Skip to content
Hermes Codex
Search
Ctrl
K
Cancel
GitHub
Select theme
Dark
Light
Auto
Select language
English
FranΓ§ais
π§ INTELLIGENCE
β‘ Today's Intelligence
π Threat Observatory
π Risk Trajectories
π― Forward Forecasts
π Prediction Benchmark
π₯ SOLUTIONS
π‘οΈ For Security Leaders & CISOs
π¬ For Security Analysts & DFIR
π» For Software & DevOps
π€ For AI & Agentic Security
π ANALYZE
π» My Stack (Sovereign)
π¦ SBOM Security Analyzer
π Software Risk (HTS)
π€ AI & Agentic Risk
π― DECIDE
π― Hermes Decision Engine
βοΈ Security Delta
π₯ Agent Blast Radius
β οΈ Agent Death Simulator
π Webhooks & Alerting
π¬ RESEARCH
π¬ Research Hub
π Historical Replay
β³ Cyber Risk Time Machine
π¬ Forensic Autopsies
𧬠Vulnerability Genome
ποΈ PLATFORM
ποΈ Platform Overview
π‘ Machine-Readable Data
πΈοΈ Knowledge Graph
π‘ STIX 2.1 & TAXII 2.1 Feeds
π‘ Data Status & Health
π‘οΈ Trust Center & Limits
π Sovereign Privacy Model
π Methodology
π PRICING
π Pricing & Commercial Plans
π¦ Software Intelligence
Interactive Workbench
Product Intelligence Pages
MaxKB Enterprise AI Platform
Adobe Acrobat Reader
Adobe ColdFusion
AWS MCP Server
Ansible Automation Platform
Claude Code Agentic CLI
Cursor AI Code Editor
Apache ActiveMQ
Apache Airflow
Apache Camel K
Apache HTTP Server
Apache Kafka
Apache Log4j
Apache Solr
Apache Struts
Apache Tomcat
Apple iOS Simulator MCP Server
Apple macOS
Arista VeloCloud Orchestrator
Atlassian Bitbucket Server & Data Center
Atlassian Confluence Server & Data Center
Atlassian Jira Software Server & Data Center
Check Point Quantum Security Gateway (Gaia OS)
Check Point Security Management Server
ChromaDB AI Vector Database
Cisco Adaptive Security Appliance (ASA)
Cisco AnyConnect Secure Mobility Client
Cisco Identity Services Engine (ISE)
Cisco IOS XE
Cisco Catalyst SD-WAN Manager
Cisco Secure Email Gateway
Cisco Secure Firewall Management Center
Citrix NetScaler ADC & Gateway
ConnectWise ScreenConnect
CrewAI
CRI-O Container Runtime
curl & libcurl
PostgreSQL Anonymizer (anon)
Dify GenAI App Platform
Django Python Web Framework
Docker Engine
Eclipse Theia IDE
Kibana Data Visualization
Elasticsearch
Elementor Website Builder
EmailGPT Service
Tuleap Enterprise ALM
Envoy Service Proxy
Erlang/OTP
F5 BIG-IP TMOS
Flowise
Fortinet FortiClient EMS
Fortinet FortiManager
Fortinet FortiOS
Fortinet FortiSandbox
Fortinet FortiWeb
Git Distributed Version Control
GitHub Copilot
GitLab CE / EE
GNU C Library (glibc)
Go Language & Standard Library
Google Chromium / V8
Grafana
HAProxy Load Balancer
HashiCorp Terraform
HashiCorp Vault
Hugging Face Transformers
IBM ContextForge MCP Gateway
Ivanti Connect Secure
Ivanti Endpoint Manager Mobile (EPMM)
Ivanti Neurons for ITSM
Ivanti Sentry
Jenkins Automation Server
JetBrains TeamCity
JFrog Artifactory
Juniper Junos OS
Kestra Orchestrator
Starlette / FastAPI ASGI Framework
Kubernetes
LangChain
Langflow
Linux Kernel Core
MLflow Machine Learning Platform
LiteLLM
Lobe Chat Framework
MariaDB Server
mcp-atlassian (Model Context Protocol)
Memcached In-Memory Cache
React & React Server Components
Microsoft Exchange Server
Microsoft 365 Copilot
Microsoft Office & 365 Apps
Microsoft SharePoint Server
Microsoft SQL Server
Microsoft Windows
MikroTik RouterOS
AnythingLLM Desktop & Workspace
Mistral Vibe Coding Agent
MongoDB Document Database
MongoDB Document Database
Mozilla Firefox
N-able N-central
n8n Automation
nginx
Node.js JavaScript Runtime
Ollama
LMDeploy Serving Engine
OpenSSH
OpenSSL
OpenVPN
Open WebUI
OpenWrt Embedded Linux
Oracle Database Server
Oracle E-Business Suite
Oracle Java SE & OpenJDK Runtime
Oracle MySQL Server & Ecosystem
Oracle WebLogic Server
Flask Python Microframework
Palo Alto Networks PAN-OS
Palo Alto Networks GlobalProtect
PaperCut NG / MF Print Management
pgAdmin 4 Administration Suite
PostgreSQL JDBC Driver (pgjdbc)
PHP Hypertext Preprocessor
PostgreSQL
Proxmox Virtual Environment (VE)
pip Package Installer for Python
CPython Interpreter & Standard Library
Pillow (Python Imaging Library)
Qdrant Vector Search Engine
QEMU Virtualizer & Machine Emulator
QNAP QTS Operating System
RabbitMQ
WinRAR
Redis
Roundcube Webmail
Ruby on Rails
Sangoma Switchvox PBX
SAP NetWeaver
SimpleHelp Remote Access
Snorkel AI Programmatic Labeling
SolarWinds Access Rights Manager (ARM)
SolarWinds Orion Platform / Hybrid Cloud Observability
Sonatype Nexus Repository Manager
SonicWall Secure Mobile Access 1000
SonicWall SMA 100 Series
SonicWall SonicOS
Splunk Enterprise
SQLite Database Library
Sudo
Zimbra Collaboration Suite (ZCS)
Synology DiskStation Manager (DSM)
systemd System & Service Manager
TanStack NPM Ecosystem
Traefik Cloud Native Proxy
Veeam Backup & Replication
Next.js
vLLM Inference Engine
VMware ESXi
VMware Horizon
Spring Framework
VMware vCenter Server
Wireshark Network Analyzer
WooCommerce E-Commerce
Wordfence Security
Agentimus AI SEO & MCP
Blocksy Companion
Kirki Customizer Framework
Really Simple Security
Slider Revolution
Super Forms - Drag & Drop Form Builder
WordPress Core
Zabbix Monitoring Platform
Zyxel GS1900 Series Smart Switch
π Canonical Observations
π Observation Registry
Registry
OBS-2020-000001 (CVE-2020-2021)
RETRO
OBS-2020-000003 (CVE-2020-3452)
RETRO
OBS-2022-000005 (CVE-2022-42475)
RETRO
OBS-2023-000007 (CVE-2023-20198)
RETRO
OBS-2023-000009 (CVE-2023-27997)
RETRO
OBS-2024-000011 (CVE-2024-0012)
RETRO
OBS-2024-000013 (CVE-2024-20353)
RETRO
OBS-2024-000015 (CVE-2024-20359)
RETRO
OBS-2024-000017 (CVE-2024-21762)
RETRO
OBS-2024-000019 (CVE-2024-3400)
RETRO
OBS-2024-000021 (CVE-2024-47575)
RETRO
OBS-2025-000003 (CVE-2025-26319)
RETRO
OBS-2025-000005 (CVE-2025-3248)
RETRO
OBS-2025-000007 (CVE-2025-39682)
RETRO
OBS-2025-000009 (CVE-2025-54794)
RETRO
OBS-2025-000011 (CVE-2025-54795)
RETRO
OBS-2025-000013 (CVE-2025-59528)
RETRO
OBS-2025-000025 (CVE-2025-26319)
RETRO
OBS-2025-000027 (CVE-2025-3248)
RETRO
OBS-2025-000029 (CVE-2025-39682)
RETRO
OBS-2025-000031 (CVE-2025-54794)
RETRO
OBS-2025-000033 (CVE-2025-54795)
RETRO
OBS-2025-000035 (CVE-2025-59528)
RETRO
OBS-2025-000173 (CVE-2025-39964)
RETRO
OBS-2025-000174 (CVE-2025-39964)
RETRO
OBS-2025-000193 (CVE-2025-39964)
RETRO
OBS-2025-000194 (CVE-2025-39964)
RETRO
OBS-2025-000221 (CVE-2025-39964)
RETRO
OBS-2025-000222 (CVE-2025-39964)
RETRO
OBS-2025-000234 (CVE-2025-39964)
RETRO
OBS-2025-000235 (CVE-2025-39964)
RETRO
OBS-2025-000246 (CVE-2025-39964)
RETRO
OBS-2025-000247 (CVE-2025-39964)
RETRO
OBS-2026-000001 (CVE-2025-25249)
RETRO
OBS-2026-000002 (CVE-2020-2021)
LIVE
OBS-2026-000004 (CVE-2020-3452)
LIVE
OBS-2026-000006 (CVE-2022-42475)
LIVE
OBS-2026-000008 (CVE-2023-20198)
LIVE
OBS-2026-000010 (CVE-2023-27997)
LIVE
OBS-2026-000012 (CVE-2024-0012)
LIVE
OBS-2026-000014 (CVE-2024-20353)
LIVE
OBS-2026-000015 (CVE-2026-11393)
RETRO
OBS-2026-000016 (CVE-2024-20359)
LIVE
OBS-2026-000017 (CVE-2026-18486)
RETRO
OBS-2026-000018 (CVE-2024-21762)
LIVE
OBS-2026-000019 (CVE-2026-19490)
RETRO
OBS-2026-000020 (CVE-2024-3400)
LIVE
OBS-2026-000021 (CVE-2026-20079)
RETRO
OBS-2026-000022 (CVE-2024-47575)
LIVE
OBS-2026-000023 (CVE-2025-25249)
RETRO
