LiveThreat Vulnerabilities
// VULNERABILITY TRACKING

VULNERABILITY TRACKER

CVE tracking, CISA KEV alerts, and zero-day disclosures with third-party risk impact analysis.

Breaches Advisories Vulnerabilities 📡 RSS
Time: Severity: 1745 items
🔴
Critical VulnerabilityLT BRIEFAug 01
Critical RCE‑Capable Vulnerability (CVE‑2026‑66066) Discovered in Rails Active Storage
Rails' Active Storage framework contains CVE‑2026‑66066, a critical flaw that lets unauthenticated attackers upload crafted images via libvips, read arbitrary files and potentially execute code. The issue highlights the …
BleepingComputer
🛡️
CVE-2026-48449CriticalLT BRIEFAug 01
Critical Remote Code Execution Vulnerability (CVE‑2026‑48449) Fixed in Adobe Campaign Classic
Adobe released a patch for a CVSS 10.0 remote code execution vulnerability (CVE‑2026‑48449) affecting Campaign Classic. The flaw allowed unauthenticated code execution via incorrect authorization. Prompt remediation is e…
Security Affairs
🛡️
CVE-2026-48449CriticalLT BRIEFAug 01
Critical RCE Vulnerability (CVE‑2026‑48449) Discovered in Adobe Campaign Classic
Adobe Campaign Classic is affected by CVE‑2026‑48449, a CVSS 10.0 remote‑code‑execution bug that bypasses authorization. The flaw highlights the need for robust SOC 2 access‑control evidence and rapid patch‑management to…
The Hacker News
🔧
Critical VulnerabilityLT BRIEFJul 31
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google released Chrome 151, fixing 370 security flaws—seven critical—across Windows, macOS, and Linux. The breadth of the update underscores the need for robust patch‑management controls to satisfy SOC 2 audit requiremen…
TechRepublic Security
🔧
High VulnerabilityLT BRIEFJul 31
Google Patches 1,442 Chrome Flaws Across Three Releases, Exceeding Prior 23 Updates Combined
Google’s Chrome 151, 150 and 149 updates fixed 1,442 security bugs, outpacing the total fixes of the previous 23 releases. The rapid patch cadence highlights the need for continuous browser‑patch management to satisfy SO…
The Hacker News
🛡️
High VulnerabilityLT BRIEFJul 31
84 Vulnerabilities Discovered in 4G/5G Core Networks, Including Session Hijacking Flaw
An academic team uncovered 84 security flaws in 4G and 5G core networks, ranging from denial‑of‑service to a session‑hijacking exploit. The findings highlight a control‑gap that SOC 2 programs must map, monitor, and evid…
The Hacker News
🛡️
Critical VulnerabilityLT BRIEFJul 30
Critical Auth‑Bypass and VM‑Escape Flaws Fixed in VMware vCenter, ESX, Workstation (CVE‑2026‑59309, CVE‑2026‑59310, CVE‑2026‑47876)
Broadcom released patches for five VMware vulnerabilities, three of which are critical and enable authentication bypass, arbitrary code execution, or VM‑escape to the host. Organizations running vCenter, ESX, Workstation…
BleepingComputer
🛡️
Critical VulnerabilityLT BRIEFJul 30
Critical CosmosEscape Vulnerability Exposes Master Key in Azure Cosmos DB Gremlin API
Wiz discovered a master‑key exposure in Azure Cosmos DB’s Gremlin API that could enable full account takeover. The flaw underscores the importance of SOC 2‑aligned key‑management and continuous access‑control monitoring.
