September 5, 2026 · Vulnerability Assurance
CISA has added CVE-2026-21962 to the KEV catalog, confirming active exploitation of an improper access control vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
Read analysis →
September 5, 2026 · Vulnerability Assurance
Analysis of CVE-2026-60004, a code injection vulnerability in Gitea allowing attackers with repository write access to execute shell commands as the service account.
Read analysis →
September 5, 2026 · Vulnerability Assurance
A critical authentication failure in the Node-RED HTTP interface of Siemens SIMATIC IoT2050 Advanced devices allows unauthenticated remote attackers to execute arbitrary code with maximum privileges.
Read analysis →
September 5, 2026 · Vulnerability Assurance
CISA has added CVE-2026-60004, a code injection vulnerability in Gitea, to the Known Exploited Vulnerabilities catalog. This analysis examines the implications for vulnerability management teams and the necessity of compromise assessments prior to remediation.
Read analysis →
September 5, 2026 · Vulnerability Assurance
A critical authorization vulnerability in the PayRange API exposes device details and allows remote modification. With no vendor patch available, defenders must prioritize network isolation to reduce exposure.
Read analysis →
September 5, 2026 · Vulnerability Assurance
An analysis of common misconfigurations in Active Directory, ADCS, and Microsoft Entra ID that enable full domain compromise, with a focus on verifying the reduction of these exposure paths.
Read analysis →
September 5, 2026 · Vulnerability Assurance
Analysis of three vulnerabilities in Bendix EC80 Brake ECUs that could lead to the loss of critical vehicle functions including ABS and steering assist.
Read analysis →
September 4, 2026 · Vulnerability Assurance
Two critical vulnerabilities affecting all versions of the FURUNO FA-50 Class B AIS Transponder cannot be patched due to the product's end-of-production status, requiring immediate network isolation and physical security controls.
Read analysis →
September 4, 2026 · Vulnerability Assurance
Rently Smart Home versions 20.1.0 and prior are vulnerable to a credential protection flaw that could allow the retrieval of Master Pins and the override of user permissions.
Read analysis →
September 4, 2026 · Vulnerability Assurance
An authenticated OS command injection vulnerability in ZoneMinder allows users with 'View Events' permissions to execute arbitrary commands via the exportFile parameter.
Read analysis →