Actively Exploited CVEs
62 article(s)
🗓 03 Feb 2026 · 👤 SECPULSE
A pair of critical vulnerabilities in Ivanti EPMM have triggered rapid, targeted exploitation attempts worldwide. Security teams are urged to patch immediately as attackers deploy advanced techniques to compromise enterprise systems.
🗓 28 Jan 2026 · 👤 LOGICFALCON · 🌍 Europe
A critical WinRAR vulnerability, CVE-2025-8088, is being exploited by state-backed hackers and cybercriminals to gain persistent access to Windows systems. Despite an available patch, the flaw remains a favorite tool for espionage and financial crime campaigns.
🗓 27 Jan 2026 · 👤 SECPULSE
Federal cybersecurity officials warn of active exploitation of two major Linux vulnerabilities, including a critical telnetd flaw allowing attackers to bypass authentication and gain root access. Organizations are urged to patch immediately as attacks escalate.
🗓 26 Jan 2026 · 👤 LOGICFALCON
AI-generated malware, ancient bugs, and hijacked browser extensions: This week in cybercrime shows how routine oversights and trusted tools are now the biggest risks. Read Netcrook’s investigative recap.
🗓 26 Jan 2026 · 👤 SECPULSE · 🌍 North America
A newly exploited VMware vCenter Server vulnerability has triggered an urgent federal response, with agencies ordered to patch systems within three weeks to prevent breaches.
🗓 26 Jan 2026 · 👤 LOGICFALCON
A critical flaw in GNU software, CVE-2026-24061, is being actively exploited across networks. Learn how attackers are targeting systems and what steps can be taken to mitigate the risk.
🗓 26 Jan 2026 · 👤 SECPULSE · 🌍 North America
CISA has confirmed active exploitation of a critical VMware vCenter Server vulnerability (CVE-2024-37079) allowing remote code execution. Organizations must patch or mitigate immediately as attackers target virtual infrastructure worldwide.
🗓 24 Jan 2026 · 👤 LOGICFALCON · 🌍 North America
A critical VMware vCenter Server flaw (CVE-2024-37079) is being actively exploited, prompting CISA to add it to its KEV catalog. Here’s what’s at stake and why rapid patching is essential.
🗓 24 Jan 2026 · 👤 SECPULSE
A dramatic authentication bypass in telnetd sparked a frenzy among cybercriminals, but most attacks failed due to hardened targets and obsolete systems. Our investigative feature unpacks the exploit, attack patterns, and lessons for legacy system security.
🗓 24 Jan 2026 · 👤 LOGICFALCON · 🌍 North America
CISA has sounded the alarm on four actively exploited vulnerabilities in major enterprise software, including Versa Concerto, Zimbra, Vite, and Prettier. Discover the technical details, risks, and what organizations must do to stay protected.