LiveThreat Vulnerabilities
// VULNERABILITY TRACKING

VULNERABILITY TRACKER

CVE tracking, CISA KEV alerts, and zero-day disclosures with third-party risk impact analysis.

🔓 Breaches 🔍 Advisories 🛡️ Vulnerabilities 📡 RSS
Time: Severity: 571 items
💥
CVE-2026-35616CriticalLT BRIEFApr 04
Critical FortiClient EMS Zero-Day (CVE-2026-35616) Actively Exploited – Immediate Hotfix Required
Fortinet disclosed that its FortiClient EMS 7.4.5/7.4.6 contains a critical improper‑access‑control vulnerability (CVE‑2026‑35616) that is being exploited in the wild. The flaw permits unauthenticated attackers to execut…
Help Net Security
🛡️
High VulnerabilityLT BRIEFApr 04
Critical Arbitrary Code Execution Vulnerability (CVE‑2026‑35616) in Fortinet FortiClientEMS Affects Enterprise Endpoint Management
Fortinet FortiClientEMS versions 7.4.5‑7.4.6 contain an unauthenticated code‑execution flaw (CVE‑2026‑35616) that is already being exploited. The vulnerability threatens any organization that relies on FortiClientEMS to …
CIS Advisories
🏛️
High VulnerabilityLT BRIEFApr 03
Chinese Hackers Exploit TrueConf Video Conferencing Vulnerability (CVE‑2026‑3502); CISA Orders Federal Patch Within Two Weeks
A critical updater flaw in TrueConf (CVE‑2026‑3502) is being weaponised by a Chinese‑state‑aligned campaign targeting government and critical‑infrastructure networks. CISA has ordered all federal agencies to patch the is…
The Record
🔧
Critical VulnerabilityLT BRIEFApr 03
Apple Patches Critical DarkSword iOS 18 Zero‑Day, Thwarting Mobile OS‑Cracking Tool
Apple released an emergency iOS 18 update that closes a zero‑day flaw exploited by the DarkSword framework, which could give attackers full control of iPhones and iPads. Organizations with iOS devices must patch immediat…
Dark Reading
🛡️
CVE-2026-20093CriticalLT BRIEFApr 03
Critical Auth Bypass in Cisco Integrated Management Controller (CVE‑2026‑20093) Enables Password Reset
Cisco has patched a critical authentication bypass in its Integrated Management Controller (IMC) that lets unauthenticated attackers reset any user password, including the admin account. The flaw affects a wide range of …
Help Net Security
🛡️
CVE-2025-55182CriticalLT BRIEFApr 02
Critical RCE in Next.js (CVE‑2025‑55182) Enables Credential Harvesting Across 766 Hosts
A remote‑code‑execution flaw in Next.js (CVE‑2025‑55182) is being actively exploited to steal database passwords, SSH keys, AWS secrets, Stripe API keys, and GitHub tokens from at least 766 web applications. The breach c…
The Hacker News
🔧
Critical VulnerabilityLT BRIEFApr 02
Active Exploit of Chrome Zero-Day (CVE‑2026‑5281) Threatens Enterprise Endpoints
Google confirmed an actively exploited zero‑day in Chrome (CVE‑2026‑5281) that enables remote code execution, prompting emergency patches for 21 vulnerabilities. The flaw affects any organization using Chrome, raising ur…
TechRepublic Security
🔴
High VulnerabilityLT BRIEFApr 02
Multiple Critical Vulnerabilities in Progress ShareFile Enable Remote Code Execution
Progress ShareFile versions before 5.12.4 contain two chained flaws (CVE‑2026‑2699, CVE‑2026‑2701) that let attackers bypass authentication and upload malicious ASPX web‑shells, achieving remote code execution. The issue…
CIS Advisories
🛡️
CVE-2026-20093CriticalLT BRIEFApr 02
Critical Authentication Bypass in Cisco IMC (CVE‑2026‑20093) & SSM On‑Prem (CVE‑2026‑20160) Threatens Server Management Infrastructure
Cisco released patches for two critical (CVSS 9.8) and six high‑severity flaws in its Integrated Management Controller and SSM On‑Prem. The vulnerabilities enable unauthenticated attackers to bypass authentication, execu…
Security Affairs
🔧
Critical VulnerabilityLT BRIEFApr 02
Apple Releases Emergency iOS 18 Patch for DarkSword Zero‑Day Exploit Impacting 270 Million iPhones
Apple has rolled out a rare emergency update for iOS 18 to fix the DarkSword zero‑day vulnerability that could allow remote code execution on up to 270 million iPhones. The patch is critical for organizations with BYOD p…
TechRepublic Security
🔧
CVE-2026-20093CriticalLT BRIEFApr 02
Critical Remote Code Execution in Cisco Integrated Management Controller (CVE‑2026‑20093) Threatens Enterprise Infrastructure
Cisco has patched a CVE‑2026‑20093 flaw in its Integrated Management Controller that enables unauthenticated attackers to bypass authentication and gain elevated privileges. The 9.8‑score vulnerability puts data‑center a…
The Hacker News
🛡️
High VulnerabilityLT BRIEFApr 02
Multiple Cisco Management Products Vulnerable to Arbitrary Code Execution – Potential Full Device Compromise
Cisco disclosed several vulnerabilities across its on‑prem management suite and Integrated Management Controller that could enable arbitrary code execution, risking full compromise of network and data‑center appliances. …
CIS Advisories
🛡️
CVE-2025-30208HighLT BRIEFApr 02
