Security Feeds

A living view of what actually matters right now: vulnerabilities under active exploitation, new high-severity CVEs, AI security research and incidents, and fresh threat intel, each with impact, remediation, and a risk rating computed from CISA KEV listing, CVSS, and EPSS exploit-prediction scores. Updated automatically twice a day. Click any row for details.

CISA Known Exploited VulnerabilitiesNIST NVD: new high/critical CVEs (7 days)GitHub Security AdvisoriesSANS Internet Storm Centerabuse.ch ThreatFox (24h IOCs)abuse.ch URLhaus (recent malware URLs)Have I Been Pwned (new breaches)arXiv: LLM/AI security researchAI Incident DatabaseEmbrace The Red (AI red-teaming)The Hacker NewsBleepingComputerGroup-IB ResearchObjective-See (macOS)Sophos X-OpsPalo Alto Unit 42Malicious Extensions (malext)LayerX SecurityAlmost Secure (Palant)Ransomware.live (leak-site victims)Vendor Watch (demo watchlist)Last updated 2026-10-11 18:11 UTC

Known-exploited or highest-likelihood items across all sources.

criticalCVE-2026-108261: TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment

TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment, allowing attackers to inject arbitrary content into the preview environment. This vulnerability affects the tinacms and @tinacms/app npm packages with critical severity.

Impact: TinaCMS administrators and users with access to the admin preview feature are at critical risk of content injection, session hijacking, or credential theft through malicious URLs.

Remediation: Update tinacms and @tinacms/app packages to patched versions immediately. Review any TinaCMS instances for signs of exploitation, particularly checking URL fragments in admin preview sessions.

GitHub Security AdvisoriesCVSS 9.3EPSS 0.2%View at sourceCheck on VirusTotal

criticalCVE-2026-107845: Contao: Cross-site scripting in the comments bundle

A cross-site scripting vulnerability exists in Contao's comments bundle that allows attackers to inject malicious scripts through comments. This vulnerability is rated as critical severity.

Impact: Any Contao installation using the comments bundle is vulnerable to XSS attacks that could compromise user sessions, steal authentication tokens, or deface website content.

Remediation: Update the contao/comments-bundle package to the latest patched version immediately through your package manager. Review any user-submitted comments in your system for suspicious content.

GitHub Security AdvisoriesCVSS 9.3EPSS 0.3%View at sourceCheck on VirusTotal

criticalCVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a vulnerability in TKEY query processing that allows remote attackers to trigger denial of service conditions. This vulnerability has been actively exploited in the wild.

Impact: DNS services relying on vulnerable BIND versions are at immediate risk of disruption due to active exploitation.

Remediation: Update ISC BIND to a patched version addressing CVE-2015-5477 immediately. If immediate patching is not possible, restrict TKEY query access at the firewall or through access control lists.

CISA Known Exploited VulnerabilitiesEPSS 99.4%View at sourceCheck on VirusTotal

criticalCVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache Struts versions with Dynamic Method Invocation enabled contain a command injection vulnerability (CVE-2016-3081) that allows remote attackers to execute arbitrary code through the method:prefix parameter. This vulnerability is actively exploited in the wild.

Impact: Organizations running vulnerable Apache Struts deployments with Dynamic Method Invocation enabled face active exploitation risk, potentially leading to full system compromise and unauthorized code ex…

Remediation: Disable Dynamic Method Invocation in Apache Struts configuration, or upgrade to a patched version of Apache Struts that addresses this vulnerability. Review deployment configurations immediately to identify affected instances.

CISA Known Exploited VulnerabilitiesEPSS 96.1%View at sourceCheck on VirusTotal

criticalCVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability

CVE-2023-22894 is a cleartext storage vulnerability in Strapi that allows attackers with admin panel access to extract sensitive user information through query filters. This vulnerability is actively exploited in the wild and affects potentially end-of-life product versions.

