CVE analysis & vulnerability intelligence

Long-form threat intelligence on specific CVEs: technical context, PoC and exploit discussion, and remediation priorities.

102 posts

  1. CVE-2026-104286: fortimail path traversal
  2. CVE-2026-76460: cisco ise authentication bypass
  3. CVE-2026-88771: citrix netscaler rce
  4. CVE-2026-65660: microsoft sharepoint code injection rce
  5. CVE-2026-87902: wordpress rce
  6. CVE-2025-39964: linux kernel af alg race condition
  7. CVE-2025-39682: linux kernel tls improper check
  8. CVE-2026-20079: cisco secure fmc authentication bypass
  9. CVE-2025-25249: critical fortinet fortios heap overflow
  10. CVE-2019-1068: microsoft sql server rce
  11. CVE-2026-19478: gitlab graphql code injection
  12. CVE-2026-15748: forminator wordpress rce
  13. CVE-2025-62593: ray rce
  14. CVE-2013-4786: ipmi bmc authentication flaw
  15. CVE-2026-18577: n able n central authentication bypass
  16. CVE-2026-50522: sharepoint rce
  17. CVE-2026-16232: check point smartconsole auth bypass
  18. CVE-2026-15410: sonicwall sma1000 code injection
  19. CVE-2026-14266: 7 zip xz rce
  20. CVE-2026-60137: wordpress sql injection rce
  21. CVE-2026-63030: wordpress pre auth rce
  22. CVE-2026-46817: oracle ebs payments remote takeover
  23. CVE-2026-15409: sonicwall sma1000 ssrf
  24. CVE-2026-55200: libssh2 out of bounds write
  25. CVE-2026-53359: januscape kvm escape
  26. CVE-2026-50656: rogueplanet defender lpe
  27. CVE-2026-48282: adobe coldfusion rce
  28. CVE-2026-45659: sharepoint rce
  29. CVE-2026-48558: simplehelp authentication bypass
  30. CVE-2026-12569: ptc windchill flexplm rce
  31. CVE-2025-3248: langflow rce
  32. CVE-2025-67038: lantronix eds5000 rce
  33. CVE-2026-41089: windows netlogon rce
  34. CVE-2026-8732: wp maps pro admin takeover
  35. CVE-2026-11645: chrome v8 zero day
  36. CVE-2026-20230: cisco unified cm ssrf rce
  37. CVE-2026-10520: ivanti sentry os command injection
  38. CVE-2026-20253: splunk enterprise postgresql sidecar rce
  39. CVE-2026-20262: cisco catalyst sd wan manager file write
  40. CVE-2026-50751: checkpoint vpn auth bypass
  41. CVE-2026-35273: oracle peoplesoft zero day rce
  42. CVE-2025-8088: winrar path traversal
  43. CVE-2026-9082: drupal sql injection
  44. CVE-2026-20245: cisco catalyst sd wan manager
  45. CVE-2022-0492: linux kernel privilege escalation container escape
  46. CVE-2026-42897: microsoft exchange xss
  47. CVE-2025-48595: android framework integer overflow
  48. CVE-2018-17144: bitcoin core dos
  49. CVE-2026-42945: nginx rce
  50. CVE-2024-21182: oracle weblogic active exploitation
  51. CVE-2026-0257: palo alto globalprotect auth bypass
  52. CVE-2026-41940: cpanel whm auth bypass
  53. CVE-2025-34291: langflow cors rce
  54. CVE-2026-23918: apache httpd modhttp2 double free
  55. CVE-2024-12802: sonicwall gen6 mfa bypass
  56. CVE-2026-20182: cisco sd wan auth bypass
  57. CVE-2024-57726: simplehelp privilege escalation
  58. CVE-2020-17103: mini plasma windows lpe
  59. CVE-2025-48700: zimbra collaboration suite xss
  60. CVE-2024-52911: bitcoin core memory bug
  61. CVE-2026-0300: palo alto pan os captive portal rce
  62. CVE-2024-1708: connectwise screenconnect path traversal
  63. CVE-2026-0073: android adb zero click rce
  64. CVE-2025-20333: cisco asa ftd rce
  65. CVE-2025-59528: flowise critical rce
  66. CVE-2026-31431: copy fail linux kernel
  67. CVE-2023-50224: tp link auth bypass
  68. CVE-2025-29635: dlink dir823x command injection
  69. CVE-2026-34197: apache activemq rce
  70. CVE-2009-0238: microsoft excel rce
  71. CVE-2023-33538: tp link command injection
  72. CVE-2026-33017: langflow rce
  73. CVE-2024-3721: tbk dvr mirai botnet
  74. CVE-2026-34621: adobe acrobat reader prototype pollution
  75. CVE-2025-0520: showdoc unauthenticated file upload rce
  76. CVE-2026-21643: forticlient ems sql injection
  77. CVE-2026-20093: cisco imc auth bypass
  78. CVE-2026-5281: chrome dawn webgpu use after free
  79. CVE-2026-35616: forticlient ems pre auth bypass
  80. CVE-2026-21992: oracle identity manager rce
  81. CVE-2021-22054: vmware workspace one ssrf
  82. CVE-2021-22681: rockwell automation auth bypass
  83. CVE-2025-31277: apple webkit buffer overflow
  84. CVE-2026-3055: citrix netscaler memory overread
  85. CVE-2025-53521: f5 big ip apm rce
  86. CVE-2023-43010: apple ios coruna exploit
  87. CVE-2025-66376: zimbra xss
  88. CVE-2024-6825: LiteLLM Infrastructure Ecosystem
  89. CVE-2026-20131: cisco fmc rce
  90. CVE-2023-50428: bitcoin core datacarrier bypass
  91. CVE-2025-32975: quest kace sma auth bypass
  92. CVE-2026-1731: beyondtrust remote support rce
  93. CVE-2025-47813: wing ftp server info disclosure
  94. CVE-2026-20127: cisco sd wan auth bypass
  95. CVE-2025-68613: n8n rce
  96. CVE-2025-59536: anthropic claude code rce
  97. CVE-2025-26399: solarwinds web help desk rce
  98. CVE-2022-20775: cisco sd wan path traversal
  99. CVE-2026-0628: google chrome gemini panel
  100. CVE-2025-55182: react2shell rce
  101. CVE-2025-40538: solarwinds serv u broken access control
  102. CVE-2017-7921: hikvision authentication bypass