026-20093: cisco imc auth bypass
- CVE-2026-5281: chrome dawn webgpu use after free
- CVE-2026-35616: forticlient ems pre auth bypass
- CVE-2026-21992: oracle identity manager rce
- CVE-2021-22054: vmware workspace one ssrf
- CVE-2021-22681: rockwell automation auth bypass
- CVE-2025-31277: apple webkit buffer overflow
- CVE-2026-3055: citrix netscaler memory overread
- CVE-2025-53521: f5 big ip apm rce
- CVE-2023-43010: apple ios coruna exploit
- CVE-2025-66376: zimbra xss
- CVE-2024-6825: LiteLLM Infrastructure Ecosystem
- CVE-2026-20131: cisco fmc rce
- CVE-2023-50428: bitcoin core datacarrier bypass
- CVE-2025-32975: quest kace sma auth bypass
- CVE-2026-1731: beyondtrust remote support rce
- CVE-2025-47813: wing ftp server info disclosure
- CVE-2026-20127: cisco sd wan auth bypass
- CVE-2025-68613: n8n rce
- CVE-2025-59536: anthropic claude code rce
- CVE-2025-26399: solarwinds web help desk rce
- CVE-2022-20775: cisco sd wan path traversal
- CVE-2026-0628: google chrome gemini panel
- CVE-2025-55182: react2shell rce
- CVE-2025-40538: solarwinds serv u broken access control
- CVE-2017-7921: hikvision authentication bypass