OBS-2026-000024 (CVE-2025-25249)
RETRO
OBS-2026-000025 (CVE-2026-20307)
RETRO
OBS-2026-000026 (CVE-2025-26319)
RETRO
OBS-2026-000027 (CVE-2026-20324)
RETRO
OBS-2026-000028 (CVE-2025-3248)
RETRO
OBS-2026-000029 (CVE-2026-22708)
RETRO
OBS-2026-000030 (CVE-2025-39682)
LIVE
OBS-2026-000031 (CVE-2026-22778)
RETRO
OBS-2026-000032 (CVE-2025-54794)
RETRO
OBS-2026-000033 (CVE-2026-28326)
RETRO
OBS-2026-000034 (CVE-2025-54795)
RETRO
OBS-2026-000035 (CVE-2026-32626)
RETRO
OBS-2026-000036 (CVE-2025-59528)
RETRO
OBS-2026-000037 (CVE-2026-11393)
RETRO
OBS-2026-000038 (CVE-2026-11393)
RETRO
OBS-2026-000039 (CVE-2026-18486)
RETRO
OBS-2026-000040 (CVE-2026-18486)
LIVE
OBS-2026-000041 (CVE-2026-19490)
RETRO
OBS-2026-000042 (CVE-2026-19490)
RETRO
OBS-2026-000043 (CVE-2026-20079)
RETRO
OBS-2026-000044 (CVE-2026-20079)
RETRO
OBS-2026-000045 (CVE-2026-20192)
RETRO
OBS-2026-000046 (CVE-2026-20192)
LIVE
OBS-2026-000047 (CVE-2026-20307)
RETRO
OBS-2026-000048 (CVE-2026-20307)
LIVE
OBS-2026-000049 (CVE-2026-20324)
RETRO
OBS-2026-000050 (CVE-2026-20324)
LIVE
OBS-2026-000051 (CVE-2026-22708)
RETRO
OBS-2026-000052 (CVE-2026-22708)
RETRO
OBS-2026-000053 (CVE-2026-22778)
RETRO
OBS-2026-000054 (CVE-2026-22778)
LIVE
OBS-2026-000055 (CVE-2026-22807)
LIVE
OBS-2026-000056 (CVE-2026-22807)
LIVE
OBS-2026-000057 (CVE-2026-27825)
RETRO
OBS-2026-000058 (CVE-2026-27826)
RETRO
OBS-2026-000059 (CVE-2026-28326)
RETRO
OBS-2026-000060 (CVE-2026-28326)
LIVE
OBS-2026-000061 (CVE-2026-31377)
LIVE
OBS-2026-000062 (CVE-2026-31377)
LIVE
OBS-2026-000063 (CVE-2026-32626)
RETRO
OBS-2026-000064 (CVE-2026-32626)
LIVE
OBS-2026-000065 (CVE-2026-37008)
RETRO
OBS-2026-000066 (CVE-2026-37008)
RETRO
OBS-2026-000067 (CVE-2026-40933)
RETRO
OBS-2026-000068 (CVE-2026-40933)
RETRO
OBS-2026-000069 (CVE-2026-41254)
RETRO
OBS-2026-000070 (CVE-2026-41254)
RETRO
OBS-2026-000071 (CVE-2026-41264)
RETRO
OBS-2026-000072 (CVE-2026-41264)
RETRO
OBS-2026-000073 (CVE-2026-41843)
RETRO
OBS-2026-000074 (CVE-2026-41843)
RETRO
OBS-2026-000075 (CVE-2026-41849)
RETRO
OBS-2026-000076 (CVE-2026-41849)
RETRO
OBS-2026-000077 (CVE-2026-42249)
RETRO
OBS-2026-000078 (CVE-2026-42249)
RETRO
OBS-2026-000079 (CVE-2026-43114)
RETRO
OBS-2026-000080 (CVE-2026-43114)
LIVE
OBS-2026-000081 (CVE-2026-43133)
RETRO
OBS-2026-000082 (CVE-2026-43133)
LIVE
OBS-2026-000083 (CVE-2026-4372)
RETRO
OBS-2026-000084 (CVE-2026-4372)
RETRO
OBS-2026-000085 (CVE-2026-46580)
RETRO
OBS-2026-000086 (CVE-2026-46580)
RETRO
OBS-2026-000087 (CVE-2026-46850)
RETRO
OBS-2026-000088 (CVE-2026-46850)
RETRO
OBS-2026-000089 (CVE-2026-46860)
RETRO
OBS-2026-000090 (CVE-2026-46860)
RETRO
OBS-2026-000091 (CVE-2026-46861)
RETRO
OBS-2026-000092 (CVE-2026-46861)
RETRO
OBS-2026-000093 (CVE-2026-46862)
RETRO
OBS-2026-000094 (CVE-2026-46862)
RETRO
OBS-2026-000095 (CVE-2026-46870)
RETRO
OBS-2026-000096 (CVE-2026-46870)
RETRO
OBS-2026-000097 (CVE-2026-47057)
RETRO
OBS-2026-000098 (CVE-2026-47057)
RETRO
OBS-2026-000099 (CVE-2026-47058)
RETRO
OBS-2026-000100 (CVE-2026-47058)
RETRO
OBS-2026-000101 (CVE-2026-47063)
RETRO
OBS-2026-000102 (CVE-2026-47063)
RETRO
OBS-2026-000103 (CVE-2026-48746)
RETRO
OBS-2026-000104 (CVE-2026-48746)
RETRO
OBS-2026-000105 (CVE-2026-5027)
RETRO
OBS-2026-000106 (CVE-2026-5027)
RETRO
OBS-2026-000107 (CVE-2026-52924)
RETRO
OBS-2026-000108 (CVE-2026-52924)
LIVE
OBS-2026-000109 (CVE-2026-52933)
RETRO
OBS-2026-000110 (CVE-2026-52933)
LIVE
OBS-2026-000111 (CVE-2026-53266)
RETRO
OBS-2026-000112 (CVE-2026-53266)
LIVE
OBS-2026-000113 (CVE-2026-54236)
RETRO
OBS-2026-000114 (CVE-2026-54236)
RETRO
OBS-2026-000115 (CVE-2026-57967)
RETRO
OBS-2026-000116 (CVE-2026-57967)
RETRO
OBS-2026-000117 (CVE-2026-59822)
RETRO
OBS-2026-000118 (CVE-2026-59822)
RETRO
OBS-2026-000119 (CVE-2026-60163)
RETRO
OBS-2026-000120 (CVE-2026-60163)
RETRO
OBS-2026-000121 (CVE-2026-60316)
RETRO
OBS-2026-000122 (CVE-2026-60316)
RETRO
OBS-2026-000123 (CVE-2026-60592)
RETRO
OBS-2026-000124 (CVE-2026-60592)
RETRO
OBS-2026-000125 (CVE-2026-60623)
RETRO
OBS-2026-000126 (CVE-2026-60623)
RETRO
OBS-2026-000127 (CVE-2026-61094)
RETRO
OBS-2026-000128 (CVE-2026-61094)
RETRO
OBS-2026-000129 (CVE-2026-61308)
RETRO
OBS-2026-000130 (CVE-2026-61308)
RETRO
OBS-2026-000131 (CVE-2026-62574)
RETRO
OBS-2026-000132 (CVE-2026-62574)
RETRO
OBS-2026-000133 (CVE-2026-64268)
RETRO
OBS-2026-000134 (CVE-2026-64268)
LIVE
OBS-2026-000135 (CVE-2026-65182)
RETRO
OBS-2026-000136 (CVE-2026-65182)
RETRO
OBS-2026-000137 (CVE-2026-65381)
RETRO
OBS-2026-000138 (CVE-2026-65381)
LIVE
OBS-2026-000139 (CVE-2026-65927)
RETRO
OBS-2026-000140 (CVE-2026-65927)
RETRO
OBS-2026-000141 (CVE-2026-67277)
RETRO
OBS-2026-000142 (CVE-2026-67277)
RETRO
OBS-2026-000143 (CVE-2026-67593)
RETRO
OBS-2026-000144 (CVE-2026-67593)
LIVE
OBS-2026-000145 (CVE-2026-68200)
RETRO
OBS-2026-000146 (CVE-2026-68200)
LIVE
OBS-2026-000147 (CVE-2026-70477)
RETRO
OBS-2026-000148 (CVE-2026-70477)
LIVE
OBS-2026-000149 (CVE-2026-7273)
LIVE
OBS-2026-000150 (CVE-2026-7273)
LIVE
OBS-2026-000151 (CVE-2026-73498)
LIVE
OBS-2026-000152 (CVE-2026-75650)
RETRO
OBS-2026-000153 (CVE-2026-75650)
RETRO
OBS-2026-000154 (CVE-2026-76461)
RETRO
OBS-2026-000155 (CVE-2026-76674)
RETRO
OBS-2026-000156 (CVE-2026-76674)
LIVE
OBS-2026-000157 (CVE-2026-77248)
LIVE
OBS-2026-000158 (CVE-2026-77254)
LIVE
OBS-2026-000159 (CVE-2026-77257)
LIVE
OBS-2026-000160 (CVE-2026-77258)
LIVE
OBS-2026-000161 (CVE-2026-77266)
LIVE
OBS-2026-000162 (CVE-2026-77267)
LIVE
OBS-2026-000163 (CVE-2026-77268)
LIVE
OBS-2026-000164 (CVE-2026-77269)
LIVE
OBS-2026-000165 (CVE-2026-77270)
LIVE
OBS-2026-000166 (CVE-2026-77272)
LIVE
OBS-2026-000167 (CVE-2026-77521)
LIVE
OBS-2026-000168 (CVE-2026-78234)
RETRO
OBS-2026-000169 (CVE-2026-78234)
LIVE
OBS-2026-000170 (CVE-2026-80351)
RETRO
OBS-2026-000171 (CVE-2026-80352)
RETRO
OBS-2026-000172 (CVE-2026-80354)
RETRO
OBS-2026-000173 (CVE-2026-80354)
LIVE
OBS-2026-000174 (CVE-2026-82331)
LIVE
OBS-2026-000175 (CVE-2026-82331)
LIVE
OBS-2026-000176 (CVE-2026-83021)
RETRO
OBS-2026-000177 (CVE-2026-83021)
LIVE
OBS-2026-000178 (CVE-2026-84285)
LIVE
OBS-2026-000179 (CVE-2026-84285)
LIVE
OBS-2026-000180 (CVE-2026-84779)
RETRO
OBS-2026-000181 (CVE-2026-84779)
LIVE
OBS-2026-000182 (CVE-2026-84939)
RETRO
OBS-2026-000183 (CVE-2026-84939)
RETRO
OBS-2026-000184 (CVE-2026-85165)
RETRO
OBS-2026-000185 (CVE-2026-85165)
LIVE
OBS-2026-000186 (CVE-2026-85166)
RETRO
OBS-2026-000187 (CVE-2026-85166)
LIVE
OBS-2026-000188 (CVE-2026-85168)
RETRO
OBS-2026-000189 (CVE-2026-85168)
LIVE
OBS-2026-000190 (CVE-2026-85654)
RETRO
OBS-2026-000191 (CVE-2026-85654)
LIVE
OBS-2026-000192 (CVE-2026-85788)
RETRO
OBS-2026-000193 (CVE-2026-85788)
LIVE
OBS-2026-000194 (CVE-2026-86060)
RETRO
OBS-2026-000195 (CVE-2026-86060)
RETRO
OBS-2026-000196 (CVE-2026-86218)
RETRO
OBS-2026-000197 (CVE-2026-86296)
RETRO
OBS-2026-000198 (CVE-2026-86296)
LIVE
OBS-2026-000199 (CVE-2026-86297)
RETRO
OBS-2026-000200 (CVE-2026-86297)
LIVE
OBS-2026-000201 (CVE-2026-86510)
RETRO
OBS-2026-000202 (CVE-2026-86510)
LIVE
OBS-2026-000203 (CVE-2026-86711)
RETRO
OBS-2026-000204 (CVE-2026-86711)
LIVE
OBS-2026-000205 (CVE-2026-87491)
RETRO
OBS-2026-000206 (CVE-2026-87911)
