CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.

Vulnerabilities

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe patched a critical authentication bypass in Campaign Classic that enables remote code execution without user interaction. CVE-2026-48449 scores …

Yesterday
Vulnerabilities

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails released patches for a critical flaw in Active Storage that exposes servers to unauthenticated file disclosure attacks. The vulnerabilit…

4 days ago
Vulnerabilities

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in ServiceNow's AI Platform that enables unauthenticated …

Jul 27, 2026
Vulnerabilities

Flaws in Passkey Implementation Show Old Attacks Still Work

Researchers ahead of Black Hat USA disclosed exploitable flaws in Microsoft's passkey implementation that could allow attackers to impersonate privile…

Jul 27, 2026
Vulnerabilities

When AI Attacks: OpenAI Models Autonomously Hack Hugging Face

OpenAI's large language models successfully escaped sandbox environments while pursuing a benign benchmark test objective, demonstrating autonomous ha…

Jul 27, 2026
Vulnerabilities

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Attackers actively exploit CVE-2026-16723, a critical remote code execution flaw in Alibaba's Fastjson JSON library for Java. ThreatBook and Imperva c…

Jul 26, 2026
Vulnerabilities

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Researchers at Zenity Labs disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed attackers to deploy rogue autonomous A…

Jul 24, 2026
Vulnerabilities

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Researchers discovered critical remote code execution vulnerabilities in Microsoft's Bing image search service that allowed arbitrary command executio…

Jul 24, 2026
Vulnerabilities

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Microsoft patched a critical misconfiguration in Azure Automation that exposed organizations to cross-tenant identity takeover attacks. The service's …

Jul 24, 2026
Vulnerabilities

Europe's Multilingual Reality Exposes AI Security Gaps

AI safety guardrails deployed across Europe fail to uniformly protect users across different languages, creating exploitable security gaps that threat…

Jul 24, 2026
Vulnerabilities

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point released patches for multiple vulnerabilities in its Security Management and Multi-Domain Management (MDSM) products after a critical flaw…

Jul 24, 2026
Vulnerabilities

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

A vulnerability chain in the Adobe Acrobat Chrome extension exposed over 314 million users to potential WhatsApp data theft. Guardio Labs researchers …

Jul 23, 2026
Vulnerabilities

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple patched a privacy vulnerability in Hide My Email that exposed users' real email addresses in Mail application logs. The flaw allowed real addres…

Jul 22, 2026
Vulnerabilities

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Researchers have disclosed seven distinct attack vectors targeting five open-source Android AI agent frameworks, including AppAgent and AppAgentX. The…

Jul 22, 2026
Vulnerabilities

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 released patches for CVE-2024-6533, a critical vulnerability in nginx that allows remote attackers to trigger a heap buffer overflow in worker proc…

Jul 20, 2026
Vulnerabilities

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

Anthropic patched a vulnerability in Claude that could automatically relay malicious prompts to AI agents without user intervention. The flaw, tracked…

Jul 20, 2026
Vulnerabilities

2-Click Cursor Exploit Enables Dev Environment Takeover

A two-click cursor exploit allows attackers to seize control of developer environments and access sensitive source code and credentials. The vulnerabi…

Jul 20, 2026
Vulnerabilities

Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear

The White House established Gold Eagle, a new interagency coordination initiative designed to address vulnerability response in AI systems. The progra…

Jul 19, 2026

Get Daily CyberWireDaily

The best stories, delivered to your inbox each morning.

Vulnerabilities context

CVEs, zero-days, patch advisories, and the security flaws putting systems at risk.