Vulnerability Intelligence Archive
π Intelligence by Year
Section titled βπ Intelligence by YearβSelect a specific year to access the complete list of technical breakdowns and forensic data.
2026 Archive Latest zero-days and active campaigns.
2025 Archive Critical vulnerabilities and forensic studies.
2024 Archive Major enterprise and perimeter infrastructure threats.
2023 Archive Historical analysis of major 2023 flaws.
2022 Archive Identity and authentication vector studies.
2020 Archive Legacy threats and long-term impact analysis.
2012 Archive Foundational vulnerability research.
2009 Archive Historical exploits and case studies.
π΄ Recent Critical Alerts
Section titled βπ΄ Recent Critical Alertsβ CVE-2026-93952: Arista VeloCloud Orchestrator Authentication Bypass and Remote Code Execution CISA KEV active exploitation: header spoofing bypassing reverse proxy trust to achieve root code execution and SD-WAN takeover (HTS 98 / CVSS 10.0).
CVE-2026-93616: Check Point Multi-Domain Security Management Web Service Traversal and RCE CISA KEV active exploitation: unauthenticated path traversal and dynamic bytecode loading on TCP 19009 (HTS 97 / CVSS 9.8).
CVE-2026-94127: F5 BIG-IP APM TMM Heap-Based Buffer Overflow Remote Code Execution CISA KEV active exploitation: unauthenticated microkernel heap buffer overflow via malformed OAuth bearer token (HTS 96 / CVSS 9.8).
CVE-2026-77521: MaxKB Enterprise AI Platform SandboxShellBackend Command Injection and Container Breakout Unauthenticated container breakout to host via prompt injection and unvalidated MCP shell tool invocation (HTS 95 / HASS 99).
CVE-2026-7273: Zyxel GS1900 Smart Switches CGI Stack Buffer Overflow RCE CISA KEV active wild exploitation: unauthenticated stack buffer overflow in embedded CGI web daemon (HTS 95 / CVSS 8.8).
CVE-2026-92574: CRI-O Checkpoint-Restore Destination Security Context Bypass Multi-tenant Kubernetes container runtime escape retaining privileged capabilities across namespaces (HTS 91 / HASS 88).
CVE-2026-84285: Tuleap Enterprise ALM Workspace Export OS Command Injection Arbitrary server command execution and software supply chain compromise via unescaped shell parameters (HTS 89 / CVSS 8.8).
CVE-2026-70477: Flowise AI CSV Agent Prompt Injection to Host RCE Unauthenticated remote code execution via prompt injection bypassing AST blocklist in Pyodide (HASS 95 / HTS 96).
CVE-2026-78234: Hawtio Operator Service CA Signing Key Theft and Cluster Takeover Arbitrary client certificate minting using the OpenShift Service CA root key enabling cluster takeover (CVSS 9.9).
CVE-2026-86711: Electerm Desktop runGlobalAsync Electron IPC Arbitrary Command Execution Renderer-to-main IPC bridge escape executing arbitrary commands on developer workstations (HTS 88).
CVE-2026-57967: Apache ActiveMQ Artemis CORE Protocol Session Reattachment Takeover Unauthenticated remote session hijacking and takeover on port 61616 (CVSS 9.8 / HTS 96).
CVE-2026-90777: ESPnet Checkpoint Deserialization Remote Code Execution Arbitrary code execution via unsafe torch.load deserialization in AI speech models (HASS 92).
CVE-2026-84939: Apache FreeMarker Malformed Locale Path Traversal to RCE Localized lookup directory traversal leading to template sandbox escape and SSTI (CVSS 9.1).
CVE-2026-86060: MikroTik RouterOS Privilege Escalation (MikroTrick) Remote administrative takeover via SSH argument delimiter injection (CISA KEV).
CVE-2026-67277: MikroTik RouterOS Kernel Memory Leak & DoS (btest) Integer underflow and auth bypass on port 2000 Bandwidth-Test service (CISA KEV).
CVE-2026-80352: Apache Camel K Master Trait YAML Injection Arbitrary Kubernetes object creation and operator privilege escalation to cluster-admin.
CVE-2026-33825: Microsoft Defender LPE Critical LPE in Defender platform access control.
CVE-2026-39842: OpenRemote RCE Critical Expression Injection via Nashorn engine.
CVE-2026-20127: Cisco Catalyst SD-WAN Authentication Bypass Cisco Catalyst SD-WAN Authentication Bypass.