New Search

If you are not happy with the results below please do another search

147 search results for: threat

31

April 2024 Threat Tracking: Record High For Security Vulnerabilities

April 2024 has compounded another record breaking month for CVE disclosure on top of the last. In this month’s threat tracking report we will investigate several new actively exploited vulnerabilities and quickly review the cyber breach of US R&D giant MITRE. The report will also uncover how end-of-life (EOL) products can have a detrimental impact […]

32

IT security update November 2023: Critical vulnerabilities and threats

In the November 2023 commVT Intelligence Update, several critical vulnerabilities and security threats have come to light. Cisco’s Internetworking Operating System (IOS) XE Software Web User Interface (UI) was found to be vulnerable to two actively exploited critical vulnerabilities, allowing attackers to execute arbitrary code remotely. The curl command-line tool, widely used across various platforms, […]

33

War in Ukraine – Cyber Attacks also Pose a Threat

Hardly any other topic is currently as present as the war in Ukraine, which is claiming numerous civilian and military victims. But in today’s interconnected and digitized world, the threat is not only military attacks, but is also expanding into cyber space. According to the Institute for Economics and Peace (IEP), cyber attacks on Ukraine […]

34

Three New JFrog Artifactory CVEs Actively Exploited in the Wild

CVE-2026-82329, CVE-2026-42018, and CVE-2026-42016, all affecting JFrog Artifactory, were added to CISA’s Known Actively Exploited (KEV) in September 2026 [1][2][3]. Artifactory acts as a central repository for software build artifacts, binaries, packages, containers, files, releases, and increasingly AI/ML artifacts. A compromise of Artifactory could allow an attacker to steal sensitive artifacts and credentials, tamper with […]

35

“MikroTrick” Exploit Chain Targets SSH-Exposed MikroTik RouterOS Devices

According to CERT Polska, active exploitation of MikroTik RouterOS has been underway since at least September 2nd, 2026. The chain leverages CVE-2026-67276 (CVSS 9.2) and CVE-2026-86060 (CVSS 9.2) against devices whose SSH service is reachable from public networks. A successful breach yields full control of the targeted system. MikroTik has published fixes for the flaws […]

36

CVE-2026-64849: SSRF Flaw in MLflow Actively Exploited

CVE-2026-64849 (CVSS 9.3, EPSS ≥ 95th pctl) is a critical-severity unauthenticated full-read server-side request forgery (SSRF) flaw [CWE-918] in MLflow webhook delivery. The CVE affects all versions prior to 3.15.0. The root cause is flawed redirect handling and DNS rebinding. The flaw is exploited by bypassing the _validate_webhook_url protections in the default MLflow Tracking Server […]

37

CVE-2026-19478: GitLab CE/EE GraphQL Unauthenticated Flaw Actively Exploited

GitLab has released fixes for CVE-2026-19478 (CVSS 9.4, EPSS 0.7% (51st percentile)), a critical-severity code injection flaw [CWE-94]. The vulnerability affects the GraphQL directive in GitLab Community Edition (CE) and Enterprise Edition (EE). According to GitLab, the flaw can allow an unauthenticated attacker to remotely modify or delete public projects and user data under certain […]

39

Patch Now! CVE-2026-18577 in N-able N-central Actively Exploited

! Update August 14th, 2026 N-able has released N-central 2026.3 Hotfix 2 (build 2026.3.1.10) after the vendor identified another attack path associated with CVE-2026-18577. Hotfix 2 adds further hardening measures and supersedes Hotfix 1 (2026.3.1.7). N-able states that the new mitigation was deployed to hosted N-central environments on August 6, while self-hosted customers must upgrade […]

40

Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water

Several concerning vulnerabilities affecting Linux have emerged in recent months. The vulnerabilities include CISA Known Exploited Vulnerabilities (KEV) entries for CVE-2026-31431 (aka Copy Fail) [1], and an older flaw, CVE-2022-0492 [2]. However, a wave of concerning new vulnerabilities are associated with publicly available exploits or proof-of-concept (PoC) code. Collectively, the flaws represent local privilege escalation, […]