CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure
A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just 10 hours of public disclosure. The vulnerability allows...
Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk
Exploit code has been publicly released for BlueHammer, a Windows zero-day privilege escalation vulnerability that allows attackers to gain full SYSTEM or administrator access. The availability of working...
Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now
A critical zero-day in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.8) is being actively exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalog, mandating...
CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed
A maximum-severity RCE vulnerability (CVE-2025-59528, CVSS 10.0) in the popular Flowise AI agent builder is under active attack. Over 15,000 instances are still exposed online. Here’s what you...
Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15
Google has patched CVE-2026-5281, a use-after-free zero-day in Chrome’s WebGPU engine already exploited in the wild. It’s the fourth Chrome zero-day of 2026. CISA has mandated federal agencies...
Unpatched Adobe Reader Zero-Day Has Been Silently Exploiting Users Since December
A highly sophisticated zero-day exploit targeting Adobe Reader has been active since December 2025, requiring just a single click to open a PDF. No patch is available yet...
GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities
Security researchers have uncovered vulnerabilities in GitLab’s Community Edition and Enterprise Edition platforms, prompting the company to release critical security patches. On December 10th, 2025, Gitlab released update...
A Critical Patch for Vulnerable Next.js: New Scanner Unveils Hidden Attacks
With the rise of Serverless functions, static site generators like Next.js have become ubiquitous in web development, streamlining functionality and boosting speed. However, while these frameworks offer undeniable...