Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution
A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...
wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In
A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...
HollowByte: How 11 Bytes Can Quietly Starve an OpenSSL Server to Death
A newly disclosed OpenSSL weakness, dubbed HollowByte, lets an unauthenticated attacker trigger a slow, memory-fragmenting denial-of-service condition using a payload as small as 11 bytes. Because it was...
This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire
A packed week in cybersecurity saw Microsoft ship roughly 570 patches including two actively exploited zero-days, a WordPress RCE bug threatening hundreds of millions of sites, and a...
Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control
Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...
Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts
A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator's registry hive, opening a path to persistence...
CISA Confirms Active Exploitation of Critical SharePoint Deserialization Flaw
CISA has added CVE-2026-58644, a critical unauthenticated remote code execution flaw in Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog after confirming real-world attacks. Federal agencies must remediate...
SonicWall SMA1000 Zero-Days Under Active Attack: Perfect-10 Flaw Chained for Root Access
Attackers were exploiting a maximum-severity SonicWall SMA1000 flaw before the vendor's advisory even landed, chaining it with a privilege-escalation bug to seize root and pivot into corporate Active...