Critical MQTT Broker Flaw: CVE-2026-44091
An unauthenticated remote attacker can manipulate system configurations via a malicious MQTT ID, creating a critical risk to data integrity and system availability.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
An unauthenticated remote attacker can manipulate system configurations via a malicious MQTT ID, creating a critical risk to data integrity and system availability.
A critical server-side request forgery vulnerability in IBM WebSphere Application Server allows unauthenticated attackers to potentially compromise systems.
New data from VulnCheck reveals that AI-assisted vulnerability discovery is not yet driving a surge in real-world exploitation.
Enterprise security frameworks require adaptation rather than complete replacement to address the rise of autonomous AI agents.
A missing authentication bug in the AMMOS Instrument Toolkit allows unauthenticated attackers to control Deep Space Network communication sessions.
A missing authentication vulnerability in the AMMOS Instrument Toolkit GUI allows unauthenticated attackers to hijack sessions and issue spacecraft commands.
A critical vulnerability in prebid-server allows attackers to manipulate outbound requests, risking unauthorized data exposure.
A legacy vulnerability in IPMI 2.0 leaves over 24,000 servers vulnerable to offline password cracking and potential remote control.
SecurityThe startup plans to expand its R&D and sales teams after raising $35 million in a new Series A investment round.
New research shows AI-discovered flaws are exploited at the same rate as traditional ones, debunking 'vulnpocalypse' fears.
SecurityNew joint guidance from US and Australian agencies outlines methods to physically isolate critical operational technology systems.
A severe SQL injection vulnerability in @hypequery/clickhouse allows attackers to execute arbitrary SQL commands by manipulating input parameters.
A critical shell command injection flaw in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code with high-level privileges.
A critical vulnerability in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code via unquoted shell interpolation.
A severe vulnerability in the IBM WebSphere administrative console allows unauthenticated attackers to gain full control of the application server.
A legal dispute over Model Context Protocol technology highlights the risks startups face when piloting tools with tech giants.
A certificate validation flaw in Apache Thrift c_glib bindings exposes systems to interception, requiring an immediate update to version 0.24.0.
Recent updates address hundreds of vulnerabilities across iOS and macOS platforms, highlighting significant risks in kernel security.
A critical third-party software flaw forces the charity-focused bank to suspend digital access for 14,000 organizations.
Hush Security secures $30 million in Series A funding to address the growing identity and governance challenges posed by AI agents.