Two chained Microsoft SharePoint flaws, patched in July and August, let an attacker take over an on-premises server without any credentials at all.
vulnerability management
-
-
Veeam, HashiCorp’s Terraform MCP Server and Django all patched critical flaws within 48 hours, including a CVSS 10.0 bug. Here’s what happened and what to check.
-
Cl0p-linked attackers are exploiting an unauthenticated flaw in PTC Windchill and FlexPLM. Here’s a practical checklist for finding out if you’re exposed.
-
The Cisco FMC vulnerability CVE-2026-20316 scores a modest 5.3 but is under active attack with no workaround. It’s a case study in why CVSS alone can’t drive your triage.
-
Broadcom has patched two 9.8-rated vCenter flaws and a VM escape bug in ESX. Here is what the VMware vCenter vulnerabilities mean for businesses running vSphere.
-
A step-by-step check for teams running Adobe Campaign Classic on-premise: confirm your build, check exposure, and patch a flaw that needs no login and no clicks.
-
F5’s nginx severity rating for CVE-2026-42533 is ‘Major’, but a researcher argues it enables an ASLR bypass. Vendor labels aren’t the last word on risk.
-
The new SharePoint zero-day vulnerability follows a pattern that patching alone won’t fix: a chained attack that steals server keys before the update ever lands.
-
Two SonicWall SMA 1000 zero-days are under active attack. Here is what CVE-2026-15409 and CVE-2026-15410 let an attacker do, and what to patch first.
-
A SharePoint bug rated 5.3 by Microsoft and 9.8 by NVD is already under active attack. Vendor severity ratings are falling behind AI-accelerated exploits.