CVE Tools

Security news, decoded.

74 stories in the last 7 days, naming 204 CVEs; 60 of those CVEs are in CISA KEV.

RSS feed

The wire

Page 31 of 36 · newest first · times in UTC

Wednesday, Jun 1030 stories

  1. BleepingComputer
  2. The Hacker News
    China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

    Security researchers report a resurgence and expansion of the JDY botnet, a covert network attributed to China-nexus state-sponsored threat activity. JDY now targets more than 1,500 SOHO and IoT devices and operates as a centralized scanner to discover, fingerprint, and continuously map exposed services for later exploitation. The activity includes use of edge-device vulnerabilities such as CVE-2026-35616, highlighting ongoing risk to internet-facing infrastructure and the persistence of reconnaissance capabilities even after related takedowns.

    ResearchJDY botnet (scanner malware)
  3. The Hacker News
  4. The Hacker News
    Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE

    Security researchers report that an unpatched vulnerability in Langflow, an open-source low-code AI application platform, is being exploited in the wild. CVE-2026-5027 (CVSS 8.8) is a path traversal issue that can allow arbitrary file writes via the POST /api/v2/files endpoint, and unauthenticated access can be sufficient to reach the vulnerable code path before exploitation. This matters because it enables remote compromise without valid credentials, adding to a series of active Langflow attacks this year tied to CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, and CVE-2025-34291.

    Reported exploitedLangflow
  5. BleepingComputer
  6. The Hacker News
    CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation

    CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after reports of in-the-wild exploitation, affecting Cisco Catalyst SD-WAN Manager, Google Chrome V8, and Arista Extensible Operating System (EOS). The listed issues are CVE-2026-20245 (Cisco; authenticated local command execution as root), CVE-2026-11645 (Chrome V8; sandbox escape via crafted HTML for remote code execution), and CVE-2026-7473 (Arista EOS; improper handling of tunnel traffic that can process unexpected tunneled packets). It matters because the KEV listing signals active attacker use, and federal civilian agencies have been directed to remediate or mitigate by June 23, 2026.

    Reported exploitedCisco Catalyst SD-WAN Manager
  7. BleepingComputer
    Microsoft patches Exchange Server zero-day exploited in attacks

    Microsoft released security updates for a zero-day in Microsoft Exchange Server that has been exploited in real-world attacks, enabling attackers to run arbitrary JavaScript via a cross-site scripting (XSS) path that targets Outlook Web Access users. The issue, tracked as CVE-2026-42897, affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE), and can be triggered remotely by sending a crafted email without special privileges. This matters because the flaw allows malicious script execution in the victim’s browser context, increasing the risk of account and session compromise; defenders should apply the June 2026 fixes and keep the related mitigations enabled.

    Reported exploitedExchange Server 2016
  8. SecurityWeek
  9. Rapid7 Blog
  10. BleepingComputer
  11. The Hacker News
  12. SecurityWeek
  13. Daily CyberSecurity (securityonline.info)
  14. SecurityWeek
  15. The Hacker News
  16. SecurityWeek
  17. BleepingComputer
  18. The Hacker News
  19. The Hacker News
    Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

    Researchers disclosed six security issues in protobuf.js (often used with Google Cloud client libraries, Baileys, and CI/CD workflows), collectively dubbed Proto6. The vulnerabilities affect Node.js services that deserialize attacker-controlled Protobuf data or generate code from schemas, enabling remote code execution and denial-of-service conditions. Affected CVEs include CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, and CVE-2026-44295, with the most critical RCE risk tied to CVE-2026-44291; patches are available in protobufjs 7.5.6 and 8.0.2, and protobufjs-cli 1.2.1 and 2.0.2.