RETRO
OBS-2026-000207 (CVE-2026-87911)
LIVE
OBS-2026-000208 (CVE-2026-87999)
RETRO
OBS-2026-000209 (CVE-2026-87999)
LIVE
OBS-2026-000210 (CVE-2026-90562)
RETRO
OBS-2026-000211 (CVE-2026-90562)
RETRO
OBS-2026-000212 (CVE-2026-90680)
RETRO
OBS-2026-000213 (CVE-2026-90680)
LIVE
OBS-2026-000214 (CVE-2026-90692)
RETRO
OBS-2026-000215 (CVE-2026-90692)
LIVE
OBS-2026-000216 (CVE-2026-90693)
RETRO
OBS-2026-000217 (CVE-2026-90693)
LIVE
OBS-2026-000218 (CVE-2026-90699)
RETRO
OBS-2026-000219 (CVE-2026-90699)
LIVE
OBS-2026-000220 (CVE-2026-90702)
RETRO
OBS-2026-000221 (CVE-2026-90702)
LIVE
OBS-2026-000222 (CVE-2026-90711)
RETRO
OBS-2026-000223 (CVE-2026-90711)
RETRO
OBS-2026-000224 (CVE-2026-90770)
RETRO
OBS-2026-000225 (CVE-2026-90770)
LIVE
OBS-2026-000226 (CVE-2026-90777)
RETRO
OBS-2026-000227 (CVE-2026-90894)
RETRO
OBS-2026-000228 (CVE-2026-90894)
LIVE
OBS-2026-000229 (CVE-2026-91749)
RETRO
OBS-2026-000230 (CVE-2026-91749)
LIVE
OBS-2026-000231 (CVE-2026-91843)
RETRO
OBS-2026-000232 (CVE-2026-91843)
LIVE
OBS-2026-000233 (CVE-2026-9186)
RETRO
OBS-2026-000234 (CVE-2026-9186)
LIVE
OBS-2026-000235 (CVE-2026-92574)
LIVE
OBS-2026-000236 (CVE-2026-92574)
LIVE
OBS-2026-000237 (CVE-2026-93372)
RETRO
OBS-2026-000238 (CVE-2026-93372)
LIVE
OBS-2026-000239 (CVE-2026-93616)
LIVE
OBS-2026-000240 (CVE-2026-93952)
LIVE
OBS-2026-000241 (CVE-2026-94089)
RETRO
OBS-2026-000242 (CVE-2026-94089)
LIVE
OBS-2026-000243 (CVE-2026-94127)
LIVE
OBS-2026-000244 (CVE-2026-95675)
LIVE
OBS-2026-000245 (CVE-2026-95675)
LIVE
OBS-2026-000246 (CVE-2026-32626)
LIVE
OBS-2026-000247 (CVE-2026-76460)
RETRO
OBS-2026-000248 (CVE-2025-39964)
LIVE
OBS-2026-000249 (CVE-2025-39964)
LIVE
OBS-2026-000251 (CVE-2025-39682)
LIVE
OBS-2026-000253 (CVE-2026-22778)
RETRO
OBS-2026-000255 (CVE-2026-22778)
LIVE
OBS-2026-000256 (CVE-2026-32626)
RETRO
OBS-2026-000258 (CVE-2026-32626)
LIVE
OBS-2026-000259 (CVE-2026-76460)
RETRO
OBS-2026-000260 (CVE-2026-76460)
LIVE
π― Agentic Attack Patterns
AAP-001: Direct System Override
AAP-002: Indirect Context Injection
AAP-004: Semantic Tool Poisoning
AAP-005: Memory & RAG Corruption
AAP-006: Inter-Agent Spoofing
AAP-007: Cascading RCE
π― Attack Patterns Overview
Taxonomy
AAP-003: Tool Parameter Tampering
P0 Pattern
π‘οΈ CVE Watch
Latest Overview
2026 Archive
2026 Vulnerability Reports
Special Report: In-Depth Analysis of Microsoft's September 2026 Patch Tuesday
CVE-2026-95675: D-Link DAP-1360 Web Management OS Command Injection Root RCE
CVE-2026-94127: F5 BIG-IP APM TMM Heap-Based Buffer Overflow Remote Code Execution
CVE-2026-94089: D-Link DIR-868L webfa_authentication.cgi Stack Buffer Overflow RCE
CVE-2026-93952: Arista VeloCloud Orchestrator Authentication Bypass and Remote Code Execution
CVE-2026-93616: Check Point Multi-Domain Security Management Web Service Traversal and RCE
CVE-2026-93372: Google Chrome Android WebGL Heap Buffer Overflow GPU Sandbox Escape
CVE-2026-92574: CRI-O Container Checkpoint-Restore Destination Security Context Bypass
CVE-2026-91843: Check Point Security Management Server Stack Buffer Overflow RCE
CVE-2026-91749: Google Chrome Web Workers Subsystem Use-After-Free Remote Code Execution
CVE-2026-90894: Parallels Desktop ParaShells Virtual Machine Host Escape & LPE
CVE-2026-90777: Arbitrary Code Execution via Insecure torch.load Checkpoint Deserialization in ESPnet
CVE-2026-90770: Spug Deployment Platform ping_check OS Command Injection RCE
CVE-2026-90711: Client IP Address Spoofing and Trust Boundary Bypass via IPv4-Mapped IPv6 CIDR Parsing Flaw in proxy-addr
CVE-2026-90702: D-Link DWR-M921 formDiskFormat OS Command Injection
CVE-2026-90699: D-Link DWR-M920 formPinManageSetup OS Command Injection
CVE-2026-90693: D-Link DIR-878 SetWan3Settings Stack-Based Buffer Overflow RCE
CVE-2026-90692: D-Link DIR-878 SetDynamicDNSIPv6Settings Stack Overflow RCE
CVE-2026-90680: D-Link DIR-823G HNAP1 SetStaticRouteSettings Buffer Overflow
CVE-2026-90562: Authentication Bypass and Administrative Takeover via Low Entropy Password Recovery in LangBot
CVE-2026-87999: Open WebUI Azure WireServer Metadata Filter Bypass SSRF
CVE-2026-87988: Mistral Vibe Arbitrary Read/Write via Discrepancy Between Auto-Approved Commands and Path Control List
CVE-2026-87987: Mistral Vibe Remote Code Execution via Environment Variable Assignment Stripping
CVE-2026-87986: Mistral Vibe Command Injection via Parser Syntax Error Node Bypass
CVE-2026-87985: Mistral Vibe Arbitrary Remote Code Execution via ANSI-C Quoting in find -exec
CVE-2026-87984: Mistral Vibe Arbitrary File Write via Shell Redirection Target Omission
CVE-2026-87983: Mistral Vibe Arbitrary File Read via Quoted Absolute Paths in Auto-Approved Commands
CVE-2026-87911: awslabs postgres-mcp-server SQL Parser Desync to Command Injection
CVE-2026-87886: Local Privilege Escalation via Insecure Permissions in Acronis Backup Plugin for cPanel & Plesk
CVE-2026-87491: Google Chromium V8 Out-of-Bounds Write Zero-Day to Sandbox RCE
CVE-2026-87230: Unauthenticated Remote Financial Ledger Compromise in Oracle Hyperion Financial Management
CVE-2026-86711: Electerm Desktop runGlobalAsync Electron IPC Handler Arbitrary Command Execution
CVE-2026-86510: D-Link DIR-822A L2TP Parser Out-of-Bounds Write RCE
CVE-2026-86297: D-Link DIR-605 L2TP Parser Off-by-One Buffer Overflow
CVE-2026-86296: D-Link DIR-822A udhcpcd Stack-Based Buffer Overflow RCE
CVE-2026-86218: Pre-Authentication Remote Code Execution via Static Code Injection in N-able N-central
CVE-2026-86060: Administrative Privilege Escalation via SSH Argument Delimiter Injection in MikroTik RouterOS ("MikroTrick")
CVE-2026-85880: Windows ALPC Heap Buffer Overflow Privilege Escalation (Actively Exploited Zero-Day)
CVE-2026-85788: awslabs mysql-mcp-server Comment-Bypass Mutation Vulnerability
CVE-2026-85706: Unauthenticated Path Traversal to Arbitrary File Read in GitLab CE/EE Repository Commits API
CVE-2026-85654: awslabs dynamodb-mcp-server CDK Generator Template Injection RCE
CVE-2026-85168: Git Node Merge-Driver & Content-Filter Command Injection in n8n
CVE-2026-85166: n8n Workflow Tool Sub-Workflow Credential Authorization Bypass
CVE-2026-85165: n8n Expression Sandbox Escape via Prototype Resolution
CVE-2026-85103: Check Point Quantum Gateway & Management Server VPN ASN.1 Heap Buffer Overflow RCE
CVE-2026-85102: Check Point Quantum Gateway VPN Certificate Trust Validation Remote Code Execution
CVE-2026-85046: Google Chromium V8 Maglev/TurboFan Type Confusion Zero-Day
CVE-2026-84939: Path Traversal to Remote Template Injection and Code Execution via Malformed Locale in Apache FreeMarker
CVE-2026-84869: Unrestricted File Transfer and Remote Execution in ConnectWise ScreenConnect Client via Active Session Authorization Bypass
CVE-2026-84779: WordPress Agentimus MCP Endpoint Broken Access Control
CVE-2026-84285: Tuleap Enterprise ALM Workspace Export OS Command Injection
CVE-2026-83549: SonicWall SMA 1000 Series AMC OS Command Injection & Chain Exploitation
CVE-2026-83548: SonicWall SMA1000 Remote Unauthenticated SSRF & Edge Gateway Takeover
