Category: Vulnerabilities

  • Attack path showing unauthorized VPN access through a vulnerable Check Point Security Gateway deployment

    June 16, 2026
    CVE-2026-50751 is an authentication bypass vulnerability affecting Check Point Security Gateway VPN services. Check Point has confirmed active exploitation against…
  • Attack path showing unauthenticated file creation and file overwrite activity against a vulnerable Splunk Enterprise deployment

    June 16, 2026
    CVE-2026-20253 is a critical unauthenticated arbitrary file write vulnerability affecting Splunk Enterprise. The flaw may allow attackers to create or…
  • Attack path showing unauthorized Technician account creation through vulnerable SimpleHelp OIDC authentication

    June 15, 2026
    CVE-2026-48558 is an authentication bypass vulnerability affecting SimpleHelp OIDC deployments. The flaw may allow attackers to create unauthorized Technician accounts…
  • Attack path showing unauthenticated remote code execution against a vulnerable Oracle PeopleSoft deployment

    June 12, 2026
    CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft PeopleTools. Threat intelligence confirms active exploitation by ShinyHunters…
  • Attack path showing unauthenticated command execution against a vulnerable Ivanti Sentry appliance

    June 11, 2026
    CVE-2026-10520 is a critical pre-authenticated OS command injection vulnerability in Ivanti Sentry that allows remote attackers to execute arbitrary commands…
  • Visualization of CVE-2026-0257 affecting Palo Alto Networks PAN-OS GlobalProtect and enabling unauthorized VPN access

    June 5, 2026
    CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect that allows unauthorized VPN access and is…
  • Attack path showing authentication to Apache Solr using hardcoded default credentials

    June 2, 2026
    CVE-2026-44825 is a hardcoded credentials vulnerability affecting Apache Solr Basic Authentication setup workflows. The flaw may allow attackers to gain…
  • Attack chain showing a Starlette Host header validation bypass leading to unauthenticated remote code execution in LiteLLM

    June 1, 2026
    CVE-2026-27771 is a high-severity authentication bypass vulnerability affecting Gitea’s built-in package and container registry functionality. The flaw may allow unauthenticated…
  • Attack path showing unauthorized VPN access through a vulnerable Check Point Security Gateway deployment

    May 29, 2026
    CVE-2026-27771 is a high-severity authentication bypass vulnerability affecting Gitea’s built-in package and container registry functionality. The flaw may allow unauthenticated…
  • Attack path showing unauthenticated file creation and file overwrite activity against a vulnerable Splunk Enterprise deployment

    May 21, 2026
    CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core affecting PostgreSQL-backed deployments. The flaw allows unauthenticated attackers to…