Security Advisories
Disclosure bulletins
Dated advisories from research and client engagements — severity, affected products, technical root cause, and remediation guidance, published under coordinated disclosure.
49 advisories published
Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)
Analysis of CVE-2026-55040, a critical Microsoft SharePoint weak authentication vulnerability allowing unauthenticated remote security bypass.
Broadcom VMware vCenter Path Traversal Vulnerability (CVE-2026-59310): Action Required
Unauthenticated RCE in Broadcom VMware vCenter (CVE-2026-59310) enables full appliance compromise. Review attack paths and forensic triage steps.
Critical Microsoft IKE Service RCE (CVE-2026-33824): Urgent Patch Required
A critical double-free flaw in Microsoft Internet Key Exchange (IKE) Service Extensions (CVE-2026-33824) allows unauthenticated remote code execution.
CVE-2025-62593: Cross-Site Code Injection Risk in Ray AI Framework
CVE-2025-62593 allows attackers to execute arbitrary code in Ray-Project Ray via browser-based CSRF attacks in Firefox and Safari.
Metabase SQL Injection Vulnerability (CVE-2026-72898) Enables Full System Takeover
An unauthenticated Metabase SQL injection vulnerability (CVE-2026-72898) allows remote attackers to compromise application databases and steal credentials.
CVE-2026-68820: Windows Ancillary Function Driver UAF Escalation Analysis
An analysis of CVE-2026-68820, a high-severity use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys).
Cisco ASA and FTD Vulnerability CVE-2026-20349 Allows Remote Denial of Service
Cisco issued updates for CVE-2026-20349, a high-severity heap inspection flaw in ASA and FTD firewalls that allows remote unauthenticated device crashes.
Progress LoadMaster Critical Command Injection Advisory (CVE-2026-8037)
A critical command injection vulnerability in Progress LoadMaster (CVE-2026-8037) allows unauthenticated remote attackers to execute arbitrary commands.
CVE-2026-63077: Critical RCE Flaw in JetBrains TeamCity Agent Polling Protocol
JetBrains TeamCity contains a critical unauthenticated deserialization flaw (CVE-2026-63077) allowing remote code execution via the agent polling protocol.
IBM Langflow CVE-2026-9198: Critical RCE Vulnerability in AI Frameworks
An unauthenticated code injection vulnerability in IBM Langflow (CVE-2026-9198) allows full remote code execution on default deployments.
No advisories match your search.