// 1 CRITICAL · 7 ZERO-DAY · 9 CVE · 9 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

FortiSandbox: Three Critical Vulnerabilities Under Active Exploitation, Defused Cyber Says

Threat intelligence firm Defused Cyber observed active exploitation of three critical pre-authentication flaws in Fortinet FortiSandbo…

Jun 16, 2026views - 1k

CYBERSECCVE

Cisco SD-WAN, CVE-2026-20262: Internal Discovery, External Exploitation

Cisco disclosed CVE-2026-20262, a path traversal vulnerability in Catalyst SD-WAN Manager actively exploited in the wild. It requires…

Jun 16, 2026views - 762

VULNEXPLOIT

LiteSpeed cPanel: Two CVEs Added to KEV Catalog, Shared Hosting at Risk

CISA adds two distinct LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog: root privilege escalation on shar…

Jun 16, 2026views - 870

VULNEXPLOIT

RoguePlanet: Zero-Day Exploit (CVE-2026-42897) Hits Fully Patched Windows 10 and 11 Systems

RoguePlanet (CVE-2026-42897) leverages a race condition in Microsoft Defender to gain SYSTEM privileges on Windows 10 and 11 devices,…

Jun 10, 2026views - 891

CYBERSECCVE

LiteLLM CVE-2026-42271: CISA Confirms Active Exploitation of CVSS 10.0 RCE Chain

CISA has added CVE-2026-42271 to its KEV catalog, confirming active exploitation of a command injection vulnerability in LiteLLM. When…

Jun 09, 2026views - 763

VULNZERO-DAY

Gogs Patches Critical CVSS 9.4 Zero-Day; Over 2,300 Servers Exposed

Gogs 0.14.3 addresses a critical argument injection zero-day in the git rebase function. Default configurations allowing open registra…

Jun 09, 2026views - 1.4k

CYBERSECCVE

CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Affiliate; Patch Released June 8

A Qilin ransomware affiliate exploited a critical zero-day in Check Point VPN’s IKEv1 protocol for over a month. The flaw (CVSS 9.3) a…

Jun 08, 2026views - 1k

microsoftZERO-DAY

Microsoft Backtracks on Legal Threats Against Zero-Day Researcher Following Industry Backlash

Microsoft threatened criminal action against researcher Nightmare-Eclipse over six Defender zero-days, partially retracting its stance…

Jun 08, 2026views - 1.5k

CYBERSECCRITICAL

CISA Adds Critical Magento Mirasvit RCE to KEV Catalog, Sets 72-Hour Patch Deadline

CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog on June 3, 2026. The flaw is a PHP object injection in…

Jun 07, 2026views - 1.4k

CYBERSECEXPLOIT

CISA: SolarWinds Serv-U Vulnerable to Remote Crashes via HTTP Header

CISA confirms active exploitation of CVE-2026-28318 in SolarWinds Serv-U. A single 'Content-Encoding: deflate' header is sufficient to…

Jun 05, 2026views - 1.7k

CYBERSECCRITICAL

Everest Forms Pro: Critical RCE Exploited Months After Patch Release

Threat actors are actively exploiting CVE-2026-3300 in the Everest Forms Pro WordPress plugin. Although version 1.9.13 has been availa…

Jun 05, 2026views - 1.3k

CYBERSECZERO-DAY

Microsoft Retracts Legal Threats Against Researchers Following Zero-Day Disclosure Backlash

Microsoft threatened criminal prosecution against researcher Nightmare-Eclipse for publishing six Windows zero-days before walking bac…

Jun 04, 2026views - 1.3k