Impact: Organizations running vulnerable or end-of-life Strapi instances face active exploitation risk, with attackers able to access sensitive user data if they gain admin panel access.

Remediation: Immediately upgrade to a supported version of Strapi if currently running an affected release. If running an unsupported version, migrate to a newer major version or discontinue use of the product.

CISA Known Exploited VulnerabilitiesEPSS 3.6%View at sourceCheck on VirusTotal

criticalCVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs Server contains a path traversal vulnerability in image upload handling when JWT authentication is used, allowing attackers to bypass directory restrictions via ../ sequences. The vulnerability can lead to remote code execution and is currently being actively exploited.

Impact: Organizations running vulnerable ONLYOFFICE Docs Server instances are at high risk of unauthorized remote code execution, data theft, and system compromise due to active exploitation.

Remediation: Update ONLYOFFICE Docs Server to a patched version immediately. If immediate patching is not possible, restrict access to the image upload functionality and disable JWT-based authentication if alternative methods are available.

CISA Known Exploited VulnerabilitiesEPSS 19.4%View at sourceCheck on VirusTotal

criticalCVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability in the site cpfr and site cpto commands that allows remote attackers to read and write arbitrary files. This vulnerability is being actively exploited in the wild.

Impact: Any organization running vulnerable ProFTPD instances faces risk of unauthorized file access, modification, or exfiltration by remote attackers.

Remediation: Update ProFTPD to a patched version that addresses CVE-2015-3306. Disable or restrict access to the site cpfr and site cpto commands if immediate patching is not possible.

CISA Known Exploited VulnerabilitiesEPSS 99.5%View at sourceCheck on VirusTotal

criticalCVE-2026-12260 (CVSS 10)

SQL injection vulnerability exists in NetBoard CRM demo platform's authentication recovery endpoint, affecting the 'user-name' POST parameter at '/module/auth/recovery.php'. The flaw allows blind SQL injection attacks via Boolean, error, time-based, and UNION query techniques, enabling unauthorized data extraction and modification.

Impact: Attackers can extract sensitive data such as database version and type, modify or delete records, and potentially escalate privileges, affecting all users and data on accessible NetBoard CRM instance…

Remediation: Apply vendor patches immediately and implement parameterized queries or prepared statements for all user inputs in the affected endpoint. If patches are unavailable, restrict network access to the recovery endpoint to trusted IP ranges until a fix is released.

NIST NVD: new high/critical CVEs (7 days)CVSS 10EPSS 0.2%View at sourceCheck on VirusTotal

criticalCVE-2026-15762 (CVSS 9.8)

IBM DataPower Gateway versions 10.5.0.0 through 11.0.0.2 contain an out-of-bounds write vulnerability allowing remote code execution. The flaw affects multiple version branches and has a critical CVSS score of 9.8.

Impact: Organizations running affected DataPower Gateway versions face remote code execution risk from network-based attacks with no authentication required, potentially compromising API management, security…

Remediation: Update IBM DataPower Gateway to a patched version above 11.0.0.2 or the latest available release for your version branch. Check IBM security advisories for specific patch versions and apply immediately.

NIST NVD: new high/critical CVEs (7 days)CVSS 9.8EPSS 0.5%View at sourceCheck on VirusTotal

criticalCVE-2026-14991 (CVSS 9.8)

IBM DataPower Gateway versions 10.5.0.0 through 11.0.0.2 contain a buffer overflow vulnerability caused by improper bounds checking that allows local users to execute arbitrary code. The vulnerability affects multiple version branches with CVSS score of 9.8.

Impact: Organizations running vulnerable DataPower Gateway versions face critical risk of complete system compromise through local code execution by authenticated users.

Remediation: Update IBM DataPower Gateway to a patched version above the affected ranges (after 10.5.0.22, 10.6.6, 10.6.0.10, or 11.0.0.2). Review access controls to restrict local user privileges on DataPower Gateway systems.