CVE-2026-83527: Unauthenticated Administrative Authentication Bypass in Ivanti Sentry via Alternate Routing Path
CVE-2026-83099: Unauthenticated Remote Code Execution in Oracle Forms Services
CVE-2026-83059: Unauthenticated Remote Compromise in Oracle Internet Directory (OID) LDAP Server
CVE-2026-83021: Unauthenticated Remote Code Execution in Oracle WebLogic Server Web Container
CVE-2026-83020: Unauthenticated Remote Code Execution in Oracle Platform Security for Java (OPSS)
CVE-2026-82474: Sudo Intercept Policy Bypass via execveat
CVE-2026-82331: Apache BuildStream Tar Plugin Link Resolution and Host File Overwrite
CVE-2026-82329: JFrog Artifactory Phantom Join-Key Authentication Bypass
CVE-2026-82078: PaperCut NG/MF Database Dynamic Class Loading RCE
CVE-2026-81963: Windows Update Stack Elevation of Privilege (Actively Exploited Zero-Day)
CVE-2026-81578: PaperCut NG/MF Web Management Authentication Bypass
CVE-2026-80354: Apache Camel K Operator Authorization Bypass via Maven Profiles ValueSources
CVE-2026-80352: Kubernetes Operator Privilege Escalation via Master Trait YAML Injection in Apache Camel K
CVE-2026-80351: Remote Code Execution via Dynamic Maven Configuration Eval Injection in Apache Camel K
CVE-2026-80083: Windows Hyper-V Virtual Switch Guest-to-Host Remote Code Execution
CVE-2026-78510: Microsoft Outlook Reading Pane Zero-Click Remote Code Execution
CVE-2026-78509: Windows Shell Preview Pane Remote Code Execution
CVE-2026-78445: Windows Services for NFS Memory Corruption Remote Code Execution
CVE-2026-78234: Hawtio Operator OpenShift Service CA Signing Key Theft and Cluster Takeover
CVE-2026-77521: MaxKB Enterprise AI Platform SandboxShellBackend Command Injection and Container Breakout
CVE-2026-77493: Windows Graphics Component Preview Pane Zero-Click Remote Code Execution
CVE-2026-76674: HPE Aruba EdgeConnect SD-WAN Buffer Overflow System Takeover
CVE-2026-76461: Zero-Click Remote Code Execution via AsyncOS Email Parsing SQL Injection in Cisco Secure Email Gateway
CVE-2026-76460: Unauthenticated REST API Authentication Bypass in Cisco Identity Services Engine (ISE)
CVE-2026-75874: Mozilla Firefox Critical Sandbox Escape via Remote Settings Client
CVE-2026-75650: Unauthenticated Remote Code Execution via 'StyleSmuggler' Template Injection in Adobe Commerce and Magento
CVE-2026-74976: Mozilla Firefox SpiderMonkey JIT Miscompilation & Type Confusion
CVE-2026-74963: Mozilla Firefox Same-Origin Policy Bypass in Cookie Engine
CVE-2026-74957: Mozilla Firefox Safe Browsing Mitigation Bypass
CVE-2026-74521: Linux Kernel ksmbd Binary ClientGUID strncmp Comparison Flaw
CVE-2026-74512: Linux Kernel Audit Subsystem Rule Deletion Premature Free Use-After-Free
CVE-2026-73431: CIRCL Vulnerability-Lookup Stateless Token Replay Account Takeover
CVE-2026-73009: Windows Secure Socket Tunneling Protocol (SSTP) VPN Remote Code Execution
CVE-2026-72982: Windows Netlogon Unauthenticated Remote Code Execution (Domain Controller Takeover)
CVE-2026-72979: Windows DHCP Server Use-After-Free Remote Code Execution
CVE-2026-72961: Windows Hyper-V Guest-to-Host Elevation of Privilege
CVE-2026-71133: Unauthenticated Identity Federation Compromise in Oracle Access Manager Authentication Engine
CVE-2026-70477: Flowise AI CSV Agent Prompt Injection to Unsandboxed Pyodide Host RCE
CVE-2026-69851: Microsoft Entra ID Server-Side Request Forgery Privilege Escalation
CVE-2026-69845: Windows DHCP Server Heap Buffer Overflow Remote Code Execution
CVE-2026-69730: Windows DNS Server Unauthenticated Remote Code Execution
CVE-2026-69676: Windows Kerberos Authentication Bypass & Remote Code Execution
CVE-2026-69649: Windows Raw Image Extension Thumbnail Preview Remote Code Execution
CVE-2026-69603: Windows Hyper-V Guest-to-Host Escape Remote Code Execution
CVE-2026-69595: Windows Services for NFS ONCRPC XDR Driver Remote Code Execution
CVE-2026-69579: Windows Message Queuing (MSMQ) Unauthenticated Remote Code Execution
CVE-2026-69518: Windows Remote Desktop Clipboard Virtual Channel Remote Code Execution
CVE-2026-68200: Linux Kernel ALSA Timer User Trigger Concurrent ioctl Use-After-Free
CVE-2026-67593: Apache ActiveMQ Artemis Pre-Authentication Queue Deletion via Openwire
CVE-2026-67277: Authentication Bypass and Integer Underflow in MikroTik RouterOS Bandwidth-Test Service (Kernel Memory Leak & DoS)
CVE-2026-65927: Access Control Bypass via RewriteValve Off-By-One Error in Apache Tomcat
CVE-2026-65777: Active Directory Cross-Realm Security Feature Bypass
CVE-2026-65400: Unauthenticated Remote Desktop Takeover in Apple macOS Screen Sharing
CVE-2026-65381: Apple macOS Entitlement Verification Sandbox Escape & Local Privilege Escalation
CVE-2026-65182: Security Constraint Order Bypass and Authorization Failure in Apache Tomcat
CVE-2026-64849: Critical Server-Side Request Forgery (SSRF) in MLflow Webhook Notifications
CVE-2026-64268: Linux Kernel Soft-iWARP (siw) RDMA Read Response Out-of-Bounds Write
CVE-2026-63077: Authentication Bypass to Remote Code Execution in JetBrains TeamCity via Agent Polling Protocol
CVE-2026-63030: WordPress Core REST API Batch Route Confusion to Remote Code Execution
CVE-2026-62818: Windows Active Directory Certificate Services (AD CS) Remote Code Execution
CVE-2026-62785: Windows LDAP Service Remote Code Execution on Domain Controllers
CVE-2026-62752: Windows Kerberos Security Authority Elevation of Privilege
CVE-2026-62574: Local Privilege Escalation via Install Component in Oracle Java SE and GraalVM
CVE-2026-61308: Information Disclosure Across Boundaries via HTTP Networking in Java SE
CVE-2026-61094: System Compromise via Binary Log Replication Subsystem in MySQL Server
CVE-2026-60623: Data Tampering and Information Disclosure in MySQL Connector/J
CVE-2026-60592: Unauthenticated Network Denial of Service and Data Tampering in NDB Operator
CVE-2026-60316: Server and Cluster Takeover via MySQL X Plugin Protocol
CVE-2026-60163: Local Privilege Escalation and Takeover in MySQL Group Replication
CVE-2026-60137: WordPress Core Facilitated SQL Injection via WP_Query author__not_in
CVE-2026-59840: Buffer Over-read in Fortinet FortiOS and FortiProxy
CVE-2026-59839: FortiOS CLI Path Traversal Arbitrary File Deletion & Code Execution
CVE-2026-59837: Stack-Based Buffer Overflow in FortiOS Log Report Generation
CVE-2026-59822: LiteLLM MCP Streamable HTTP Authentication Bypass
CVE-2026-59310: Remote Code Execution in VMware vCenter Server via Syslog Service Directory Traversal
CVE-2026-58704: Zero-Click Adjacent Privilege Escalation in Google Pixel Cellular Modem
CVE-2026-58644: Remote Code Execution in Microsoft SharePoint Server via Workflow Event Receiver Deserialization
CVE-2026-58599: Microsoft HEVC Video Extensions Heap Buffer Overflow Remote Code Execution
CVE-2026-58480: Blocksy Companion Pro Unauthenticated Arbitrary File Upload Remote Code Execution
CVE-2026-58070: Cleartext Guest OS Credentials Disclosure in Veeam Backup Support Logs
CVE-2026-57967: Unauthenticated Remote Session Hijacking via CORE Protocol Reattachment in Apache ActiveMQ Artemis
