Back to Blog

Vulnerability Management

10 articles on this topic.

Vulnerabilities & Exploitation29 September 2026

CVE-2026-87902: Actively Exploited, but Preconditions Decide Your Real Exposure

WordPress core's CVSS 9.2 path traversal drew exploitation attempts within hours of the patch. It is also a case study in why a vulnerable version is not the same as an exploitable one — the route to code execution depends on a site's theme layout and PHP configuration.

wordpresscve-2026-87902path-traversal
6 min readRead
Vulnerability Management17 September 2026

Cisco ISE Zero-Day (CVE-2026-76460, CVSS 10.0) Actively Exploited — No Workaround

A maximum-severity authentication bypass in Cisco Identity Services Engine is being exploited in the wild, with no interim mitigation beyond restricting network access — patching is the only real fix.

ciscoisecve-2026-76460
4 min readRead
Vulnerability Management10 September 2026

Microsoft's Record 973-CVE Patch Tuesday: Two SYSTEM-Level Zero-Days Under Attack

September 2026 is Microsoft's largest Patch Tuesday on record, and two of the fixes — both elevation-of-privilege bugs — are already being exploited to seize SYSTEM control on Windows machines.

patch-tuesdaywindows-securityzero-day
4 min readRead
Vulnerability Management6 September 2026

VM Escape via VMXNET3: Critical VMware Workstation/Fusion Flaw Patched

Broadcom has patched a critical integer-overflow bug in VMware Workstation and Fusion that lets an attacker with admin rights inside a VM run code on the host — plus a related HGFS buffer overflow. Neither is remotely exploitable, but both break the guest/host boundary that desktop virtualization depends on.

vmwarevm-escapevulnerability-management
4 min readRead
Vulnerability Management3 September 2026

CISA Adds Seven Actively Exploited Flaws to KEV — Shells and Miners Follow

A fresh CISA KEV batch spans SonicWall, Sangoma, JFrog, Kestra and LiteLLM — and in several cases the exploitation has already moved past initial access to reverse shells and cryptomining.

cisa-kevvulnerability-managementsonicwall
4 min readRead
Threat Intelligence28 August 2026

Patch Discussion to Exploit Probe: Now Measured in Minutes, Not Days

Maintainers are reporting that automated attackers are weaponising vulnerability rumours before a patch even ships — collapsing the gap between disclosure and exploitation from days to minutes.

vulnerability-managementpatch-managementai-security
4 min readRead
Vulnerability Management11 August 2026

CISA KEV Alert: Langflow RCE Exploited at Scale, AI Agents in the Loop

CISA added an unauthenticated Langflow RCE, an Apache Tomcat cluster-encryption bypass, and two N-able N-central auth-bypass bugs to its KEV catalog on August 5 — one of them already chained by an actor using agentic AI tooling.

kev-cataloglangflowai-agent-security
4 min readRead
Firmware & Boot Security29 July 2026

11 Old Microsoft-Signed UEFI Shims Left Secure Boot Bypassable for 13 Years

ESET found that 11 old UEFI shim bootloaders, still validly signed under Microsoft's third-party CA, let attackers bypass Secure Boot on any UEFI machine that trusts that certificate — no exploit development required.

uefisecure-booteset
4 min readRead
CI/CD & DevSecOps28 July 2026

CVE-2026-63077: Critical TeamCity Flaw Enables Unauthenticated RCE

A critical bug in the agent polling protocol lets an unauthenticated attacker with network access to a TeamCity On-Premises server run arbitrary OS commands — no credentials required.

teamcitycicd-securityvulnerability-management
4 min readRead
Vulnerability Management18 July 2026

OpenSSL's HollowByte DoS Flaw Shipped With No CVE — Here's Why That Matters

An 11-byte TLS handshake header can lock up hundreds of megabytes of server memory before authentication even starts. OpenSSL fixed it in June 2026 without a CVE, an advisory, or a changelog entry.

openssldenial-of-servicevulnerability-management
4 min readRead