CVE-2026-87902: Actively Exploited, but Preconditions Decide Your Real Exposure
WordPress core's CVSS 9.2 path traversal drew exploitation attempts within hours of the patch. It is also a case study in why a vulnerable version is not the same as an exploitable one — the route to code execution depends on a site's theme layout and PHP configuration.
CISA KEV Alert: Ray's Browser-Triggered RCE Flaw Is Now Actively Exploited
A critical Ray vulnerability lets a malicious webpage hijack a developer's local AI cluster through DNS rebinding — CISA's KEV listing confirms it's no longer theoretical.
ServiceNow AI Platform Flaw (CVE-2026-6875) Now Under Active Exploitation
A pre-authentication sandbox-escape bug in ServiceNow's AI Platform is being exploited in the wild via a second gadget chain, weeks after a patch and public disclosure.
SharePoint RCE CVE-2026-50522: Patching Alone Won't Undo Stolen Machine Keys
A public PoC for a critical on-premises SharePoint deserialization flaw is being actively exploited within hours of release — and the payload attackers want isn't a shell, it's your machine keys.
Fastjson 1.x RCE (CVE-2026-16723) Is Under Active Attack — No Patch Yet
A critical, unauthenticated RCE in Alibaba's Fastjson 1.x is being exploited against Spring Boot fat-JAR deployments, and there is still no fixed 1.x release.