CVE-2026-55653: OpenSSH DH-GEX Client Path Double-Free in FIPS Known-Group Validation
CVE-2026-55040: Authentication Bypass and Privilege Escalation in Microsoft SharePoint Server via JWT Signature Spoofing
CVE-2026-54291: pgjdbc Silent SCRAM Channel-Binding Authentication Downgrade
CVE-2026-54236: vLLM Multimodal Image Processing Unhandled Exception Memory Pointer Disclosure
CVE-2026-53266: Linux Kernel Netfilter ebtables SNAT ARP Out-of-Bounds Write & Privilege Escalation
CVE-2026-52933: Linux Kernel io_uring/poll Signed Comparison Ownership Privilege Escalation
CVE-2026-52924: Linux Kernel SCTP Stale COOKIE-ECHO Outqueue Purge Use-After-Free
CVE-2026-50522: Remote Code Execution in Microsoft SharePoint Server via .NET Deserialization
CVE-2026-50500: Windows Netlogon Secure Channel Use-After-Free Elevation of Privilege
CVE-2026-50481: Azure Active Directory Immutable Data Manipulation Privilege Escalation
CVE-2026-50391: Windows Group Policy Client Elevation of Privilege
CVE-2026-50346: Windows Netlogon RPC Runtime Elevation of Privilege
CVE-2026-49869: Authentication Bypass to Remote Code Execution in Kestra OSS via Path Suffix Whitelisting
CVE-2026-49179: Windows Active Directory Domain Services Remote Code Execution
CVE-2026-48746: vLLM OpenAI API Authentication Middleware Bypass via ASGI Request Handling Inconsistency
CVE-2026-48710: Starlette & FastAPI BadHost Path Smuggling & Auth Bypass
CVE-2026-47876: VMware ESXi VMXNET3 Out-of-Bounds Write Virtual Machine Escape
CVE-2026-47063: Existential Forgery and JAR Verification Bypass in Oracle Java SE Libraries
CVE-2026-47058: Out-of-Bounds Memory Corruption in Java Scripting DataView Implementation
CVE-2026-47057: Remote Denial of Service in Oracle Java SE Scripting Engine
CVE-2026-46870: Access Control Bypass and Workstation Compromise in MySQL Shell for VS Code
CVE-2026-46862: Unauthenticated Remote Denial of Service via TLS in MySQL Router
CVE-2026-46861: Privilege Escalation and Cluster Takeover in MySQL NDB Operator
CVE-2026-46860: Unauthenticated Remote Administrative Takeover in MySQL Router
CVE-2026-46850: Remote Code Execution via Code Injection in MySQL Shell for VS Code
CVE-2026-46580: Eclipse Theia Prompt Template Injection & Untrusted Workspace RCE
CVE-2026-45321: Large-Scale Supply Chain Compromise Across 42 Packages in the TanStack NPM Ecosystem
CVE-2026-44963: Remote Code Execution in Veeam Backup & Replication via .NET Remoting ObjRef Deserialization
CVE-2026-43386: Linux Kernel Realtek rtl8723bs Wi-Fi WMM IE Parsing Out-of-Bounds Read
CVE-2026-43133: Linux Kernel KVM nSVM VMLOAD/VMSAVE Emulation Hypervisor Escape
CVE-2026-43114: Linux Kernel Netfilter nft_set_pipapo AVX2 Lookup Expiry Bypass
CVE-2026-42271: Unauthenticated Remote OS Command Injection in LiteLLM Proxy Test Endpoints
CVE-2026-42249: Ollama Windows Auto-Updater HTTP Header Path Traversal RCE
CVE-2026-42208: LiteLLM Proxy API Key SQL Injection
CVE-2026-42018: Anonymous User Token Generation Exposure in JFrog Artifactory
CVE-2026-42016: Privilege Escalation in JFrog Artifactory via Token Scope Authorization Validation Bypass
CVE-2026-41849: Integer Overflow Denial of Service via SpEL String Multiplication in Spring Framework
CVE-2026-41843: Path Traversal in Spring Framework Versioned Static Resource Resolution
CVE-2026-41709: VMware ESXi Insufficient Logging & Forensic Evasion
CVE-2026-41703: VMware ESXi Out-of-Bounds Read in VM Lifecycle Handling
CVE-2026-41264: Flowise CSV Agent Prompt Injection to Remote Code Execution
CVE-2026-41254: Integer Overflow in Little CMS (lcms2) Affecting Java 2D Color Management
CVE-2026-41035: rsync receiver use-after-free
CVE-2026-40933: Flowise MCP Adapter Stdio Command Injection RCE
CVE-2026-40227: systemd IPC API Array Null Element Assertion Crash
CVE-2026-40192: Pillow FITS Image GZIP Decompression Bomb Denial of Service
CVE-2026-40170: ngtcp2 stack buffer overflow
CVE-2026-40087: LangChain Incomplete f-string Validation & Attribute Exposure
CVE-2026-39884: Argument Injection in mcp-server-kubernetes
CVE-2026-39842: Expression Injection in OpenRemote IoT Platform
CVE-2026-39808: Root OS Command Injection in Fortinet FortiSandbox Administrative API
CVE-2026-37338: SQL Injection in SourceCodester Simple Music Cloud Community System
CVE-2026-37008: CrewAI CodeInterpreterTool Python Sandbox Escape & Host Takeover
CVE-2026-35385: OpenSSH scp Legacy Protocol Setuid File Installation
CVE-2026-35188: OpenSSL Double-Free in TLS OCSP Stapling Verification
CVE-2026-34621: Acrobat Reader Prototype Pollution
CVE-2026-34197: Apache ActiveMQ Classic Remote Code Execution
CVE-2026-34183: OpenSSL QUIC PATH_CHALLENGE Unbounded Memory Growth DoS
CVE-2026-33873: Langflow Agentic Assistant Dynamic Execution Sink RCE
CVE-2026-33825: Microsoft Defender 'BlueHammer' LPE
CVE-2026-33634: Supply Chain Compromise in Aqua Security Trivy GitHub Actions Workflow
CVE-2026-33626: LMDeploy Vision-Language SSRF & Cloud Metadata Exfiltration
CVE-2026-33017: Unauthenticated RCE in Langflow via build_public_tmp Endpoint
CVE-2026-32997: Arbitrary File Write in Linux-based Veeam Backup & Replication
CVE-2026-32626: AnythingLLM Desktop Streaming Phase XSS to Electron Host RCE
CVE-2026-32201: Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-31845: Reflected XSS in Rukovoditel CRM
CVE-2026-31718: Linux Kernel ksmbd Durable File Handle Scavenger Use-After-Free
CVE-2026-31633: Linux Kernel AF_RXRPC rxgk Token Handling Integer Overflow
CVE-2026-31431 (Copy-Fail)
CVE-2026-31430: Linux Kernel X.509 Certificate Parser Empty Extension Out-of-Bounds Read
CVE-2026-31377: Apache Doris Frontend Meta Service Unauthenticated Access and Metadata Exfiltration
CVE-2026-31368: Database Initialization Failure
CVE-2026-31223: Snorkel AI BaseLabeler pickle.load Insecure Deserialization RCE
CVE-2026-30624: Agent Zero External MCP Servers Command Injection
CVE-2026-30623: LiteLLM Authenticated MCP RCE
CVE-2026-30617: Remote Code Execution in LangChain-ChatChat
CVE-2026-30615: Windsurf MCP Prompt Injection RCE
CVE-2026-28326: SolarWinds Access Rights Manager Hard-coded Key Remote Code Execution
CVE-2026-27966: Langflow CSV Agent allow_dangerous_code Hardcoded RCE
CVE-2026-25750: URL Parameter Injection Vulnerability in LangSmith Studio
CVE-2026-25724: Anthropic Claude Code Agentic Permission Bypass via Symlink Traversal
CVE-2026-25089: Unauthenticated Remote OS Command Injection in Fortinet FortiSandbox Web Interface
CVE-2026-24858: Critical FortiCloud SSO Authentication Bypass (Active In-The-Wild Exploitation)
CVE-2026-24307: Microsoft 365 Copilot Input Type Confusion & Information Disclosure
CVE-2026-23772: Privilege Escalation in Dell Storage Manager
CVE-2026-23432: Linux Kernel Hyper-V mshv Guest Memory Mapping Use-After-Free
CVE-2026-23288: Linux Kernel AMD XDNA NPU Command Ring Out-of-Bounds Write
CVE-2026-23269: Linux Kernel AppArmor DFA Policy Unpack Out-of-Bounds State Validation
CVE-2026-23246: Linux Kernel mac80211 Wi-Fi 7 MLO Reconfiguration link_id Array Index Overflow
