Exchange Online Authentication Flaw
A critical vulnerability identified in Microsoft Exchange Online creates a significant risk of unauthorized network tampering.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A critical vulnerability identified in Microsoft Exchange Online creates a significant risk of unauthorized network tampering.
A newly disclosed heap-based buffer overflow in Microsoft Account creates a high-stakes path for unauthorized remote code execution.
A critical authorization vulnerability in Azure Red Hat OpenShift allows attackers to elevate privileges over a network, warranting immediate attention.
A critical vulnerability identified as CVE-2026-54120 allows for remote code execution via improper input validation.
A path traversal vulnerability in Bold Reports Standalone Report Designer allows unauthenticated attackers to read sensitive files from the server.
A critical vulnerability identified in SolarWinds Serv-U allows for unauthorized privilege escalation and potential root code execution.
A critical vulnerability in the lmdeploy API server enables unauthenticated attackers to reach internal network services.
A critical remote code execution vulnerability identified in SolarWinds Serv-U requires domain administrator access to exploit.
A critical vulnerability identified in SolarWinds Serv-U allows domain administrators to elevate privileges to system administrator.
A critical IDOR vulnerability in SolarWinds Serv-U allows authenticated attackers to execute code as root, earning a CVSS score of 9.1.
WordPress Core is under active attack via an interpretation conflict vulnerability that allows for SQL injection and remote code execution.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
A critical vulnerability in a WordPress plugin allows unauthenticated users to gain full administrator access to affected websites.
A critical vulnerability in AVideo allows for arbitrary OS command execution, bypassing previous security mitigations.
A critical vulnerability in LightRAG allows unauthorized cross-origin requests, potentially exposing sensitive documents and knowledge graph data.
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
A severe vulnerability in the node-tar library allows attackers to crash servers and exhaust storage through maliciously crafted archive files.
A campaign dubbed FakeGit uses 7,600 fake GitHub repositories to trick AI agents into installing the SmartLoader malware family.
Researchers detail how malicious GPU workloads could trigger cascading power grid failures through high-frequency electrical modulation.
The American-Israeli startup steps out of stealth with significant backing to manage agentic software risks within enterprises.