Back to Blog
116 posts in this category

vulnerability

116 posts
Unfixed Gogs flaw can turn pull requests into server-side RCE

Unfixed Gogs flaw can turn pull requests into server-side RCE

Unfixed Gogs flaw can turn pull requests into server-side RCE A newly disclosed Gogs bug matters because it blurs the line between "authenticated" and "practica...

June 2, 2026
5 min read
Palo Alto GlobalProtect auth bypass turns cookie trust into VPN access risk

Palo Alto GlobalProtect auth bypass turns cookie trust into VPN access risk

Palo Alto GlobalProtect auth bypass turns cookie trust into VPN access risk CVE-2026-0257 matters because it turns a trust shortcut on the VPN edge into an iden...

June 1, 2026
5 min read
FortiClient EMS exploit turns endpoint management into credential theft at scale

FortiClient EMS exploit turns endpoint management into credential theft at scale

FortiClient EMS exploit turns endpoint management into credential theft at scale CVE-2026-35616 matters because it breaks a security assumption many teams quiet...

May 31, 2026
5 min read
CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline

CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline

CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline CVE-2026-48172 has escalated from vendor emergency to federal patching priority. On May 26, 2...

May 27, 2026
5 min read
CVE-2026-9082 makes Drupal on PostgreSQL an urgent KEV patch priority

CVE-2026-9082 makes Drupal on PostgreSQL an urgent KEV patch priority

CVE-2026-9082 makes Drupal on PostgreSQL an urgent KEV patch priority CVE-2026-9082 is no longer just a critical Drupal patch note. It is now an actively target...

May 27, 2026
5 min read
Microsoft MDASH surfaces 16 Windows network flaws defenders should patch first

Microsoft MDASH surfaces 16 Windows network flaws defenders should patch first

Microsoft MDASH surfaces 16 Windows network flaws defenders should patch first Microsoft's May 12, 2026 security disclosures included a point that deserves more...

May 26, 2026
7 min read
CVE-2024-12802 leaves SonicWall Gen6 VPNs exposed after incomplete patching

CVE-2024-12802 leaves SonicWall Gen6 VPNs exposed after incomplete patching

CVE-2024-12802 leaves SonicWall Gen6 VPNs exposed after incomplete patching CVE-2024-12802 is the kind of edge-device flaw that can fool defenders twice: once d...

May 21, 2026
6 min read
CVE-2026-41615: Microsoft Authenticator Token Theft Risk

CVE-2026-41615: Microsoft Authenticator Token Theft Risk

CVE-2026-41615: Microsoft Authenticator Token Theft Risk | 2026 Executive Summary CVE-2026-41615 is a critical Microsoft Authenticator flaw that can expose ente...

May 19, 2026
5 min read
CVE-2026-42945 makes NGINX rewrite chains a live patch priority

CVE-2026-42945 makes NGINX rewrite chains a live patch priority

CVE-2026-42945 makes NGINX rewrite chains a live patch priority CVE-2026-42945 has moved from fresh disclosure to active exploitation in days, which is exactly...

May 18, 2026
6 min read
CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority

CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority

CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority CVE-2026-42897 is the kind of [zero-day](https://invaders.ie/resources/glossary/zero-day)...

May 16, 2026
5 min read
CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority

CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority

CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority CVE-2026-20182 is not landing as a routine patch bulletin. Cisco says the flaw is already b...

May 15, 2026
6 min read
Exim BDAT flaw makes mail servers urgent RCE patch targets

Exim BDAT flaw makes mail servers urgent RCE patch targets

Exim BDAT flaw makes mail servers urgent RCE patch targets CVE-2026-45185 is the kind of bug that forces defenders to remember an old lesson: email infrastructu...

May 14, 2026
5 min read