LiveThreat Vulnerabilities
// VULNERABILITY TRACKING

VULNERABILITY TRACKER

CVE tracking, CISA KEV alerts, and zero-day disclosures with third-party risk impact analysis.

Breaches Advisories Vulnerabilities 📡 RSS
Time: Severity: 4061 items
🛡️
Critical VulnerabilityLT BRIEFOct 09
Critical Remote Code Execution Vulnerability (CVE‑2026‑107406) in Citrix NetScaler ADC & Gateway Appliances
Citrix disclosed CVE‑2026‑107406, a critical memory‑overflow flaw in NetScaler ADC and Gateway that can enable remote code execution when the appliance acts as a SAML IdP/SP. The vulnerability underscores the importance …
DataBreachToday
🔴
High VulnerabilityLT BRIEFOct 09
Remote Code Execution Vulnerability Discovered in Citrix NetScaler ADC and Gateway
Citrix NetScaler ADC and Gateway appliances configured as SAML IdP/SP contain critical RCE flaws (CVE‑2026‑19490, CVE‑2026‑88771, CVE‑2026‑88779, CVE‑2026‑88772). The issue underscores the need for continuous vulnerabili…
CIS Advisories
🛡️
Critical VulnerabilityLT BRIEFOct 09
Researchers Release Working Exploit for Pre‑Auth AnyDesk Linux RCE Granting Root Access
Researchers have published a functional exploit for a pre‑authentication remote code execution flaw in AnyDesk's Linux client that provides root access. The vulnerability highlights the need for robust vulnerability‑mana…
The Hacker News
🛡️
CVE-2026-105133MediumLT BRIEFOct 09
Improper Authentication in AhsayCBS Backup Utility (CVE‑2026‑105133) Enables Crypto‑Miner Deployment
AhsayCBS backup software contains an authentication bypass (CVE‑2026‑105133) that attackers are exploiting to install XMRig miners disguised as Microsoft Edge. The flaw underscores the importance of robust authentication…
The Hacker News
🛡️
CVE-2026-102255CriticalLT BRIEFOct 09
Critical Remote‑Code‑Execution Vulnerability in SonicWall SMA1000 Appliances (CVE‑2026‑102255) Exploited in the Wild
SonicWall’s SMA1000 series (models 6210, 7210, 8200v) contain a maximum‑severity SSRF/RCE flaw (CVE‑2026‑102255) that attackers are already probing. The issue underscores the need for robust access‑control, rapid patchin…
BleepingComputer
🛡️
CVE-2026-47483HighLT BRIEFOct 09
Unauthenticated Attackers Can Crash NVIDIA DCGM Exporter (CVE-2026-47483), Threatening AI GPU Monitoring
A high‑severity flaw (CVE‑2026‑47483) in NVIDIA’s DCGM Exporter lets anyone on the Internet send crafted requests that crash the metrics service, exposing GPU inventory and potentially halting AI workloads. The issue und…
Help Net Security
🏛️
CVE-2015-3306CriticalLT BRIEFOct 09
Critical Improper Access Control in ProFTPD (CVE‑2015‑3306) Exploited by Flax Typhoon
Flax Typhoon is weaponising CVE‑2015‑3306, a critical improper‑access‑control bug in ProFTPD that grants unauthenticated file‑system access. Organizations must patch and prove control‑area compliance to satisfy audit exp…
The Hacker News
🛡️
Critical VulnerabilityLT BRIEFOct 09
FBI Warns FortiBleed Campaign Still Active, Compromising Over 86,000 FortiGate Firewalls
The FBI alerts that the FortiBleed (CVE‑2022‑42475) vulnerability continues to be weaponized, with more than 86,000 FortiGate firewalls reported compromised. The episode underscores the need for continuous vulnerability…
HackRead
🛡️
CVE-2026-107406CriticalLT BRIEFOct 09
Critical Remote Code Execution Vulnerability in Citrix NetScaler ADC and Gateway (CVE‑2026‑107406)
Citrix disclosed CVE‑2026‑107406, a memory‑overflow flaw in NetScaler ADC/Gateway that can enable RCE or DoS when the device is configured as a SAML SP/IdP. The high CVSS score underscores the need for rapid patching and…
Security Affairs
🛡️
Critical VulnerabilityLT BRIEFOct 09
GoBalance Vulnerability Enables Hijacking of .onion Addresses via Secret Key Recovery
A cryptographic flaw in the GoBalance tool allows attackers to recover the private key that defines a hidden‑service .onion address, enabling full site takeover. This highlights the need for robust key‑management and con…
The Hacker News
🔴
Critical VulnerabilityLT BRIEFOct 09
Critical Remote Code Execution Vulnerability (CVE‑2026‑107406) in Citrix NetScaler ADC & Gateway
Citrix disclosed CVE‑2026‑107406, a memory‑overflow RCE flaw affecting NetScaler ADC and Gateway when used as SAML IdP/SP. The vulnerability underscores the need for continuous patch management and audit‑ready evidence o…
BleepingComputer
🔴
CVE-2026-107406CriticalLT BRIEFOct 09
Critical RCE Vulnerability in Citrix NetScaler ADC/Gateway (CVE‑2026‑107406)
Citrix disclosed CVE‑2026‑107406, a memory‑overflow bug in NetScaler ADC and Gateway that can enable remote code execution or denial‑of‑service under certain configurations. The flaw underscores the importance of continu…
The Hacker News
🛡️
Critical VulnerabilityLT BRIEFOct 08