NIST NVD: new high/critical CVEs (7 days)CVSS 9.8EPSS 0.4%View at sourceCheck on VirusTotal

criticalCVE-2026-107722: fast-jwt: Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion

The fast-jwt library contains an incomplete patch for a previous algorithm confusion vulnerability. An attacker can use non-whitespace key prefixes to bypass the remediation and exploit RSA to HS256 algorithm confusion attacks.

Impact: Applications using vulnerable versions of fast-jwt are at critical risk of authentication bypass and token forgery attacks.

Remediation: Update fast-jwt to the latest patched version immediately. Review any authentication systems using fast-jwt to ensure they enforce strict algorithm validation at the application level.

GitHub Security AdvisoriesCVSS 9.8EPSS 0.3%View at sourceCheck on VirusTotal

criticalCVE-2026-61445: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsAI

PraisonAI versions distributed via pip contain a critical vulnerability allowing arbitrary file write and command execution through LLM tool calls. An attacker can exploit the AICoder component to write malicious files or execute arbitrary commands on affected systems.

Impact: Systems running vulnerable PraisonAI versions face complete compromise through remote code execution, affecting any application or service relying on the library.

Remediation: Immediately update PraisonAI to a patched version from pip and review any systems that may have executed untrusted LLM-generated commands through this tool. Restrict LLM tool call permissions and monitor file system activity on affected servers.

GitHub Security AdvisoriesCVSS 9.9EPSS 0.9%View at sourceCheck on VirusTotal

criticalCVE-2026-76482 (CVSS 10)

Cisco License On-Prem (formerly Smart Software Manager On-Prem) contains a critical, network-exploitable vulnerability (CVE-2026-76482, CVSS 10.0) discovered during an internal security review. The flaw affects the licensing management system and requires immediate patching.

Impact: Any organization running Cisco License On-Prem is at critical risk of remote compromise, potentially affecting license management and dependent services across their infrastructure.

Remediation: Apply the software hardening release from Cisco that addresses CVE-2026-76482 as soon as possible. Restrict network access to Cisco License On-Prem systems until the patch is deployed.

NIST NVD: new high/critical CVEs (7 days)CVSS 10EPSS 0.2%View at sourceCheck on VirusTotal

criticalCVE-2025-70518 (CVSS 10)

Fanvil x7a firmware version 2.6.0.1182 contains a critical command injection vulnerability in the diagnostic ping tool that allows unauthenticated attackers to execute arbitrary code on the device. The management portal fails to properly validate user input, enabling remote code execution on the underlying Android operating system.

Impact: Any attacker on the network can remotely execute commands with system privileges on affected Fanvil x7a phones without authentication, potentially compromising call integrity, data stored on devices,…

Remediation: Immediately update Fanvil x7a devices to a patched firmware version beyond 2.6.0.1182. If an update is unavailable, restrict network access to the management portal using firewall rules to block unauthorized connections.

NIST NVD: new high/critical CVEs (7 days)CVSS 10EPSS 0.6%View at sourceCheck on VirusTotal

criticalCVE-2026-102255 (CVSS 10)

A critical pre-authentication SSRF vulnerability (CVE-2026-102255) in SMA1000 Appliance Work Place interface allows remote unauthenticated attackers to bypass authentication and make the appliance issue arbitrary requests to internal systems. An attacker could exploit this to access restricted functionality and perform unauthorized operations.

Impact: Any organization using SMA1000 appliances is at risk of complete compromise of internal systems accessible from the appliance, including data theft and unauthorized administrative actions.

Remediation: Apply the vendor security patch for CVE-2026-102255 to the SMA1000 appliance immediately, as this vulnerability requires no authentication to exploit. If patching is delayed, restrict network access to the Work Place interface to trusted networks only.

NIST NVD: new high/critical CVEs (7 days)CVSS 10EPSS 0.5%View at sourceCheck on VirusTotal