Back to Blog

vulnerability

42 posts
CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path A critical point in the new PAN-OS warning is that defenders are not looking at a ro...

May 7, 2026
4 min read
CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise

CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise

CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise Copy Fail is the kind of Linux flaw defenders should not shrug off just becau...

May 1, 2026
6 min read
CVE-2026-33032 lets attackers take over exposed nginx-ui servers

CVE-2026-33032 lets attackers take over exposed nginx-ui servers

CVE-2026-33032 lets attackers take over exposed nginx-ui servers CVE-2026-33032 is the kind of [vulnerability](https://invaders.ie/resources/glossary/vulnerabil...

April 27, 2026
5 min read
Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path

Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path

Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path The newly disclosed Pack2TheRoot issue, tracked as CVE-2026-41651, is a strong reminde...

April 25, 2026
5 min read
CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk

CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk

CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk CVE-2025-32975 is the kind of issue defenders should triage quickly because it affects a manag...

April 22, 2026
5 min read
SGLang CVE-2026-5760 turns malicious GGUF models into RCE

SGLang CVE-2026-5760 turns malicious GGUF models into RCE

SGLang CVE-2026-5760 turns malicious GGUF models into RCE Executive summary A newly disclosed flaw in SGLang means a malicious GGUF model file can become an exe...

April 21, 2026
5 min read
Apache ActiveMQ RCE CVE-2026-34197 Lands in CISA KEV

Apache ActiveMQ RCE CVE-2026-34197 Lands in CISA KEV

Apache ActiveMQ RCE CVE-2026-34197 lands in CISA KEV Executive summary CISA has added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog after attack...

April 20, 2026
5 min read
Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution

Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution

Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution A newly disclosed protobuf.js issue deserves attention well beyond the JavaScri...

April 19, 2026
5 min read
Leaked Windows Defender zero-days are already being used to gain SYSTEM access

Leaked Windows Defender zero-days are already being used to gain SYSTEM access

Leaked Windows Defender zero-days are already being used to gain SYSTEM access A fast-moving Windows story matters to defenders this week for a simple reason: p...

April 17, 2026
5 min read
CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access

CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access

CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access A critical flaw in nginx-ui, the web-based Nginx management tool, c...

April 15, 2026
2 min read
CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments

CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments

CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments CVE-2026-5194 is a reminder that core cryptographic libraries can create outsized enterp...

April 14, 2026
4 min read
Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls

Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls

Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls A newly disclosed Docker Engine and Moby flaw, tracked as CVE-2026-34040, show...

April 13, 2026
3 min read