Chrome Firefox security update July 2026 delivered emergency patches across five vendors on July 15: Mozilla confirmed public exploit code for both critical Firefox 152.0.6 CVEs, Google patched two ...
CISA adds Progress Kemp LoadMaster CVE-2026-8037 to KEV after active exploitation reports, with 792 attempts logged across 65 ...
ServiceNow CVE-2026-6875, a critical unauthenticated RCE in the AI Platform, is under active exploitation. Threat intelligence firm Defused confirmed a second sandbox-escape gadget chain that bypasses ...
A newly published BootROM exploit targeting iPhone 11 and A12/A13 chips has been pulled offline after Magnet Forensics sued the researchers who disclosed it. The vulnerability cannot be patched ...
CVE-2026-63077 could let unauthenticated attackers bypass TeamCity checks and run OS commands; JetBrains patched all ...
Windows Server 2025 is currently open to a Remote Code Execution exploit via the Windows Update Service, and at the time of this writing a fix from Microsoft has yet to fully patch the issue. Reports ...
Contrast Security has launched CVE Shield, a runtime control that detects, monitors and blocks exploitation of known vulnerabilities in production ...
Threat actors are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in the WordPress theme 'Alone,' to achieve remote code execution and perform a full site takeover.
The risk of attackers exploiting a recently disclosed maximum severity vulnerability in Cisco's IOS XE Wireless Controller software has increased significantly following the public release of detailed ...
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code ...