SCTPhantom Linux Kernel Flaw: 18-Year-Old SCTP Bug Enables Root and Container Escape
August 9, 2026 Researchers at Tencent Zhuque Lab disclosed an 18-year-old Linux kernel vulnerability in the Stream Control Transmission Protocol (SCTP) that could allow a local attacker to gain root privileges and escape container boundaries. Tracked as…
CISA KEV Alert: IBM Langflow CVE Enables Unauthenticated RCE on AI Workflow Platform
August 8, 2026 The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog. This critical flaw in IBM Langflow OSS allows unauthenticated attackers to execute remote code with superuser…
NatJack NAT Attack Hijacks TCP Sessions and Spoofs DNS
August 6, 2026 Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation connection state to hijack active TCP sessions, spoof DNS responses, and disclose victim IP addresses and mapped…
CISA KEV Alert for Active Zero-Day Exploitation of Cisco FMC
July 30, 2026 CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The vulnerability, tracked as CVE-2026-20316, allows…
Critical Rails Active Storage Flaw Exposes Server Secrets
July 29, 2026 A critical vulnerability in Ruby on Rails Active Storage could let unauthenticated attackers read arbitrary files from application servers using crafted image uploads. Tracked as CVE-2026-66066 with a CVSS score of 9.5, the flaw exposes…
Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
July 28, 2026 More than 24,000 internet-exposed servers are leaking authentication password hashes through a 20-year-old vulnerability in their Baseboard Management Controller interfaces. Researchers at cybersecurity firm Lava discovered that…
Critical Pre-Auth RCE Flaw Enables Remote Code Execution
July 28, 2026 A critical pre-authentication remote code execution vulnerability in vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code on affected servers. The flaw, tracked as CVE-2026-61511, impacts versions 5.7.5…
Dysphoria IoT Botnet Hijacks Devices Worldwide
July 28, 2026 A rapidly evolving IoT botnet named Dysphoria has infected an estimated 200,000 devices worldwide. Consequently, defenders must understand its blockchain-based command-and-control architecture and aggressive DDoS capabilities. The botnet…
Critical Fastjson RCE Under Active Exploitation
July 25, 2026 Security researchers have uncovered a critical remote code execution flaw in Alibaba’s Fastjson 1.x library. Tracked as CVE-2026-16723, this vulnerability carries a CVSS score of 9.0 and is already under active exploitation in the…
XBOW Bing Images RCE: SVG Command Injection Yields SYSTEM Shells
July 24, 2026 XBOW, an autonomous offensive security startup, disclosed two critical remote code execution vulnerabilities in Microsoft Bing’s image processing pipeline. The flaws, tracked as CVE-2026-32194 and CVE-2026-32191, both carry a CVSS…