Cve
Curated coverage and analysis in this editorial area.

Gitea CVE-2026-60004: Real-World Victim Reports CPU Spike and Dropper
A Russian sysadmin documented an attack on their self-hosted Gitea instance via CVE-2026-60004. Hosting provider HOSTKEY flagged susta…

Citrix NetScaler in the Crosshairs: Pre-Auth RCE via SAML Heap Overflow, Likely CVE-2026-8452
WatchTowr Labs has reverse-engineered a critical pre-authentication remote code execution flaw in Citrix NetScaler ADC/Gateway. The vu…

7-Zip 26.00: Any .zip File Can Trigger the Most Severe Heap Overflow Yet
CVE-2026-48095 is a heap overflow in 7-Zip's NTFS parser caused by undefined behavior in a 32-bit shift. An apparently harmless archiv…

CISA Orders 3-Day Patch Deadline for CVE-2026-18577 in N-able N-central
CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog with a three-day patching deadline for federal agencies. The…

Adobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update
Adobe patched 10 ColdFusion vulnerabilities, including CVE-2026-48282 with a CVSS 10.0 score and confirmed exploitation. The legacy RD…

NGINX Rift: Active Exploitation of CVE-2026-42945 Detected In the Wild
In-the-wild attacks targeting CVE-2026-42945 (NGINX Rift) began on May 16, 2026. Security researchers analyze the critical heap buffer…

CVE-2026-44338: Working Exploit Scanner for PraisonAI Deployed in Under 4 Hours
The first automated scanner targeting PraisonAI was detected less than four hours after the disclosure of CVE-2026-44338. The authenti…

CVE-2026-41940: Global Campaign Targets cPanel Authentication Bypass to Deploy Cross-Platform Backdoors
Threat actor Mr_Rot13 is actively exploiting CVE-2026-41940 in cPanel/WHM to deploy the 'Filemanager' backdoor. With over 2,000 IPs in…

cPanel Auth Bypass Under Mass Attack: 2,000 IPs Exploiting CVE-2026-41940
The threat actor Mr_Rot13 is weaponizing CVE-2026-41940 to deploy backdoors and steal credentials from cPanel/WHM instances. Security…

Active Exploitation of cPanel Vulnerability Deploys 'Filemanager' Backdoor
Threat actor Mr_Rot13 is weaponizing CVE-2026-41940 in cPanel/WHM to distribute the Filemanager backdoor. With over 2,000 IPs targetin…

CVE-2026-31431: CISA Mandates Container Patch — Actively Exploited in the Wild
CISA has confirmed active exploitation of CVE-2026-31431, a critical Linux kernel vulnerability dubbed "Copy Fail." With a 732-byte Po…