Guardians of the Enterprise — Insights from leading cyber experts.

Listen Now →

Security Bulletin

79 articles

← All Articles
<em>Oracle’s July 2026 CPU</em>: Critical Unauth Vulnerabilities in PeopleSoft, WebLogic, and E-Business Suite

Oracle’s July 2026 CPU: Critical Unauth Vulnerabilities in PeopleSoft, WebLogic, and E-Business Suite

Oracle's largest-ever CPU patches critical unauthenticated flaws in PeopleSoft, WebLogic, and E-Business Suite. See AppTrana's coverage for each.

<em>Copilot RCE</em>, <em>Entra SSRF</em>, and <em>SharePoint Zero-Day</em>: Critical Vulnerabilities in Microsoft’s July 2026 Advisory

Copilot RCE, Entra SSRF, and SharePoint Zero-Day: Critical Vulnerabilities in Microsoft’s July 2026 Advisory

An actively exploited SharePoint zero-day, Copilot command injection, and Entra SSRF top Microsoft's July 2026 advisory. Get the…

<em>CVE-2026-6875</em>: ServiceNow Sandbox Escape Leads to Pre-Auth RCE in AI Platform

CVE-2026-6875: ServiceNow Sandbox Escape Leads to Pre-Auth RCE in AI Platform

Critical unauthenticated RCE vulnerability CVE-2026-6875 hits ServiceNow via a GlideRecord sandbox escape. Attackers are already exploiting unpatched instances.

WP2Shell: WordPress Core SQLi + REST API Chain to Pre-Auth RCE

WP2Shell: WordPress Core SQLi + REST API Chain to Pre-Auth RCE

WP2Shell chains CVE-2026-60137 and CVE-2026-63030 for unauthenticated RCE on WordPress Core. Patch to 6.8.6, 6.9.5, or 7.0.2 now,…

<em>CVE-2026-48282</em>: ColdFusion RDS Vulnerability Actively Exploited

CVE-2026-48282: ColdFusion RDS Vulnerability Actively Exploited

CVE-2026-48282 is a critical ColdFusion RDS path traversal vulnerability under active exploitation. Learn the risks, IOCs, and how…

CVE-2026-33017: Langflow RCE Deploys Monero Miners on AI Servers

CVE-2026-33017: Langflow RCE Deploys Monero Miners on AI Servers

Langflow CVE-2026-33017 is under active exploitation. Attackers deploy Monero miners via unauthenticated RCE. Get IOCs, patch steps, and…

CVE-2026-46817: Oracle EBS Payments Vulnerability Under Active Exploitation

CVE-2026-46817: Oracle EBS Payments Vulnerability Under Active Exploitation

Oracle E-Business Suite (EBS) sits at the center of finance, procurement, and payment operations for many large enterprises.…

<em>CVE-2026-42271</em>: Unauthenticated RCE in <em>LiteLLM </em>AI Gateway

CVE-2026-42271: Unauthenticated RCE in LiteLLM AI Gateway

CVE-2026-42271 enables unauthenticated RCE in LiteLLM when chained with CVE-2026-48710. Learn wha is at risk and how to…

<em>CVE-2026-35273</em>: Active Exploitation of<em> Oracle PeopleSoft Zero-Day </em>Vulnerability

CVE-2026-35273: Active Exploitation of Oracle PeopleSoft Zero-Day Vulnerability

Oracle has disclosed CVE-2026-35273, a critical vulnerability in PeopleSoft Enterprise PeopleTools that has already been exploited by threat…

<em>CVE-2026-45247</em>: Critical RCE Vulnerability in <em>Mirasvit Cache Warmer</em>

CVE-2026-45247: Critical RCE Vulnerability in Mirasvit Cache Warmer

CVE-2026-45247 is a critical PHP deserialization vulnerability in Mirasvit Cache Warmer allowing unauthenticated RCE. Learn the impact and…

NGINX Under Active Attack: <em>CVE-2026-42945</em> and <em>CVE-2026-9256</em> Put Your Infrastructure at Risk

NGINX Under Active Attack: CVE-2026-42945 and CVE-2026-9256 Put Your Infrastructure at Risk

Two critical NGINX heap buffer overflows are under active exploitation. Learn what's at risk, affected versions, and fixes…

CVE-2026-9082: Critical <em>Drupal SQL Injection Vulnerability</em> Affects PostgreSQL Deployments

CVE-2026-9082: Critical Drupal SQL Injection Vulnerability Affects PostgreSQL Deployments

A critical SQLi vulnerability in Drupal core is actively exploited. Find out which versions are affected, what's at…