Critical Vulnerability in AWS Bedrock AgentCore Allows Single Prompt to Hijack Entire Fleet
A newly disclosed vulnerability in AWS Bedrock AgentCore lets an attacker use one crafted AI prompt to take over every agent in an organization’s AWS environment. The flaw underscores the need for continuous AI‑service m…
Dark Reading
🛡️
Critical VulnerabilityLT BRIEFOct 08
Critical Validation Flaws in Cisco Nexus Switches Enable Remote Code Execution and Denial‑of‑Service
Cisco disclosed five critical CVEs affecting Nexus 3000 and 9000 switches that allow arbitrary code execution with root privileges or forced reload when NX‑API, NGOAM, or MPLS OAM are active. The flaws underscore the nee…
BleepingComputer
🛡️
CVE-2026-32645CVE-2026-39460CVE-2026-28745CVE-2026-33367HighLT BRIEFOct 08
Multiple High‑Severity Auth Bypass & Credential Flaws in Red Lion N‑Tron 700 Series Switches
Seven critical vulnerabilities in Red Lion N‑Tron 700 series switches allow unauthenticated admin access, configuration tampering, and scripted reboot loops. The flaws expose gaps in authentication and change‑management …
CISA Advisories
🛡️
CVE-2026-104629CVE-2026-100730CVE-2026-105281CVE-2026-85479CriticalLT BRIEFOct 08
Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian
CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management,…
CISA Advisories
🛡️
CVE-2026-105269HighLT BRIEFOct 08
Stored XSS (CVE‑2026‑105269) in Satel Netco Design Enables Arbitrary Script Execution
Satel Netco Design versions before v2.1.7 contain a stored cross‑site scripting flaw (CVE‑2026‑105269) that lets a privileged network operator inject malicious web content. Exploitation can lead to script execution, file…
CISA Advisories
🛡️
CVE-2026-21589CriticalLT BRIEFOct 08
Critical Arbitrary File Access Flaw (CVE‑2026‑21589) in Atlassian Data Center Products Under Active Exploitation
A CVSS 9.3 path‑traversal bug (CVE‑2026‑21589) affecting multiple Atlassian Data Center applications is being actively exploited to read sensitive files. Enterprises must patch, tighten access controls, and capture evide…
Security Affairs
🏛️
CVE-2015-3306HighLT BRIEFOct 08
Improper Access Control in ProFTPD (CVE‑2015‑3306) Enables Remote File Read/Write
ProFTPD versions before 1.3.5a allow unauthenticated attackers to read or overwrite arbitrary files via FTP commands. The flaw underscores the need for auditable access‑control evidence and continuous monitoring to satis…
CISA KEV· 🏢 ProFTPD· ProFTPD
🏛️
CVE-2021-3199CriticalLT BRIEFOct 08
Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution
A path traversal flaw in ONLYOFFICE Docs (CVE‑2021‑3199) allows an attacker to embed a '..' sequence in an image‑upload request, bypassing JWT checks and potentially executing arbitrary code on the server. The vulnerabil…
CISA KEV· 🏢 ONLYOFFICE· Docs
🏛️
CVE-2023-22894HighLT BRIEFOct 08
Cleartext Storage of Sensitive Data in Strapi (CVE‑2023‑22894) Risks Admin‑Panel Confidentiality
Strapi’s CMS stores user details in cleartext, allowing anyone with admin‑panel access to read them. The issue also enables a chain to remote code execution, highlighting the need for encryption‑at‑rest controls and audi…
CISA KEV· 🏢 Strapi· Strapi
🏛️
CVE-2016-3081HighLT BRIEFOct 08
CVE‑2016‑3081: Apache Struts Command Injection Allows Remote Code Execution
Apache Struts versions with Dynamic Method Invocation enabled are vulnerable to a command‑injection flaw (CVE‑2016‑3081) that can lead to remote code execution. The issue highlights the need for continuous vulnerability …
CISA KEV· 🏢 Apache· Struts
🏛️
CVE-2015-5477MediumLT BRIEFOct 08
ISC BIND Vulnerability (CVE‑2015‑5477) Allows Remote Denial‑of‑Service via TKEY Queries
A data‑processing error in ISC BIND can be triggered by malicious TKEY queries, causing the DNS service to crash. The issue highlights the need for continuous patch management and auditable evidence of service‑availabili…
CISA KEV· 🏢 ISC· BIND
🛡️
High VulnerabilityLT BRIEFOct 07
Multiple Zero-Day Vulnerabilities Disclosed in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows Drivers
Cisco Talos disclosed seven new CVEs affecting Adobe, Apple, Foxit, and Microsoft products; patches are available. The findings underscore the need for continuous vulnerability management and auditable patch‑deployment e…
Cisco Talos Intelligence
🛡️
CVE-2026-102255CriticalLT BRIEFOct 07
Critical Pre‑Auth SSRF Flaw (CVE‑2026‑102255) in SonicWall SMA1000 Appliances Allows Unauthenticated Access
SonicWall disclosed a CVSS 10.0 pre‑authentication SSRF vulnerability (CVE‑2026‑102255) affecting SMA1000 models, enabling unauthenticated attackers to reach internal functions. The flaw underscores the need for continuo…
Security Affairs
Page 1 of 163