Oracle WebLogic Vulnerability Exploited in the Wild

A critical vulnerability, identified as CVE-2024-21182, in Oracle WebLogic Server is actively being exploited in the wild. This vulnerability can be exploited without requiring any authentication, posing a significant risk to affected servers.

Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

Attackers are actively exploiting a Palo Alto Networks GlobalProtect vulnerability, tracked as CVE-2026-0257, to gain unauthorized VPN access into corporate networks. The flaw, which allows for credential-less authentication bypass, was initially disclosed as medium severity but was quickly escalated to high urgency by Palo Alto Networks due to observed exploitation.

Microsoft Threatening Security Researcher

A security researcher known as 'Nightmare Eclipse' has published details of significant Windows exploits, including one that bypasses BitLocker encryption. Microsoft has responded by threatening legal action against the researcher, leading to a public exchange of recriminations.

Microsoft's Zero-Day Legal Threats Spark Backlash

Microsoft has threatened legal action against a security researcher who published several zero-day exploits, sparking backlash from the cybersecurity community. Critics argue that Microsoft's stance discourages responsible disclosure and could hinder vulnerability research.

Oracle’s first monthly patch release fixes 35 flaws, including 11 rated ‘critical’

Oracle has released its first monthly Critical Security Patch Update (CSPU) for May 2026, addressing 35 vulnerabilities, including 11 rated as critical. Among these are several flaws with publicly available exploit code, some of which have been known for a considerable time, highlighting ongoing challenges with patching embedded open-source components.

Vulnerability Disclosure in the Age of AI

A new article by Melissa Hathaway argues that AI is dramatically accelerating vulnerability discovery, exposing decades of software development prioritizing speed over security. It calls for a coordinated national and international effort involving governments, vendors, and operators to accelerate remediation and invest in automated repair before adversaries exploit this opportunity.

Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit

Palo Alto Networks is urging users to patch a critical authentication bypass vulnerability in its PAN-OS GlobalProtect VPN, which is being actively exploited in the wild. Adversaries have already launched two waves of attacks leveraging this flaw, highlighting the urgency for defenders to apply the necessary security updates.

Race Against Time: Why Faster Vulnerability Alerts Matter

Attackers are increasingly exploiting vulnerabilities before organizations can identify and patch them. Faster vulnerability alerts are crucial for reducing exposure and improving security response times.

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium has issued a warning that threat actors are actively exploiting a critical Windows Netlogon Remote Code Execution (RCE) vulnerability in ongoing attacks. This vulnerability was recently patched, highlighting the ongoing threat posed by unaddressed security flaws.

Palo Alto VPN bug graduates from advisory to active exploitation

Attackers are actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS software. This flaw allows unauthorized access to VPNs, necessitating urgent patching for affected users and organizations.

Flowise’s MCP implementation can run ghost commands

A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-40933, has been discovered in self-hosted Flowise deployments. The flaw exists within the implementation of Model Context Protocol (MCP) stdio servers, allowing attackers to trigger code execution with a single click via a malicious chatflow import. This vulnerability could grant attackers root-level access in containerized environments.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition is based on evidence of active exploitation, posing significant risks to federal networks. Federal agencies are required to remediate this vulnerability, and CISA strongly encourages all organizations to prioritize its patching.

Recent Palo Alto Networks Vulnerability Exploited for Weeks

Hackers have been actively exploiting a critical authentication bypass vulnerability, identified as CVE-2026-0257, in Palo Alto Networks' PAN-OS software. The exploitation began just four days after the vulnerability was publicly disclosed.

CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic Server has an unspecified vulnerability allowing unauthenticated network attackers to compromise the server via T3 or IIOP protocols. Successful exploitation can lead to unauthorized access to critical or all accessible data.

WP Maps Pro bug exploited to create admin accounts on WordPress sites

A critical vulnerability in the WP Maps Pro plugin for WordPress is being actively exploited by hackers. The flaw allows unauthenticated attackers to create new administrator accounts on vulnerable websites. This could lead to full site compromise and malicious activity.

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Palo Alto Networks has issued a warning that a critical authentication bypass flaw in its GlobalProtect VPN, identified as CVE-2026-0257, is actively being exploited by attackers to compromise corporate networks. The vulnerability allows unauthenticated attackers to bypass authentication and gain access to sensitive systems.

Exploit Code Published for Critical Flowise RCE Vulnerability

Exploit code has been publicly released for a critical remote code execution (RCE) vulnerability in Flowise. This vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow.