HackRead
🛡️
CVE-2026-42897HighLT BRIEFJul 30
Cross‑Site Scripting in Microsoft Exchange (CVE‑2026‑42897) Enables OWAReaper Backdoor – Targeting Government & Private Sectors
Laundry Bear is weaponising CVE‑2026‑42897, an XSS bug in Exchange OWA, to deliver the OWAReaper backdoor that steals credentials and OAuth tokens. The flaw underscores the need for SOC 2‑aligned access‑control monitorin…
Help Net Security
🛡️
CVE-2026-18064CVE-2026-15352HighLT BRIEFJul 30
Critical NULL Pointer Dereference (CVE‑2026‑18064) in NASA cFS Health & Safety Application Enables DoS and Processor Reset
NASA’s Core Flight System Health & Safety application (≤ v7.0.1) contains a CVE‑2026‑18064 NULL‑pointer dereference that can crash the system, causing denial‑of‑service and a processor reset. For SOC 2‑ready organization…
CISA Advisories
🛡️
CVE-2026-12927HighLT BRIEFJul 30
Critical Out‑of‑Bounds Write (CVE‑2026‑12927) in Schneider Electric IGSS Risks Arbitrary Code Execution
Schneider Electric disclosed CVE‑2026‑12927, an out‑of‑bounds write in the IGSS Definition module that could allow data loss or arbitrary code execution when a malicious CGF file is imported. For SOC 2‑compliant organiza…
CISA Advisories
🛡️
CVE-2026-5846MediumLT BRIEFJul 30
Hard‑coded RSA Key Flaw (CVE‑2026‑5846) Lets Attackers Take Over Watchfire Controller Software
A CVE‑2026‑5846 vulnerability in Watchfire Controller Software embeds hard‑coded RSA private keys, allowing malicious actors to deliver firmware and seize full control of the controller. The flaw affects multiple version…
CISA Advisories
🛡️
CVE-2026-63362CVE-2026-65423CVE-2026-63035CVE-2026-63559HighLT BRIEFJul 30
Critical Integer Underflow/Overflow Flaws in o6 Automation open62541 Library (CVE‑2026‑63362‑63559) Threaten Industrial Control Systems
CISA reports four high‑severity vulnerabilities in the open62541 OPC UA stack that could enable remote code execution or denial‑of‑service on Windows and Linux deployments. For SOC 2‑ready organizations, mapping and evid…
CISA Advisories
🛡️
CVE-2026-9636MediumLT BRIEFJul 30
Improper Certificate Revocation Check (CVE‑2026‑9636) in Rockwell Automation CompactLogix & ControlLogix Modules Enables DoS
Rockwell Automation’s CompactLogix 5380, ControlLogix 5580 and EN4TR communication modules fail to reject certificates signed by a revoked intermediate, allowing a network‑based attacker to trigger denial‑of‑service. The…
CISA Advisories
🛡️
CVE-2026-21662CVE-2026-34495CVE-2026-34497LowLT BRIEFJul 30
Multiple Web Vulnerabilities (CVE‑2026‑21662, CVE‑2026‑34495, CVE‑2026‑34497) in Johnson Controls OpenBlue Employee Enable Malicious File Upload & XSS
Johnson Controls’ OpenBlue Employee platform (≤ V2025.3.1) contains three CVEs that permit unrestricted file uploads and cross‑site scripting. The flaws map to SOC 2 CC6 controls, making timely patching essential for aud…
CISA Advisories
🛡️
CVE-2026-14227MediumLT BRIEFJul 30
Insufficient Session Expiration in MikroTik RouterOS (CVE‑2026‑14227) Risks VPN Key Exposure
MikroTik RouterOS versions with the API enabled suffer an insufficient session‑expiration bug (CVE‑2026‑14227) that can let a low‑privilege user retain prior permissions and steal the router’s WireGuard private key. For …
CISA Advisories
🛡️
CVE-2026-12562HighLT BRIEFJul 30
Critical Unauthenticated Remote Access Vulnerability (CVE‑2026‑12562) in Toptech RCU II+ & Multiload II+ Devices Threatens Energy Infrastructure
