CISA documents four actively exploited security vulnerabilities in widely used enterprise software, including a critical path-traversal flaw in Adobe ColdFusion with maximum CVSS rating.
AI models are accelerating autonomous attack chain execution to such an extent that classical patch management alone no longer serves as sufficient protection.
FortiBleed actors monetize their access to Fortinet firewalls through cooperation with Inc and Lynx ransomware groups while also deploying zero-day exploits against Nextcloud.
An actively exploited XSS vulnerability in Exchange OWA is being patched for current versions but remains unfixed for Exchange 2016/2019 without paid Extended Support.
The GreatXML exploit leverages a security vulnerability in Microsoft’s offline scan function to bypass BitLocker and access encrypted drives from recovery mode after a successful Defender offline scan.
Oracle has patched a critical vulnerability in PeopleSoft Suite (CVE-2026-35273) enabling unauthenticated remote code execution that is already being actively exploited in targeted data theft campaigns by the ShinyHunter group.
Of 206 patched vulnerabilities, 39 are classified as critical, including 56 remote code execution and 63 privilege escalation flaws, with three publicly disclosed zero-days.