CVE-2026-22807: vLLM Dynamic Module Auto-Map Pre-Auth Remote Code Execution
CVE-2026-22778: vLLM Multimodal Video URL Heap Overflow and ASLR Bypass RCE
CVE-2026-22708: Cursor IDE Terminal Tool Allowlist Bypass via Shell Built-ins to RCE
CVE-2026-22153: FortiOS LDAP Authentication Bypass in Agentless VPN & FSSO
CVE-2026-21962: Critical Authentication & Access Control Bypass in Oracle WebLogic Server Proxy Plug-in
CVE-2026-21708: PostgreSQL SQL Injection to Remote Code Execution via Backup Viewer Role in Veeam Backup & Replication
CVE-2026-21672: Local Privilege Escalation on Windows Veeam Backup & Replication Servers
CVE-2026-21671: High Availability Cluster Remote Code Execution in Veeam Backup & Replication
CVE-2026-21670: Low-Privileged Saved SSH Credential Extraction in Veeam Backup & Replication
CVE-2026-21669: Authenticated Domain User Remote Code Execution in Veeam Backup & Replication
CVE-2026-21643: Fortinet FortiClient EMS SQL Injection
CVE-2026-21510: Windows Shell Security Feature Bypass
CVE-2026-20324: Cisco Secure Firewall Management Center sftunnel OS Command Injection RCE
CVE-2026-20307: Cisco Identity Services Engine Insecure Java Deserialization RCE
CVE-2026-20205: Sensitive Information Disclosure in Splunk MCP Server
CVE-2026-20192: Cisco Identity Services Engine Unauthenticated Authorization Bypass
CVE-2026-20186 - Cisco ISE Command Injection
CVE-2026-20184: Cisco Webex SSO Impersonation Vulnerability
CVE-2026-20180: Cisco ISE Multiple Remote Code Execution Vulnerability
CVE-2026-20147: Cisco ISE Remote Code Execution Vulnerability
CVE-2026-20133: Cisco Catalyst SD-WAN Manager Sensitive Information Disclosure Vulnerability
CVE-2026-20128: Cisco Catalyst SD-WAN Manager DCA Credential Disclosure and Privilege Escalation Vulnerability
CVE-2026-20127: Cisco Catalyst SD-WAN Authentication Bypass
CVE-2026-20122: Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite
CVE-2026-20079: Cisco Secure FMC Authentication Bypass to Root RCE
CVE-2026-19490: Citrix NetScaler ADC & Gateway Authentication Bypass
CVE-2026-18851: Authenticated Privilege Escalation to Administrator in Ivanti Endpoint Manager Mobile via Missing Authorization
CVE-2026-18503: CPython csv.Sniffer Super-Linear ReDoS CPU Consumption
CVE-2026-18486: IBM ContextForge MCP Gateway jq Filter Credential Theft
CVE-2026-16356: Mozilla Firefox Use-After-Free in Accessibility APIs
CVE-2026-15719: Mozilla Firefox Site Isolation Bypass via DOM Navigation
CVE-2026-15718: Mozilla Firefox WebAssembly Invalid Pointer Dereference
CVE-2026-15308: CPython HTMLParser.feed() Unterminated Markup CPU Exhaustion DoS
CVE-2026-14894: Super Forms WordPress Plugin Unauthenticated Arbitrary File Upload to Remote Code Execution
CVE-2026-12745: Secondary Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization Flaw
CVE-2026-12744: Unauthenticated Remote Code Execution in Ivanti Neurons for ITSM via Insecure .NET Object Deserialization
CVE-2026-12651: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Data Deserialization
CVE-2026-12650: Authenticated Remote Code Execution with Scope Elevation in Ivanti Neurons for ITSM via Insecure Deserialization
CVE-2026-12648: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Deserialization of Untrusted Data
CVE-2026-12647: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Automation Engine
CVE-2026-12646: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Business Logic Actions
CVE-2026-12645: Authenticated Remote Code Execution in Ivanti Neurons for ITSM via Missing Authorization in Workflow Handlers
CVE-2026-12304: Mozilla Firefox Cross-Origin Cookie Leakage & SOP Bypass
CVE-2026-12293: Mozilla Firefox WebGPU Use-After-Free Code Execution
CVE-2026-12289: Mozilla Firefox WebRender Graphics Privilege Escalation
CVE-2026-12045: pgAdmin 4 AI Assistant Read-Only Transaction Bypass to RCE
CVE-2026-11972: CPython tarfile Streaming Mode EOF Denial of Service
CVE-2026-11945: PostgreSQL Anonymizer Rules Import Function SQL Injection
CVE-2026-11940: CPython tarfile Extraction Filter Directory Traversal Bypass
CVE-2026-11393: AWS Bedrock AgentCore Multi-Agent Collaboration Poisoning via Triple-Quote Injection RCE
CVE-2026-9586: Unauthenticated SQL Injection to Remote Code Execution in Sangoma Switchvox PBX
CVE-2026-9186: Langflow Localhost Restriction Bypass Arbitrary IDE mcp.json Overwrite
CVE-2026-9050: Slider Revolution Missing Authorization to Arbitrary Plugin Deactivation
CVE-2026-9048: Slider Revolution Sensitive Information Exposure via slider.get.full
CVE-2026-8932: curl Incomplete mTLS Configuration Matching in Connection Reuse
CVE-2026-8719: Privilege Escalation in AI Engine
CVE-2026-8643: pip console_scripts Out-of-Directory Arbitrary File Overwrite
CVE-2026-8452: Unauthenticated Heap Buffer Overflow to Root RCE in NetScaler ADC & Gateway via SAML Canonicalization
CVE-2026-8293: Really Simple Security Authentication Bypass via 2FA Challenge Skip
CVE-2026-8206: Kirki Customizer Framework Unauthenticated Privilege Escalation to Account Takeover
CVE-2026-7814: pgAdmin 4 Stored XSS via Database Object Names in Browser Tree
CVE-2026-7273: Zyxel GS1900 Smart Switches CGI Stack Buffer Overflow RCE
CVE-2026-7210: CPython Expat and ElementTree Insufficient Entropy Hash-Flooding DoS
CVE-2026-7141: vLLM KV Cache Handler RCE
CVE-2026-6638: PostgreSQL REFRESH PUBLICATION Table Name SQL Injection
CVE-2026-6615: TransformerOptimus SuperAGI Path Traversal
CVE-2026-6605: AgentScope SSRF Vulnerability
CVE-2026-6604: AgentScope Blind SSRF via Prompt Injection
CVE-2026-6603: Remote Code Execution in AgentScope Framework
CVE-2026-6602: Arbitrary File Upload in rickxy Hospital Management System
CVE-2026-6596: Arbitrary File Upload in Langflow
CVE-2026-6595: SQL Injection in School Management System
CVE-2026-6560: H3C Magic B0 Router Buffer Overflow
CVE-2026-6507: dnsmasq Out-of-Bounds Write
CVE-2026-6490: QueryMine SMS SQL Injection
CVE-2026-6476: PostgreSQL pg_createsubscriber Subscription Name SQL Injection
CVE-2026-6473: PostgreSQL Server Memory Allocation Integer Wraparound OOB Write
CVE-2026-6443: WordPress Essential Plugin Supply Chain Attack
CVE-2026-6276: curl Stale Custom Host Header Cookie Leak
CVE-2026-6138: Critical Remote OS Command Injection in Totolink A7100RU
CVE-2026-6105: Improper Authorization in perfree go-fastdfs-web
CVE-2026-6100: CPython Decompressor Use-After-Free under Memory Pressure
CVE-2026-5966: Arbitrary File Deletion in ThreatSonar Anti-Ransomware
CVE-2026-5809: Arbitrary File Deletion in wpForo Forum
CVE-2026-5364: Arbitrary File Upload in Drag and Drop File Upload for Contact Form 7
CVE-2026-5059: aws-mcp-server RCE
CVE-2026-5027: Langflow Multipart Form Files Path Traversal and Arbitrary File Overwrite RCE
CVE-2026-5002: Critical Prompt Injection in localGPT
CVE-2026-4519: CPython webbrowser.open() Leading Dash Argument Injection
CVE-2026-4372: Hugging Face Transformers Configuration Injection RCE via Attention Implementation
CVE-2026-3195: QEMU virtio-snd PCM Input Buffer Heap Overflow (Incomplete CVE-2024-7730 Fix)