CISA has issued an advisory for CVE‑2026‑12562, a missing‑authentication flaw in Toptech Systems’ RCU II+ and Multiload II+ controllers that allows an attacker to obtain full root control. The issue affects energy‑sector…
CISA Advisories
🛡️
CVE-2026-66720CVE-2026-66369CVE-2026-63550CVE-2026-65421HighLT BRIEFJul 30
Multiple High‑Severity DoS Vulnerabilities in MZ Automation libiec61850 Library Threaten Energy Control Systems
CISA reports eight CVEs in MZ Automation's libiec61850 (< 1.6.2) that enable unauthenticated denial‑of‑service attacks on IEC 61850 GOOSE traffic. The flaws affect energy‑sector control equipment worldwide and require im…
CISA Advisories
🛡️
CVE-2026-61893CVE-2026-63033MediumLT BRIEFJul 30
Out‑of‑Bounds Read Vulnerabilities (CVE‑2026‑61893, CVE‑2026‑63033) in MZ Automation lib60870 Could Crash Industrial Devices
MZ Automation disclosed two out‑of‑bounds read flaws (CVE‑2026‑61893, CVE‑2026‑63033) in lib60870 2.4.0 that can cause device crashes. For SOC 2‑ready organizations, the issue highlights the need for rigorous third‑party…
CISA Advisories
🛡️
CVE-2026-13584HighLT BRIEFJul 30
Timing‑Based Tampering Vulnerability (CVE‑2026‑13584) in Mitsubishi Electric CC‑Link IE TSN Protocol Threatens Industrial Controllers
CISA reports CVE‑2026‑13584 in Mitsubishi Electric’s CC‑Link IE TSN communication protocol, allowing an attacker on the same network segment to inject crafted packets that can disrupt or mis‑direct controller operations.…
CISA Advisories
🛡️
CVE-2026-20316HighLT BRIEFJul 30
Cisco FMC Static Credentials (CVE‑2026‑20316) Actively Exploited – Immediate Rotation Required
Cisco Secure Firewall Management Center contains a static‑credential vulnerability (CVE‑2026‑20316) that attackers are exploiting to gain unauthorized access. Organizations must apply the hot‑fix, rotate all credentials,…
Help Net Security
🏛️
CVE-2026-20316MediumLT BRIEFJul 30
Static Credential Flaw (CVE‑2026‑20316) in Cisco Secure Firewall Management Center Enables Unauthenticated Access
Cisco Secure Firewall Management Center (FMC) contains a hard‑coded low‑privileged account that attackers can use without authentication to view sensitive data. The vulnerability (CVE‑2026‑20316, CVSS 5.3) is actively ex…
Security Affairs
💥
CVE-2026-20316HighLT BRIEFJul 30
Cisco FMC Zero‑Day (CVE‑2026‑20316) Actively Exploited – Immediate Threat to Access Controls
Cisco Secure Firewall Management Center (FMC) contains a zero‑day flaw (CVE‑2026‑20316) that lets unauthenticated attackers gain admin access and harvest static credentials. For SOC 2‑compliant organizations, the issue h…
The Hacker News
💥
High VulnerabilityLT BRIEFJul 29
Russian Group Exploits Exchange OWA Zero‑Day (CVE‑2026‑42897) for Persistent Mailbox Access
Laundry Bear is exploiting CVE‑2026‑42897, an XSS flaw in Microsoft Exchange OWA, to deliver the OWAReaper backdoor and gain long‑term mailbox access. The activity spans government, telecom, finance, hospitality, and aer…
BleepingComputer
💥
CVE-2026-20316HighLT BRIEFJul 29
Static Credential Flaw in Cisco Secure FMC (CVE‑2026‑20316) Enables Zero‑Day Unauthorized Access
Cisco disclosed that a built‑in static account in Secure FMC (CVE‑2026‑20316) is being used in zero‑day attacks to gain unauthorized access. The issue highlights the need for robust access‑control evidence and rapid patc…
BleepingComputer
Page 1 of 70