    Researchprotobuf.js
  20. Daily CyberSecurity (securityonline.info)
    Ivanti Sentry RCE: Publicly Disclosed PoC for CVSS 10

    Ivanti has published urgent fixes for its gateway appliances after researchers and watchTowr Labs disclosed a publicly available proof of concept for an Ivanti Sentry remote code execution issue. The affected component is associated with CVE-2026-10520 (CVSS 10), and a related authentication/privilege bypass is tracked as CVE-2026-10523 (CVSS 9.9), which can enable creation of administrative accounts and full administrative access. Because these systems sit at the edge of corporate traffic, unpatched deployments face a heightened risk of full administrative compromise; organizations should review logs and upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.

    PoC publicIvanti Sentry
  21. Daily CyberSecurity (securityonline.info)
    OpenSSL Security Patches Fix Remote Code Execution Risk

    OpenSSL has released emergency security updates to fix multiple memory-safety flaws in its certificate and QUIC-related code paths, including a use-after-free that can be triggered remotely and lead to Remote Code Execution via CVE-2026-45447. The release also covers additional security issues such as input-validation weaknesses (CVE-2026-34182), nonce handling problems in AES-OCB one-shot operations (CVE-2026-45445), and denial-of-service and crash conditions in the QUIC stack (CVE-2026-34183, CVE-2026-42764, CVE-2026-42765) plus an OCSP stapling double-free hazard (CVE-2026-35188). OpenSSL users are urged to upgrade promptly—e.g., from version 4.0 to version 4.0.1, and from 1.1.1 to 1.1.1zh—because unauthenticated attackers may be able to exploit these problems over the network.

    PatchOpenSSL
  22. Daily CyberSecurity (securityonline.info)
    CISA Expands Active Exploit Catalog with Cisco, Arista, and Chromium Flaws

    The US CISA has updated its Known Exploited Vulnerabilities catalog/active exploit list by adding three newly identified, in-the-wild flaws. Affected products include Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Arista EOS (CVE-2026-7473), and Google Chromium (CVE-2026-11645), spanning command-injection, tunneling/decapsulation weaknesses, and memory-safety issues that can lead to remote code execution. Because attackers are already targeting these weaknesses, organizations should prioritize patching and remediation immediately.

    Reported exploitedCisco Catalyst SD-WAN Manager
  23. Daily CyberSecurity (securityonline.info)
  24. Daily CyberSecurity (securityonline.info)
  25. Daily CyberSecurity (securityonline.info)
  26. Daily CyberSecurity (securityonline.info)
    Critical Veeam Backup Vulnerability ExposedPatchVeeam Backup & Replication
  27. Daily CyberSecurity (securityonline.info)
  28. Daily CyberSecurity (securityonline.info)
  29. watchTowr Labs
  30. Daily CyberSecurity (securityonline.info)
    MBS Universal Gateway Flaws Threaten Building Automation Networks

    MBS GmbH disclosed multiple critical security issues in its MBS Universal Gateway devices affecting firmware version V6005 and earlier, including unauthenticated access via a default credential weakness tracked as CVE-2026-35075 (CVSS 9.8) and remotely exploitable stack buffer overflow problems tracked as CVE-2026-35085, CVE-2026-35084, and CVE-2026-35083. The flaws could allow attackers to obtain full root control and, in some cases, read sensitive logs, placing smart building perimeter networks at risk. Administrators should update affected gateways to V6007 immediately to reduce the likelihood of compromise.

    AdvisoryMBS Universal Gateway

Tuesday, Jun 910 stories

  1. Krebs on Security
  2. Dark Reading
  3. Cisco Talos
  4. Rapid7 Blog
    Rapid7RoundupWindows
  5. Ars Technica (Security)
    Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosedPoC publicWindows Collaborative Translation Framework (CTFMON)
  6. Qualys Security Blog
  7. BleepingComputer
  8. SecurityWeek
  9. BleepingComputer
    Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsReported exploitedWindows Collaborative Translation Framework (CTFMON)
  10. BleepingComputer
    Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsPatchWindows Collaborative Translation Framework (CTFMON)

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store