Vulnerabilities & Exploits Zammad's Two-Flaw Exploit Chain and the Two Affected-Version Lists A session-hijack flaw and a local privilege escalation in Zammad chain into root access in seconds, and the version lists published by the coordinating institute and the vendor read differen
Vulnerabilities & Exploits GitLab's AI Gateway Sandbox Escape Ends in Command Execution on Self-Hosted Instances CVE-2026-90970 lets an authenticated user with Duo Agent Platform access escape the GitLab AI Gateway's prompt template sandbox through a crafted flow configuration, and run arbitrary comman
Vulnerabilities & Exploits The NetScaler Payloads That Create Their Own Superusers and Hide in CSS URLs LevelBlue's Threat Hunt Operations team documented what actually ran on compromised NetScaler appliances after CVE-2026-88771 and CVE-2026-88772 were exploited: a Perl script that creates a
Vulnerabilities & Exploits Disclosure Doubled and Exploitation Followed: What GTIG's AI-Era Data Actually Shows Google Threat Intelligence Group's first full dataset on vulnerabilities in the AI era reports monthly disclosures more than doubling — from 5,045 in January 2026 to 10,740 in August — while
Vulnerabilities & Exploits Cisco SD-WAN Manager Auth Bypass: Actively Exploited, No Workaround (CVE-2026-76504) Cisco disclosed CVE-2026-76504, a CVSS 9.8 auth bypass in Catalyst SD-WAN Manager, on September 30, 2026 — and confirmed active exploitation. A URI-encoded character defeats the login rule,
Vulnerabilities & Exploits The Zimbra Bug That Turned a Monitoring Add-on into a Command Line Microsoft published a September 30, 2026 deep-dive on CVE-2026-73570 — an unauthenticated command injection in Zimbra's optional SNMP notification path — with exploitation observed between t
Vulnerabilities & Exploits The Controller That Runs Your AI Data Center Had Hard-Coded Credentials NVIDIA's September 22 bulletin disclosed a CVSS 9.8 hard-coded-credential flaw in NICo, the Kubernetes-based controller that provisions bare-metal AI infrastructure. The tool that manages ev
Vulnerabilities & Exploits A Public Exploit Escapes Ubuntu Containers Before the Patch Ships DepthFirst published a working container-escape exploit for CVE-2026-80521, an AF_UNIX use-after-free, while Ubuntu still lists the fix as work in progress. MicroVMs are the only real mitiga
Vulnerabilities & Exploits Oracle PeopleSoft Exploitation: How One Encoded Character Bypassed a WAF Rule A URL-encoded P let UNC6240 evade literal-path WAF rules at Oracle PeopleSoft. Netics examines the patch-first response to renewed CVE-2026-35273 exploitation.
Vulnerabilities & Exploits A CVSS-10 Path Traversal in GitLab's Commits API Is Being Exploited GitLab patched a maximum-severity unauthenticated file-read flaw in the repository commits API and CISA added it to the KEV catalog. Netics on why CVSS 10.0 in a self-managed DevSecOps tool
Vulnerabilities & Exploits Vulnerability Remediation Needs Production Context, Not Another Bigger Scanner Cloudflare’s context-aware remediation service points to a better security priority: prove exposure, controls, and validation before asking teams to patch.
Vulnerabilities & Exploits Copy-Fail Shows Why Container Security Still Depends on the Host Kernel Docker’s Copy-Fail guidance shows the layered response to a Linux kernel privilege escalation: patch the kernel, upgrade Engine, and reduce AF_ALG exposure.