More than 1,300 internet-exposed Microsoft SharePoint servers remain vulnerable to ongoing intrusions weaponizing the zero-day spoofing flaw,...
patchconfiguration-management
The vulnerability stems from a regression in specific versions of the Microsoft.AspNetCore.DataProtection NuGet packages.
The vulnerability, identified as CVE-2026-28950, was patched on April 22, 2026, in iOS 26.4.2 and iPadOS 26.4.2,...
A BeyondTrust report found a twofold increase in critical flaws in Microsoft software despite a 6% drop...
Active intrusions exploiting the high-severity Apache ActiveMQ code injection flaw, tracked as CVE-2026-34197, could compromise 6,476 internet-exposed...
Misconfigured Perforce servers remain widespread, threaten sensitive data exposure Improperly secured internet-exposed Perforce P4 servers continue to...
SecurityWeek reports that Forescout Technologies identified 20 new vulnerabilities in Sliex and Lantronix serial-to-IP converters, or serial...
CISA flags new Cisco SD-WAN flaw amid active exploit chains, urging rapid patching.
The median lead time between activity surge and advisory publication was 11 days.
The vulnerability, tracked as GHSA-xq3m-2v4x-88gg, stems from unsafe dynamic code generation within protobuf.js.