New CIFSwitch Linux flaw gives root on multiple distributions

A new Linux kernel vulnerability named CIFSwitch has been discovered, enabling local privilege escalation. Attackers can exploit this flaw to forge CIFS authentication key descriptions and gain root access on affected systems.

Certifiably random: Swiss researchers claim perfect random number source

Swiss researchers have developed a new method for generating truly random numbers using quantum superconducting chips and a long microwave pipe. This advancement aims to overcome biases found in traditional random number generators, which have previously led to security issues in various applications.

With Complex Cloud Integrations, Small Errors Lead to Major Compromises

Researchers have identified an exploit chain that leverages over-permissioned cloud roles, secrets discovery, and non-human identities to compromise automation services. This vulnerability chain highlights how seemingly small misconfigurations in complex cloud environments can lead to significant security breaches.

Gogs Zero-Day Exposes Servers to Remote Code Execution

A critical-severity zero-day vulnerability in Gogs, a self-hosted Git service, allows authenticated attackers to execute remote code via pull requests with malicious branch names. The flaw has a CVSS score of 9.4 and is described as an argument injection vulnerability.

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added CVE-2026-0257, a Palo Alto Networks PAN-OS authentication bypass vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion is due to evidence of active exploitation, posing significant risks to federal networks. CISA urges all organizations to prioritize the remediation of these cataloged vulnerabilities as part of their security practices.

ChatGPT blindly trusts browser content, turning the page into a payload

Researchers have discovered that ChatGPT can be manipulated to execute arbitrary code when presented with specially crafted web content. By embedding malicious JavaScript within seemingly innocuous browser content, attackers can trick ChatGPT into running this code, potentially leading to system compromise or data exfiltration.

Chrome 148 Update Patches 151 Vulnerabilities

Google has released Chrome 148, which addresses a significant number of security vulnerabilities. The update resolves 151 security defects, including several critical-severity flaws that could have allowed for remote code execution.

Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects

A critical argument injection vulnerability has been discovered in the open-source Gogs Git service, allowing authenticated users to execute code remotely. The maintainer of Gogs has not responded to the vulnerability disclosure for over two months, leaving it unpatched and highlighting potential risks associated with self-hosted code platforms from smaller open-source projects.

CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

A critical authentication bypass vulnerability (CVE-2026-0257) has been identified in Palo Alto Networks PAN-OS, allowing unauthorized VPN connections. Federal agencies must apply mitigations by June 1, 2026, or discontinue product use if mitigations are unavailable.

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are exploiting a critical vulnerability in FortiClient EMS to deploy a new infostealer malware known as EKZ. The vulnerability, an authentication bypass flaw, allows attackers to gain unauthorized access and push the malware to vulnerable systems.

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

A critical RCE vulnerability has been found in Gogs, an open-source self-hosted Git service. This flaw allows any authenticated user to execute arbitrary code on the server under specific circumstances. Rapid7 has rated the vulnerability a 9.4 on the CVSS scale, and it does not currently have a CVE identifier.

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are actively exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to distribute credential-stealing malware. The campaign leverages trusted endpoint management infrastructure to deliver payloads disguised as legitimate Fortinet software across managed endpoints.

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Fortinet has released patches for a critical vulnerability in FortiClient EMS, which was actively exploited in the wild as a zero-day. The company urged users to apply the fixes immediately following the discovery of these attacks.

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is addressing multiple software supply chain attacks that target developer ecosystems, including CI/CD pipelines. These attacks involve malicious VS Code extensions and poisoned GitHub Action workflows, leading to unauthorized access and exfiltration of sensitive information like credentials and tokens. The incidents highlight the exploitation of developer tools and processes by threat actors.

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

CISA has issued an alert for a critical vulnerability (CVE-2026-7786) in Jinan USR IOT Technology Limited's USR-W610 RS232/485 to Wi-Fi/Ethernet Converter. The vulnerability stems from hard-coded administrative credentials embedded in the firmware, which can be exploited for administrator access. The affected product is deployed worldwide, including in critical manufacturing sectors.

KMW CCTV Security Cameras

CISA has issued an alert regarding a critical vulnerability in KMW CCTV Security Cameras, specifically versions KM-IP521 IPCAM_V4.04.91.230307 and KM-IP421 IPCAM_V4.04.53.210416. The vulnerability, CVE-2026-5386, allows for unauthenticated remote password resets, granting attackers full control over camera feeds and settings. KMW has released a firmware update to address this flaw, along with recommended mitigation steps for network segmentation and regular updates.