Threat Intelligence
A live, filtered feed of the most dangerous and urgent items, grouped by threat type.
// 55 ACTIVE THREATS · 4 IN THE LAST 24H
CRITICAL 5 Critical severity · CVSS ≥ 9.0 or pipeline-flagged
CRITICAL
Acer Wave 7: Critical Zero-Days Exposed, Patch Not Expected Until Late June
CRITICALMicrosoft Patched a Critical SharePoint RCE but Omitted the CVE from Official Documentation
CRITICALCritical Flowise RCE: Exploit Code Released for CVSS 9.9 Vulnerability
CRITICALChrome 148: Google Patches 151 Vulnerabilities, Including 22 Critical Flaws
CRITICALCritical Ghost CMS Flaw Exploited: 700+ Sites Compromised by Competing Threat Actors
ZERO-DAY 9 Actively exploited zero-days
ZERO-DAY
Acer Wave 7: Critical Zero-Days Exposed, Patch Not Expected Until Late June
ZERO-DAYKemp LoadMaster API Flaw Enables Authenticated RCE: CVSS 8.8 Vulnerability Patched
ZERO-DAYAI Zero-Days and OT Vulnerabilities: ESET’s May 2026 Security Briefing
ZERO-DAYTuskira Unveils Quell: AI Agent Designed to Mitigate Zero-Days Before Patches Exist
ZERO-DAYCyber May: AI Attacks Emerge, but Basic Vectors Remain the Primary Threat
ZERO-DAYAI-Directed Attacks and ICS Vulnerabilities: ESET’s Tony Anscombe on DynoWiper and the First AI Zero-Day
ZERO-DAYCVE-2026-0257: Active Exploitation Confirmed for GlobalProtect Authentication Bypass
ZERO-DAYWorld Cup 2026: A Cyber-Physical Attack Surface Spanning Three Nations
ZERO-DAYFortiClient EMS: EKZ Infostealer May Target VPN Management Channels
CVE 19 Advisories and patches with an assigned CVE
CVE
CVE-2026-20230: Public PoC for Cisco Unified CM Vulnerability Risks Remote Root Access
CVEWhy CVSS Scores Fail the Factory Floor: A New Framework for OT Vulnerability Management
CVECVE-2026-48095: 7-Zip NTFS Handler Heap Overflow
CVEMicrosoft Refuses to Patch Windows Search URI Flaw Enabling NTLM Hash Theft
CVEKemp LoadMaster API Flaw Enables Authenticated RCE: CVSS 8.8 Vulnerability Patched
CVECVE-2026-0826: Root RCE Vulnerability Hits HP Poly Enterprise VoIP Phones
CVEGamaredon APT Weaponizes WinRAR Path Traversal Bug for Ukrainian Espionage
CVECISA Warns of Active Exploitation for Two-Year-Old Oracle WebLogic Flaw
CVEGitea Bug Exposed Private Container Images for Four Years
CVEAnthropic Grants ENISA Access to Mythos: A Strategic Shift for EU Cybersecurity
CVEAudit Slams NIST Over NVD Collapse: 27,000 CVE Backlog and $200,000 in Wasted Funds
CVEMicrosoft Patched a Critical SharePoint RCE but Omitted the CVE from Official Documentation
EXPLOIT 16 PoC and exploits in the wild
EXPLOIT
CVE-2026-20230: Public PoC for Cisco Unified CM Vulnerability Risks Remote Root Access
EXPLOITCVE-2026-48095: 7-Zip NTFS Handler Heap Overflow
EXPLOITKemp LoadMaster API Flaw Enables Authenticated RCE: CVSS 8.8 Vulnerability Patched
EXPLOITCVE-2026-0826: Root RCE Vulnerability Hits HP Poly Enterprise VoIP Phones
EXPLOITGamaredon APT Weaponizes WinRAR Path Traversal Bug for Ukrainian Espionage
EXPLOITCISA Warns of Active Exploitation for Two-Year-Old Oracle WebLogic Flaw
EXPLOITInsight Launches Managed Exposure Defense to Combat AI-Driven Exploit Speed
EXPLOITMicrosoft Patched a Critical SharePoint RCE but Omitted the CVE from Official Documentation
EXPLOITCERT-In Mandates 12-Hour Patching Window to Combat AI-Driven Exploits
EXPLOITCritical Flowise RCE: Exploit Code Released for CVSS 9.9 Vulnerability
EXPLOITCIFSwitch: Linux Kernel Bug Grants Root Access on CentOS and Rocky Linux
EXPLOITCVE-2026-0257: Active Exploitation Confirmed for GlobalProtect Authentication Bypass
ADVISORY 6 CISA, CERT-AgID and vendor advisories
ADVISORY