Vulnerabilities
Curated coverage and analysis in this editorial area.

CNIL Fines French Hospital €500K: 727,000 Profiles Exposed Without MFA or VPN
France's data protection authority fined Hôpital privé de la Loire €500,000 for a 2025 breach that exposed 727,113 individuals. The at…

CVE-2026-20212: Cisco Nexus 9000 with Silicon One ASIC Exposed to Pre-Auth Root RCE
Cisco disclosed a critical vulnerability in Nexus 9000 Series Switches equipped with Silicon One ASIC. CVE-2026-20212 carries a CVSS 9…

Plex Demands Urgent Update: Patches Before CVEs, Admins Left in the Dark
Plex urged users to immediately update Plex Media Server and Plex Desktop between September 1 and 3, 2026, without publishing the CVE…

Backup Turned Weapon: How the All-in-One WP Migration Plugin Exposes 3.2 Million Sites
CVE-2026-19949: A second-order SQL injection in the WordPress plugin All-in-One WP Migration enables remote code execution via the res…

FalconFlank PoC: Zero-Day Privilege Escalation in CrowdStrike Falcon Sensor
A researcher has publicly released a proof-of-concept exploiting the Office macro remediation feature to escalate privileges in the ED…

Public Exploit for CVE-2026-84115 Puts Cleo Harmony at Immediate Risk
A public exploit for the authentication-bypass vulnerability CVE-2026-84115 in Cleo Harmony has been released. Versions 5.8.1.0 throug…

FulcrumSec Steals 86 GB of MAG Data: API Keys Were Hardcoded in Client-Side JavaScript
The FulcrumSec data extortion group claimed responsibility for the Manchester Airports Group breach, publishing ~86 GB of data. Access…

SonicWall SMA1000: Active Zero-Days Enable Lateral Movement Without VPN
Two zero-day vulnerabilities in SonicWall SMA1000 allow unauthenticated RCE and lateral movement to Active Directory without VPN tunne…

ZDI-26-614: 0-day in PDF Architect Enables Remote Code Execution
The Zero Day Initiative published advisory ZDI-26-614 on August 31, 2026, detailing a 0-day vulnerability in the pdfforge PDF Architec…

CVE-2026-0768: Active Exploitation of Langflow, 360+ Attacks in Hours
The Langflow AI platform is under massive exploitation: over 360 attempts detected in hours leveraging critical vulnerability CVE-2026…

Honeypot Confirms Active Exploitation of Sangoma Switchvox RCE
CVE-2026-9586 affects roughly 4,000 internet-exposed Switchvox systems. Defused Cyber honeypots recorded in-the-wild exploitation with…

JFrog Artifactory Authentication Bug Exposes Supply Chain, Zeroes Defenses
CVE-2026-82329 hits JFrog Artifactory with a CVSS 9.8: an authentication bypass granting admin privileges. WatchTowr confirms in-the-w…