Skip to content
Threat Feed

Tag

Vulnerability-Management

10 briefs RSS
high advisory

Detection of Assets with Elevated Vulnerability Exposure via Wiz

This brief describes a detection capability designed to identify cloud assets exhibiting poor security posture by correlating high volumes of vulnerabilities, exploitable findings, and critical-severity bugs reported by the Wiz Cloud Security Platform.

Wiz Cloud Security Platform vulnerability-management cloud-security wiz
1t
high threat

CISA Adds Two Exploited Linux Kernel Vulnerabilities to KEV Catalog

CISA has added CVE-2025-39964 and CVE-2026-53266, two actively exploited Linux kernel vulnerabilities, to its Known Exploited Vulnerabilities catalog.

exploited Linux Kernel +1 vulnerability-management linux kernel cisa-kev
2c
critical threat

Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days

Microsoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 2c
high advisory

SQL Injection in Doctor Appointment System 1.0

An SQL injection vulnerability in the email parameter of the patient_login.php file allows unauthenticated remote attackers to execute arbitrary SQL commands in Doctor Appointment System 1.0.

Doctor Appointment System web-vulnerability sqli vulnerability-management injection cve-2026-85403
2r 1t 1c
critical threat

Active Exploitation of Siemens S7 Series PLCs in US Critical Infrastructure

The IC3 has issued an advisory regarding the active exploitation of Siemens S7 Series PLCs within US critical infrastructure sectors using CVE-2026-4357 to disrupt operational technology.

exploited S7 Series PLC critical-infrastructure ot-security vulnerability-management
1t
high advisory

SQL Injection in Simple Online Food Ordering System

SourceCodester Simple Online Food Ordering System 1.0 is vulnerable to unauthenticated SQL injection via the admin login endpoint, allowing remote attackers to execute arbitrary SQL commands.

Simple Online Food Ordering System cve-2026-76048 sql-injection web-application web-vulnerability sqli vulnerability-management
2r 1t 1c
high advisory

Mattermost Security Update for CVE-2026-9816

Mattermost has released critical security patches for multiple versions to address vulnerabilities tracked under CVE-2026-9816.

Mattermost +2 vulnerability-management security-advisory patch-management
1c
critical threat

August 2026 Microsoft Security Update Analysis

Microsoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 5c updated
high advisory

SQL Injection Vulnerability in MingSoft MCMS

MingSoft MCMS versions up to 3.0.6 contain a remote SQL injection vulnerability in the ms-mdiy component, allowing unauthenticated attackers to manipulate the formFields argument to execute arbitrary database queries.

MCMS web-vulnerability sqli vulnerability-management
1r 1t 1c
high advisory

SolarWinds Web Help Desk Security Bypass Vulnerability

A vulnerability in SolarWinds Web Help Desk, identified as CVE-2024-28986, allows remote unauthenticated attackers to bypass security measures, potentially leading to unauthorized access.

Web Help Desk web-application security-bypass vulnerability-management
1c