Complete article archive
260 published articles · Showing 61–72 · Newest first
Credential Exposure in Johnson Controls Simplex Incident Manager
A vulnerability in Simplex Incident Manager (CVE-2026-27875) allows local attackers to extract cleartext passwords and tokens from system memory. Vulnerability management teams should prioritize upgrading to version v2.01.01.
Read article →Active Exploitation of TrueConf Server Vulnerabilities
CISA has added CVE-2026-72529 and CVE-2026-72530 to the KEV Catalog, confirming active exploitation of TrueConf Server. This analysis focuses on identifying affected assets and verifying remediation.
Read article →Zimbra Collaboration Suite OS Command Injection (CVE-2026-73570)
CISA has added CVE-2026-73570 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of an OS command injection flaw in Zimbra Collaboration Suite.
Read article →Improper Access Control in Oracle HTTP Server and WebLogic Server Proxy Plug-in
CVE-2026-21962 allows unauthorized access to critical data within Oracle HTTP Server and WebLogic Server Proxy Plug-in. With CISA adding this to the Known Exploited Vulnerabilities catalog, vulnerability management teams must prioritize remediation via the January 2026 CPU.
Read article →Active Exploitation of CVE-2026-21962 in Oracle HTTP and WebLogic Proxy
CISA has added CVE-2026-21962 to the KEV catalog, confirming active exploitation of an improper access control vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
Read article →Gitea Code Injection via diffpatch API (CVE-2026-60004)
Analysis of CVE-2026-60004, a code injection vulnerability in Gitea allowing attackers with repository write access to execute shell commands as the service account.
Read article →Unauthenticated Remote Code Execution in SIMATIC IoT2050 Advanced
A critical authentication failure in the Node-RED HTTP interface of Siemens SIMATIC IoT2050 Advanced devices allows unauthenticated remote attackers to execute arbitrary code with maximum privileges.
Read article →Gitea Code Injection (CVE-2026-60004) Added to CISA KEV
CISA has added CVE-2026-60004, a code injection vulnerability in Gitea, to the Known Exploited Vulnerabilities catalog. This analysis examines the implications for vulnerability management teams and the necessity of compromise assessments prior to remediation.
Read article →PayRange API Authorization Flaw CVE-2026-18965
A critical authorization vulnerability in the PayRange API exposes device details and allows remote modification. With no vendor patch available, defenders must prioritize network isolation to reduce exposure.
Read article →Reducing Domain and Cloud Exposure: Lessons from Red Team Assessments
An analysis of common misconfigurations in Active Directory, ADCS, and Microsoft Entra ID that enable full domain compromise, with a focus on verifying the reduction of these exposure paths.
Read article →Bendix EC80 Brake ECU Firmware Vulnerabilities
Analysis of three vulnerabilities in Bendix EC80 Brake ECUs that could lead to the loss of critical vehicle functions including ABS and steering assist.
Read article →Permanent Exposure in FURUNO FA-50 AIS Transponders
Two critical vulnerabilities affecting all versions of the FURUNO FA-50 Class B AIS Transponder cannot be patched due to the product's end-of-production status, requiring immediate network isolation and physical security controls.
Read article →Page 6 of 22. This archive includes every published article; drafts and articles still processing are not public.
From government advisory to practical action
Vulnerability Assurance turns government cybersecurity reporting into original articles written for the people responsible for fixing vulnerabilities. Each analysis connects the source information to the decisions, corrective actions, and verification steps that matter in an affected environment.
Latest analysis
What our articles cover
- What happened: the vulnerability, the affected technology, and what the available evidence establishes.
- Who needs to act: relevant versions, configurations, exposure conditions, and operational dependencies.
- How to mitigate it: applicable patches, configuration changes, or compensating controls, with important limitations.
- How to verify the result: checks and retesting that can demonstrate whether the affected condition or exposure remains.
- What remains unresolved: uncertainty, residual risk, and follow-up work.
Analysis you can use here
Government advisories provide the evidence behind our reporting. Our articles explain that evidence in context and add practical mitigation and validation guidance. Source citations support the analysis; they do not replace it.
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