Active Exploit Attempts Target Exposed Vite Builds (CVE‑2025‑30208) Threaten Front‑End Supply Chains
A path‑traversal vulnerability (CVE‑2025‑30208) in the open‑source frontend build tool Vite is being actively exploited against publicly exposed instances. The flaw enables attackers to read arbitrary files and inject ma…
SANS Internet Storm Center
🔧
High VulnerabilityLT BRIEFApr 02
OpenSSH 10.3 Fixes Five Critical Vulnerabilities and Removes Legacy Rekeying Support, Disrupting Incompatible SSH Deployments
OpenSSH 10.3 addresses five security flaws—including a shell‑injection via usernames and certificate‑principal mismatches—and drops legacy rekeying support, potentially breaking older SSH clients. Organizations must veri…
Help Net Security
🔧
High VulnerabilityLT BRIEFApr 02
Apple Expands DarkSword Patch to iOS 18.7.7, Protecting Hundreds of Millions of Devices
Apple broadened its iOS 18.7.7 update to patch the six‑vulnerability DarkSword exploit chain, covering older iPhone and iPad models that were left on vulnerable iOS 18 builds. The move mitigates a remote‑code‑execution t…
Malwarebytes Labs
🔴
High VulnerabilityLT BRIEFApr 02
Pre‑Auth RCE Chain Discovered in Progress ShareFile Storage Zones Controller (CVE‑2026‑2699 & CVE‑2026‑2701) Exposes 30K Instances
Researchers uncovered a chained authentication‑bypass and remote‑code‑execution vulnerability in Progress ShareFile’s Storage Zones Controller, affecting roughly 30 000 publicly exposed instances. The flaws allow unauthe…
BleepingComputer
🏛️
CVE-2026-3502HighLT BRIEFApr 02
Active Exploitation of TrueConf Client (CVE‑2026‑3502) Added to CISA KEV Catalog
CISA has placed TrueConf Client CVE‑2026‑3502 in its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaw lets malicious actors download and run unsigned code, creating a supply‑chain risk fo…
CISA Advisories
🛡️
CVE-2025-7741LowLT BRIEFApr 02
Hardcoded Password in Yokogawa CENTUM VP (CVE‑2025‑7741) Enables Privilege Escalation in Critical OT Systems
A hard‑coded credential in Yokogawa CENTUM VP (CVE‑2025‑7741) permits an attacker who already reaches the HIS screen to log in as the PROG user and, if permissions are elevated, modify control‑system settings. The flaw a…
CISA Advisories
🛡️
CVE-2025-10492CriticalLT BRIEFApr 02
Critical RCE in Hitachi Energy Ellipse (CVE‑2025‑10492) Threatens Industrial Control Systems
A Java deserialization vulnerability (CVE‑2025‑10492) in the JasperReports library bundled with Hitachi Energy Ellipse (≤ 9.0.50) allows unauthenticated remote code execution. The flaw impacts global deployments in criti…
CISA Advisories
🛡️
CVE-2026-27663CVE-2026-27664HighLT BRIEFApr 02
High‑Severity DoS in Siemens SICAM 8 Products (CVE‑2026‑27663, CVE‑2026‑27664) Threatens Critical Manufacturing Operations
Two CVEs in Siemens SICAM 8 firmware enable remote resource exhaustion, causing denial‑of‑service. The flaws affect CPCI85, RTUM85, and SICORE components used worldwide in critical manufacturing. TPRM teams must verify v…
CISA Advisories
🔴
High VulnerabilityLT BRIEFApr 02
Apple Extends iOS 18 Patches After DarkSword Exploit Kit Targets Legacy Devices
Apple is back‑porting critical security fixes to iOS 18 devices after the DarkSword exploit kit began targeting legacy iPhones and iPads. The move expands protection for users who have not upgraded to iOS 26, reducing th…
Help Net Security
🛡️
Critical VulnerabilityLT BRIEFApr 02
Critical Cisco IMC Authentication Bypass (CVE‑2026‑20093) Grants Unauthenticated Admin Access
Cisco has disclosed CVE‑2026‑20093, a critical authentication bypass in its Integrated Management Controller that allows unauthenticated attackers to obtain admin rights on UCS servers. The flaw affects out‑of‑band manag…
BleepingComputer
🔴
Critical VulnerabilityLT BRIEFApr 02
Over 14,000 F5 BIG‑IP APM Instances Exposed to Critical RCE Vulnerability (CVE‑2025‑53521)
Shadowserver reports more than 14 k internet‑exposed BIG‑IP APM devices vulnerable to CVE‑2025‑53521, a critical RCE that is actively being exploited. Organizations using F5’s access management platform must patch immedi…
BleepingComputer
⬆️
CVE-2026-3775HighLT BRIEFApr 02
Foxit PDF Reader Update Service Local Privilege Escalation (CVE‑2026‑3775) Risks Enterprise Endpoints
A critical local privilege escalation (CVE‑2026‑3775) has been disclosed in Foxit PDF Reader's Update Service. The flaw lets a low‑privileged attacker load a malicious library and gain SYSTEM rights, posing a serious ris…
Zero Day Initiative
🔴
CVE-2026-4698HighLT BRIEFApr 02
Remote Code Execution in Mozilla Firefox (CVE‑2026‑4698) via IonMonkey Switch Optimization Type Confusion
A type‑confusion vulnerability (CVE‑2026‑4698) in Mozilla Firefox’s IonMonkey JavaScript engine allows remote attackers to execute arbitrary code after a user visits a malicious page or opens a crafted file. The flaw pos…
Zero Day Initiative
Page 1 of 23