CISA’s KEV listing of two Fortinet flaws shows how a security appliance can become a remote-command foothold when command input is not properly controlled.
Two exploited command-injection flaws put Fortinet’s sandbox appliance in the uncomfortable role of attack surface, not inspection shield.
A critical Oracle E-Business Suite flaw tied to Oracle Payments is being treated as an urgent patching problem because exploitation is already underway.
Two newly disclosed zero-days in the SMA1000 line combine SSRF and code injection into a chain that can lead to root-level command execution, pushing defenders toward forensic triage, not just patching.
CISA’s addition of CVE-2026-46817 turns an Oracle E-Business Suite Payments issue into an urgent remediation problem, not a routine maintenance item.
Mozilla has pushed security updates for two critical Firefox flaws that are reportedly being exploited online, putting patch speed and endpoint visibility at the center of defense.
Active exploitation against iCagenda and Balbooa Forms shows how a routine upload feature can become a dangerous server-side trust boundary when controls are too loose.
File-upload flaws in iCagenda and Balbooa Forms show how a routine form feature can become a serious server-side risk when untrusted files are handled too loosely.
A maximum-severity Adobe ColdFusion flaw has moved into emergency patch territory, showing how quickly an internet-facing server bug can become a compliance and exposure problem.
A critical Adobe ColdFusion flaw is drawing attacker interest because the real danger is not only severity, but whether exposed servers were patched before exploitation began.
A Cisco Unified CM flaw tied to WebDialer shows how a small, enabled feature can turn a communications platform into a live target once a public exploit appears.
A May Microsoft fix has already become a live defensive problem, with public vulnerability records pointing to a high-severity SharePoint server flaw now under attack.
A new KEV entry for a Microsoft SharePoint Server vulnerability shifts the issue from routine patching to urgent exposure control for on-prem defenders.
Cisco has confirmed active exploitation of a Unified Communications Manager flaw patched in early June, turning a routine update into an urgent inventory and patching problem for enterprise voice teams.
CISA’s addition of CVE-2026-45659 to its exploited-vulnerability catalog puts Microsoft SharePoint Server operators on a short clock, with deserialization risk now treated as an active threat rather than a routine patch item.
Multiple internet-reachable E-Business Suite instances are drawing scrutiny as a critical Oracle Payments flaw is described as actively exploited.
A patched flaw in Windchill PDMLink and FlexPLM is being actively abused in the wild, turning a product-data platform into an urgent patch-and-hunt problem.
A recent critical flaw in Oracle E-Business Suite has crossed from disclosure into active exploitation, putting payment workflows in the crosshairs of opportunistic attackers.
A critical weakness in remote-support software shows how one privileged login path can become a launch point for malware, secret theft, and broader endpoint risk.
A critical Oracle E-Business Suite flaw tied to payment processing has moved into the exploitation phase, turning patch urgency into an operational risk for exposed enterprise systems.