The critical vulnerability CVE-2026-50571 with CVSS 9.3 allows attackers to establish VPN sessions without valid passwords and has been actively exploited against organizations worldwide since May.
Unauthenticated attackers can gain VPN access without a password through a certificate verification flaw in IKEv1 configuration and are being exploited by ransomware groups.
LiteLLM contains critical SQL injection and code execution vulnerabilities that allow complete database access and remote code execution as a system service.
Attackers systematically exploit AI branding in social engineering campaigns to manipulate employees — the attack vector is shifting from technical to behavioral vulnerabilities.
JavaScript can reveal which applications and websites a user opens via SSD-timing side channels without requiring system privileges or browser extensions.
SolarWinds Serv-U is vulnerable to unauthenticated DoS attacks through CVE-2026-28318 (CVSS 7.5); CISA reports active exploitation and sets a deadline of June 19, 2026.
Locally deployed open-source language models enable autonomous attack worms when equipped with appropriate agent architectures, independent of paid frontier models.
Ubiquiti UniFi OS contains three maximum-severity vulnerabilities that, when combined, enable unauthenticated remote access and require immediate patching.