CVE Tools

The cve.tools Blog

Product updates, the weekly threat signal, and monthly trends: what shipped, what's exploited, and where we're heading.

Follow CVE Pulse on Telegram
  1. BRIDGE:BREAK — one request to root on an internet-exposed OT deviceSome bugs are dangerous because they're clever. CVE-2025-67038 is dangerous because it's simple, it's on a device that should never have been on the internet, and it lands you at the doorway to an…CVE-2025-670385 min
  2. CVE-2026-45657: Windows Kernel TCP/IP use-after-free — wormable CVSS 9.8, no exploit yetCVE-2026-45657 is the marquee bug of the June 2026 Patch Tuesday — a record 208-CVE release — and the reason it stands out is deceptively simple: the vulnerable surface is the Windows Kernel…CVE-2026-4565715 min
  3. CVE-2026-44812: the Win32k GRFX graphics RCE hiding inside your Preview PaneMicrosoft labelled this one "Remote Code Execution." The CVSS vector tells the real story: AV:L / UI:R — a user previews or opens a crafted graphics file in the Windows File Explorer Preview Pane,…CVE-2026-4481212 min
  4. RoguePlanet: Microsoft Defender Becomes the Attack Surface (CVE-2026-50656)The software running on your endpoints to catch malware just became the malware's foothold. CVE-2026-50656 — nicknamed RoguePlanet by the researcher who found and published it — is an Elevation…CVE-2026-5065615 min
  5. CVE-2026-35273: the PeopleSoft zero-day ShinyHunters used to extort universitiesCVE-2026-35273 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in Oracle PeopleSoft Enterprise PeopleTools 8.61 and 8.62 — specifically the Environment Management Hub…CVE-2026-352737 min
  6. SimpleHelp's 10.0 auth bypass: forge a token, own the RMM (CVE-2026-48558)SimpleHelp is remote-support / RMM software — the kind of tool that, by design, can remote into, transfer files to, and run scripts on every machine it manages. CVE-2026-48558 turns that reach…CVE-2026-485589 min
  7. UniFi OS root with no password: CVE-2026-34910 and the unauthenticated RCE chainOn its own, CVE-2026-34910 is a command-injection flaw in a UniFi OS Server update endpoint. The reason it's an emergency is the company it keeps: Bishop Fox showed it chains with two sibling bugs…CVE-2026-349107 min
  8. PixelSmash: one video file that puts FFmpeg-powered servers at riskFFmpeg's libavcodec is the quiet engine behind a staggering amount of the internet's media handling — media servers, file-sync previews, desktop thumbnailers, NAS boxes, and AI data pipelines all…CVE-2026-84616 min
  9. CVE-2026-24858 and FortiBleed: the Fortinet auth bypass behind a credential gold rushCVE-2026-24858 keeps showing up in coverage of FortiBleed — the credential-harvesting campaign that exposed tens of thousands of Fortinet devices — so it's worth separating the two cleanly. The…CVE-2026-248585 min
  10. UniFi OS root with no password: CVE-2026-34910 and the unauthenticated RCE chainOn its own, CVE-2026-34910 is a command-injection flaw in a UniFi OS Server update endpoint. The reason it's an emergency is the company it keeps: Bishop Fox showed it chains with two sibling bugs…CVE-2026-349106 min
  11. Cisco SD-WAN root access: inside CVE-2026-20245, exploited for months before disclosureCisco's Catalyst SD-WAN management plane took another hit. CVE-2026-20245 lets an authenticated attacker who already holds netadmin rights run arbitrary commands as root on SD-WAN Controller…CVE-2026-202456 min
  12. One Box, Three Perfect 10s: The Week Networking Gear Broke BadUbiquiti's UniFi OS collected three CVSS-10 bugs on CISA's KEV in one June 23 batch. A casual, no-FUD roundup of what's actually being exploited — and how to prioritise it.CVE-2026-349104 min
  13. See what’s actively exploited right now — Threat Radar is liveHey there 👋 It's been a busy couple of weeks, and almost all of it lands right where you'll see it. We've been making it easier to tell what actually matters today, to browse CVEs the way you…3 min
  14. Browse CVEs by vendor, product and sectorRaw vulnerability data is a mess. The same vendor shows up spelled five different ways. A single product is scattered across dozens of near-duplicate version strings. Ask a simple question — "show…3 min
  15. Security news, trend reports and sector intel arriveHey there 👋 It's been a big week. cve.tools grew two whole new public sections — a security news feed and monthly trend reports — and the database itself got smarter about who is affected, not…3 min
  16. What's new — late May & early JuneOver the past two weeks we shipped the things you've been asking for: personal API keys, a public place to file bugs and ideas, and a much more lively landing page. Smaller polish along the way.2 min

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store