CVE-2026-3055: NetScaler Memory Overread (SAML IdP)
CVE-2026-2360: PostgreSQL Anonymizer Operator search_path Superuser Privilege Escalation
CVE-2026-2007: PostgreSQL pg_trgm Heap Buffer Overflow Pattern Corruption
CVE-2026-2006: PostgreSQL Multibyte Character Length Validation Buffer Overrun RCE
CVE-2026-1340: Unauthenticated Remote Code Execution in Ivanti EPMM
CVE-2026-0915: glibc getnetbyaddr Stack Memory Leak to DNS Resolver
CVE-2026-0770: Unauthenticated Remote Code Execution in Langflow via Code Validation Sandbox Escape
CVE-2026-0300: Unauthenticated Stack Buffer Overflow to Root RCE in Palo Alto Networks PAN-OS User-ID Captive Portal
CVE-2026-0257: Critical Authentication Bypass in Palo Alto Networks GlobalProtect Portal
CVE-2026-27825: mcp-atlassian Confluence Download Attachment Arbitrary File Write RCE
CVE-2026-27826: mcp-atlassian Unvalidated Header SSRF to Cloud Instance Metadata
CVE-2026-73498: mcp-atlassian Confluence Upload Attachment Arbitrary File Exfiltration
CVE-2026-77248: mcp-atlassian Unauthenticated Arbitrary File Read and Attachment Exfiltration
CVE-2026-77254: mcp-atlassian Missing Authentication on HTTP Transport Endpoint
CVE-2026-77257: mcp-atlassian Jira Upload Attachment Path Traversal
CVE-2026-77258: mcp-atlassian Confluence Attachment Handler Missing Safe Path Validation
CVE-2026-77266: mcp-atlassian Absolute Path Traversal Bypass in Attachment Operations
CVE-2026-77267: mcp-atlassian Header-Based SSRF in Fetcher Constructor
CVE-2026-77268: mcp-atlassian World-Readable Permissions on OAuth Fallback Tokens
CVE-2026-77269: mcp-atlassian Incomplete Fix for Path Traversal in Attachment Uploads
CVE-2026-77270: mcp-atlassian Blind Path Trust in File Dispatcher
CVE-2026-77272: mcp-atlassian Reflected XSS in OAuth Callback Error Response
2025 Archive
2025 Vulnerability Reports
CVE-2025-66389: GitHub Copilot Workspace Traversal & File-Handler Exfiltration
CVE-2025-64504: Langfuse Cross-Organization Member Enumeration
CVE-2025-61882: Zero-Day RCE in Oracle E-Business Suite (BI Publisher / Concurrent Processing)
CVE-2025-60710 - Elevation of Privilege in Host Process for Windows Tasks
CVE-2025-59528: Flowise CustomMCP Node JavaScript Function Constructor Remote Code Execution
CVE-2025-59470: PostgreSQL Remote Code Execution via Operator Role in Veeam Backup & Replication
CVE-2025-59469: Arbitrary File Write as Root by Operators in Veeam Backup & Replication
CVE-2025-59468: PostgreSQL Remote Code Execution via Malicious Password Parameter in Veeam Backup & Replication
CVE-2025-59417: Lobe Chat lobeArtifact SVG dangerouslySetInnerHTML XSS to RCE
CVE-2025-58434: FlowiseAI Unauthenticated Full Account Takeover
CVE-2025-55182: 'React2Shell' β Pre-Auth Deserialization RCE in Meta React Server Components
CVE-2025-55125: Root Command Injection via Backup Configuration in Veeam Backup & Replication
CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted Context
CVE-2025-54794: Claude Code Working Directory Sandbox Escape via Path Prefix Matching
CVE-2025-53844: FortiOS Out-of-Bounds Write via Compromised Fabric Devices
CVE-2025-53773: GitHub Copilot RCE via Prompt Injection
CVE-2025-53770: Insecure Deserialization RCE in Microsoft SharePoint Server (ToolShell)
CVE-2025-52970: Access Control Bypass and Privilege Escalation in Fortinet FortiWeb
CVE-2025-52573: iOS Simulator MCP Server ui_tap Command Injection
CVE-2025-50105: Privilege Escalation and Workflow Tampering in Oracle E-Business Suite (Universal Work Queue)
CVE-2025-49704: Remote Code Injection in Microsoft SharePoint Server
CVE-2025-49150: Cursor AI Editor Automatic JSON Schema Download Data Exfiltration
CVE-2025-49113: Authenticated RCE via PHP Deserialization in Roundcube Webmail (upload.php)
CVE-2025-47277: vLLM Distributed KV-Cache PyNcclPipe Remote Code Execution
CVE-2025-42944: Unauthenticated Java Deserialization RCE in SAP NetWeaver AS Java (RMI-P4)
CVE-2025-39964: Linux Kernel Crypto AF_ALG Concurrent Write Race Condition
CVE-2025-39682: Linux Kernel kTLS Receive Path Zero-Length Record Use-After-Free Privilege Escalation
CVE-2025-32724: Remote Denial of Service and System Crash in Windows LSASS via RPC
CVE-2025-32711 (EchoLeak)
CVE-2025-32433: Pre-Authentication Command Execution in Erlang/OTP SSH Server
CVE-2025-30733: Pre-Authentication Memory Leak in Oracle Database Server (RDBMS Listener)
CVE-2025-29927: Middleware Authorization Bypass via x-middleware-subrequest Header in Next.js
CVE-2025-29824: SYSTEM Privilege Escalation in Windows CLFS Driver (Use-After-Free)
CVE-2025-29635: Command injection vulnerability in D-Link DIR-823X router firmware
CVE-2025-26319: Flowise Arbitrary File Upload and Directory Traversal Remote Code Execution
CVE-2025-25257: Unauthenticated SQL Injection in Fortinet FortiWeb Management Interface
CVE-2025-25249: Fortinet FortiOS cw_acd CAPWAP Heap Overflow to Unauthenticated RCE
CVE-2025-24813: RCE via Partial PUT Requests and Session Deserialization in Apache Tomcat
CVE-2025-24472: Super-Admin Authentication Bypass in Fortinet FortiOS & FortiProxy (CSF Proxy)
CVE-2025-24054: NTLM Hash Disclosure and Coerced Authentication in Windows (.library-ms)
CVE-2025-23304: NVIDIA NeMo Framework RCE
CVE-2025-22457: Subsequent Pre-Auth Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)
CVE-2025-21333: Windows Kernel Privilege Escalation via Hyper-V VSP (Heap Overflow)
CVE-2025-20393: Unauthenticated Root RCE in Cisco Secure Email Gateway (Spam Quarantine)
CVE-2025-20352: SNMP Stack Buffer Overflow in Cisco IOS and IOS XE (DoS & RCE)
CVE-2025-20281: Unauthenticated Root RCE in Cisco Identity Services Engine (ISE) API
CVE-2025-20188: Arbitrary File Upload and Root RCE in Cisco IOS XE WLC via Hard-Coded JWT
CVE-2025-8088: WinRAR Path Traversal Vulnerability
CVE-2025-5777: OOB Memory Disclosure and MFA Session Hijacking in Citrix NetScaler ADC & Gateway (CitrixBleed 2)
CVE-2025-5277: Command Injection in AWS MCP Server via Prompt-Coerced Tool Execution
CVE-2025-3248: Langflow Unauthenticated Code Validation Python exec() Remote Code Execution
CVE-2025-0282: Pre-Authentication Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA)
2024 Archive
2024 Vulnerability Reports
CVE-2024-57728 : SimpleHelp Arbitrary File Upload
CVE-2024-47575: Fortinet FortiManager fgfmd Authentication Bypass & Remote Code Execution (FortiJump)
CVE-2024-21762: Fortinet FortiOS SSL-VPN Out-of-Bounds Write Remote Code Execution Zero-Day
CVE-2024-20359: Cisco ASA and FTD Persistent Local Code Execution (Line Runner / ArcaneDoor)
CVE-2024-20353: Cisco ASA and FTD Web Server Denial of Service & Memory Corruption (ArcaneDoor)
CVE-2024-5184: EmailGPT Direct Prompt Injection & Email Data Exfiltration
CVE-2024-3400: Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day
CVE-2024-0012: Palo Alto Networks PAN-OS Management Web Interface Authentication Bypass
2023 Archive
2023 Vulnerability Reports
CVE-2023-36424: VMware vCenter Server Authentication Bypass
CVE-2023-27997: Fortinet FortiOS SSL-VPN Heap Buffer Overflow RCE (Volt Typhoon)
