Threat Intelligence
A live, filtered feed of the most dangerous and urgent items, grouped by threat type.
// 57 ACTIVE THREATS · 5 IN THE LAST 24H
CRITICAL 6 Critical severity · CVSS ≥ 9.0 or pipeline-flagged
CRITICAL
SAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks
CRITICALProgress Orders ShareFile Shutdown: Third Critical Incident in Three Years
CRITICALBeyondTrust Patches Four Critical Flaws: The AI That Finds Bugs Risks Becoming the Weapon That Exploits Them
CRITICALAdobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update
CRITICALZimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG
CRITICALBeyondTrust Patches Four Critical Remote Support Flaws — Self-Hosted Servers Left Exposed for Months
ZERO-DAY 14 Actively exploited zero-days
ZERO-DAY
Microsoft July 2026 Patch Tuesday: Record Vulnerability Volume Forces a Reckoning
ZERO-DAYSonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough
ZERO-DAYSharePoint JWT Bypass and the AI Agent That Rewrites Zero-Day Discovery
ZERO-DAYFortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day
ZERO-DAYCISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13
ZERO-DAYAnyDesk 0Day ZDI-26-401: No Patch After 15 Months, DoS Remains Active
ZERO-DAYZDI Publishes 0-Day in Glary Utilities: LPE via Junction, No Patch
ZERO-DAYMicrosoft Patches RoguePlanet: When the Antivirus Becomes the Attack Surface
ZERO-DAYLorex 0-Day ZDI-26-399: Root RCE on Wi-Fi Camera, No Patch After 14 Months
ZERO-DAYOllama Zero-Day DoS: downloadBlob Bug Puts Local AI Servers at Risk
ZERO-DAYIRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup
ZERO-DAYKDDI: Zero-Day in Third-Party Software Exposes 12,233,087 Email Addresses
CVE 18 Advisories and patches with an assigned CVE
CVE
ArcGIS Server Path Traversal Masqueraded as Moderate: CVSS Jumps from 7.5 to 9.8 in Two Days
CVESAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks
CVESonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough
CVEMicrosoft Revokes 11 Legacy UEFI Shims: Secure Boot Bypassed via Signed Bootloaders
CVEFortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day
CVEMetasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework
CVEAdobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update
CVEThe Gentlemen Climbs RaaS Rankings: 90% Payout and 580 Victims in One Year
CVEZimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG
CVEChinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
CVEFortiBleed: 74,000 FortiGates Exposed — Patching Alone Won't Fix It
CVEQualys Unveils Risk Operations Center for the 'Day Minus Seven' Era
EXPLOIT 17 PoC and exploits in the wild
EXPLOIT
SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough
EXPLOITCISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13
EXPLOITBeyondTrust Patches Four Critical Flaws: The AI That Finds Bugs Risks Becoming the Weapon That Exploits Them
EXPLOITMetasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework
EXPLOITAdobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update
EXPLOITFriendly Fire: Defensive AI Agents Turn into RCE Attack Vectors
EXPLOITChinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
EXPLOITLorex 0-Day ZDI-26-399: Root RCE on Wi-Fi Camera, No Patch After 14 Months
EXPLOITFortiBleed: 74,000 FortiGates Exposed — Patching Alone Won't Fix It
EXPLOITIRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup
EXPLOITKDDI: Zero-Day in Third-Party Software Exposes 12,233,087 Email Addresses
EXPLOITGhostLock: 15-Year Linux Kernel Bug Now Publicly Exploitable, Guarantees Root
ADVISORY 2 CISA, CERT-AgID and vendor advisories