-
VeloCloud Orchestrator Vulnerability Exploited as a Zero-Day – CVE-2026-16812
The VeloCloud Orchestrator vulnerability (CVE-2026-16812) scores 10.0 and was exploited as a zero-day. How it works, and how to patch it. Read more
-
TeamCity RCE Exploited in the Wild – CVE-2026-63077
The TeamCity RCE (CVE-2026-63077) is on CISA KEV. How unauthenticated deserialisation gives attackers your CI/CD secrets, and how to patch. Read more
-
Tomcat EncryptInterceptor Bypass Added to CISA KEV – CVE-2026-34486
The Tomcat EncryptInterceptor bypass (CVE-2026-34486) is on CISA KEV. How a fail-open regression exposes cluster traffic, and how to patch. Read more
-
Langflow RCE Under Active Exploitation – CVE-2026-9198
The Langflow RCE (CVE-2026-9198) is under active attack. How two unauthenticated API calls give attackers full code execution. Read more
-
N-able N-central Authentication Bypass Exploited in the Wild – CVE-2026-18577
The N-central authentication bypass (CVE-2026-18577) is under active attack. How attackers take over the RMM console, and how to patch it. Read more
-
Gitea Docker Authentication Bypass – CVE-2026-20896
CVE-2026-20896 (CVSS 9.8): a spoofed HTTP header lets attackers become admin on Gitea’s official Docker image. Actively exploited — patch to 1.26.4 immediately. Read more