CVE-2023-27532: Veeam Backup & Replication API Credential Disclosure
CVE-2023-21529: Microsoft Exchange Server RCE via Untrusted Deserialization
CVE-2023-20198: Cisco IOS XE Software Web UI Privilege Escalation Zero-Day
2022 Archive
2022 Vulnerability Reports
CVE-2022-42475: Fortinet FortiOS SSL-VPN Pre-Auth Heap Buffer Overflow
CVE-2022-29230: XSS in Shopify Hydrogen
2020 Archive
2020 Vulnerability Reports
CVE-2020-9715: Adobe Acrobat and Reader Use-After-Free
CVE-2020-3452: Cisco ASA and FTD Web Services Read-Only Path Traversal
CVE-2020-2021: Palo Alto Networks PAN-OS SAML Authentication Bypass
2012 Archive
2012 Vulnerability Reports
CVE-2012-1854: Microsoft VBA Insecure Library Loading
2009 Archive
2009 Vulnerability Reports
CVE-2009-0238: Microsoft Excel Remote Code Execution
π Forensic Lab
Overview
Active Directory
01. Local vs Domain Accounts
02. SID, RID & Windows Identity
03. Privileged & Built-in Accounts
04. Local Admin vs Domain Admin
05. Authentication vs Authorization
06. Access Tokens & Context
07. Groups & Nesting
08. NTFS & Share Permissions
09. Privileges vs Permissions
10. Administrative Boundaries
11. Multi-Domain, Trees, and Forests
12. Forest, Tree, and Domain Trusts
13. Trust Fundamentals
14. Trust Types
15. Trust Direction and Transitivity
16. Cross-Domain Authentication
17. SID Filtering & Name Suffix Routing
18. Cross-Domain Groups & FSPs
19. Domain A to Domain B Takeover
20. Local Accounts on Domain Machines
21. NTLM vs Kerberos in DFIR
22. The Kerberos PAC
23. NetExec: What Results Actually Prove
24. Cross-Domain Lateral Movement
25. Kerberos Delegations
26. DCSync Mechanics & Artefacts
27. Golden Ticket vs Silver Ticket
28. DCs as Lateral Movement Hubs
29. RODC: Promises & Forensic Reality
30. Azure AD / Entra ID Connect
31. GPO Lateral Movement & Persistence
32. DFIR Identity Triage
33. AD Investigation Decision Tree
34. AD Edge Cases & False Friends
35. DFIR Cheat Sheet & Matrix
Active Directory Fundamentals
AD CS Exploitation
GPO Architecture & Abuse
Kerberos Authentication
NTLM Authentication
Microsoft 365
01. M365 DFIR Fundamentals
02. Entra ID Identity Plane
03. Accounts, Groups & Roles
04. Preparing Tenant for DFIR
05. Global Reader in DFIR
06. DFIR Access Matrix
07. Urgent Evidence Preservation
08. Logging Architecture
09. Entra Sign-in Logs
10. Entra Audit Logs
11. Provisioning Logs
12. Risk & Identity Protection
13. Unified Audit Log
14. Audit Log vs UAL vs Entra
15. Message Trace Forensics
16. Trace vs Mailbox vs UAL
17. Mailbox Auditing
18. Audit Retention Policies
19. Account Compromise Kill Chain
20. M365 Phishing Techniques
21. Adversary-in-the-Middle (AiTM)
22. AiTM Forensic Detection
23. Illicit Consent Grants
24. Password Spray & Brute Force
25. Device Code Flow Abuse
26. Persistence Techniques
27. Mailbox Rules Persistence
28. Mail Forwarding Persistence
29. OAuth & App Persistence
30. Auth Methods Backdoors
31. Roles & Privilege Escalation
32. M365 Data Attack Surface
33. Exchange Online Investigation
34. SharePoint Online Forensics
35. OneDrive Forensics
36. Microsoft Teams Forensics
37. Data Paths & Blast Radius
38. AD to Entra Identity Bridge
39. Entra Connect Forensics
40. Password Hash Sync (PHS)
41. Pass-through Auth (PTA)
42. Seamless SSO & Kerberos
43. Hybrid Attack Paths
44. M365 Incident Triage
45. Reconstructing Timeline
46. What Evidence Proves
47. Correlating Evidence Sources
48. Unknown Tenant Investigation
49. BEC Investigation Playbook
50. AiTM Session Theft Case
51. OAuth Compromise Case
52. M365 Data Theft Case
53. Ransomware & Cloud Extortion
54. DFIR Quick Reference
55. DFIR Decision Tree
56. What Changed in 2026?
Windows
Advanced Injection (Evasion)
Advanced
NTFS Alternate Data Streams (ADS)
Amcache & RecentFileCache
BAM
BITS (Transfer Service)
DLL Hijacking & Sideloading
Event 4624/4625 (Logons)
Event 4663/5145 (Object Access)
Event 4688 (Process Creation)
Event 7045/4698 (Persistence)
EVTX Event Logs
Jumplists
LNK Files
LOLBAS Reconnaissance
MFT ($MFT)
Named Pipes (IPC)
Prefetch
Process Injection (Basics)
Process Lineage
PsExec
RDS (Remote Desktop)
Shellbags
Shimcache (AppCompatCache)
SMB & Lateral Movement
SRUM
Sysmon (System Monitor)
UserAssist & MUIcache
USN Journal
WER
Windows MRU (Most Recently Used) Lists
Windows Registry
Windows Timeline
WMI (Management Inst.)
Linux
Linux Account Analysis
Advanced Persistence (Rootkits)
Linux Auth Logs
Linux Connection Logs
Linux Cron Persistence
Text Editor Artifacts
Exfiltration & Staging
Filesystem & MAC Times
Linux Legacy Persistence
Package Analysis
Process & Memory (Live)
Linux Shell History
Linux SSH Artifacts
Sudoers Analysis
Systemd Persistence
Ivanti
Architecture & Versioning
Artifact & Webshell Hunting
Ivanti Log Analysis
Ivanti Ecosystem
Fortinet
Fortinet Ecosystem
Veeam
Architecture & Threat Actors
Vulnerability Matrix & Exploitation
Hardening & Zero Trust Guide
DFIR Forensic Investigation
π€ AI Security Research
Overview
Deep Dives & Architecture
Can AI Agents Really Perform Reverse Engineering? SRE-Bench Reveals Their Limits
Can an AI Agent Really Exploit a Real Vulnerability? ExploitGym Puts LLMs to the Test
AI Cybersecurity Benchmarks Compared: CyberGym vs ExploitGym vs ExploitBench vs SRE-Bench
ExploitBench: How Far Can an AI Agent Go When Exploiting a Vulnerability?
Can One AI Hack Another AI? PIMiner and the Rise of Autonomous Prompt Injection
Are Prompt Injections Impossible to Solve? The Contextual Integrity Impossibility Debate
Is MCP a Major New Attack Surface for AI Agents? Hybrid Analysis with MTGuard
AgentPoison: Red-teaming LLM Agents via Memory and Knowledge Base Poisoning
What Can AI Agents Actually Do in Cybersecurity in 2026? A Systematic Mapping of Capabilities, Benchmarks, and Limits
Can LLMs Accelerate Cyber Ranges and Attack Simulations? Analyzing arXiv:2608.16422
The State of Generative AI in Cybersecurity & Privacy: 2026 Landscape, Frontiers, and Gaps
Can You Trust LLMs with Cyber Threat Intelligence? Empirical Limits and Hallucinations (arXiv:2503.23175)
How Do You Attack an AI Agent? The Complete Anatomy of Agentic Exploitation
SysEvolve: Autonomous Attack-Defense Co-Evolution in Cyber Ranges β Analyzing arXiv:2608.15012
Can AI Agents Defend Real Systems? Autonomous SOCs, Malware Analysis, and Automated Remediation
Prompt Injection vs Tool Poisoning vs RAG Poisoning vs MCP Attacks: A Comparative Attack Taxonomy
The 10-Level AI Cyber Capability Ladder: A Living Taxonomy of Autonomous Agent Capabilities
A2A Lateral Movement
Deep Dive
Agent Misconfigurations
Operational
The Alignment Layer (RLHF)
Deep Dive
Direct Prompt Injection
Research
Function Hijacking (FHA)
Deep Dive
GPU Memory Forensics (KV Cache)
Deep Dive
Indirect Prompt Injection
Research
Least Privilege & Agent IAM
Deep Dive
LLM-Mediated Web Attacks (arXiv:2608.10281)
Empirical Study
Mathematics of Attention
Deep Dive
MCP Security Risks
Deep Dive
Agent Security as a Networking Problem
Architecture
The OWASPification of AI
Deep Dive
RAG Poisoning
Research
Runtime Security & AI EDR
Deep Dive
Semantic Execution Layers
Deep Dive
Tokenization Layer Exploitation
Research
Tool Injection (The RCE of AI)
Deep Dive
Tool Poisoning (Supply Chain)
Deep Dive
Training Data Poisoning
Research
Trust Boundary Collapse
Deep Dive
Agentic LLM Vulnerability Taxonomy
Deep Dive
Technical Research Briefs
Adversarial Agentic Workflows - AI Research Brief
Brief
Adversarial Poetry: A Universal Single-Turn Jailbreak - AI Research Brief
Brief
SIA: Self-Improving AI with Harness & Weight Updates - AI Research Brief
Brief
The Promptware Kill Chain: Re-framing Prompt Injections as Malware - AI Research Brief
Brief
π Playbooks
Overview
AD Credential Attacks
AD Lateral Movement
AD Persistence & Domination
BEC Investigation
EDR Alert Triage
Insider Exfiltration
Ivanti EPMM RCEs
SMB vs. RDP Lateral Movement
Ransomware Investigation
Suspicious Email Analysis
Hunting Persistence
π΅οΈ Threat Intel
Overview
MITRE ATLAS (AI Matrix)
PaperCut AI Campaign (GreyNoise)
Akira Ransomware
Cobalt Strike
The Diamond Model
Initial Access Brokers
Medusa & Storm-1175
ATT&CK Framework (Basics)
Hunting: Evasion & Lateral Movement
Hunting: Access & Execution
Hunting: Persistence & Privilege
Operationalizing ATT&CK
ATT&CK v19 Analysis
New
Qilin Ransomware
STIX Framework
TAXII Protocol
π Methodology
Overview & Principles
Knowledge Graph Architecture
Relationship Vocabulary
Evidence & Provenance
Source Reliability
Agent Blast Radius Methodology: Kinetic Damage Propagation & Boundary Attenuation
Agent Death & Emergency Termination Methodology (HDTM): Deterministic Kill-Switches & Epistemic Suicide
AI Agents & Cybersecurity Editorial Strategy
Hermes Decision Engine Methodology (HDEM): Multi-Objective Remediation Arbitration
Hermes Data Integrity & Epistemic Audit: Foundation & Trust Architecture (V3.0.1)
Agentic Security Observatory
Architecture
Agentic Security Score (HASS)
P0 Standard
Confidence Model & Evidence
P0 Standard
Hermes Autopsy
Forensic Matrix
Hermes Forecast
Forecast Engine
Hermes Threat Score (HTS)
P0 Standard
Historical Immutability (P5)
Epistemic Core
Prediction Benchmark
Leaderboard
Threat Trajectory (HTR)
Temporal Engine
Vulnerability Genome
Genetic Model
GitHub
Select theme
Dark
Light
Auto
Select language
English
FranΓ§ais
2012 Vulnerability Reports
CVE-2012-1854: Microsoft VBA Insecure Library Loading
Analysis of the CVE-2012-1854 vulnerability in Microsoft Office, a CISA Known Exploited Vulnerability enabling privilege escalation.