CVE-2026-58048 is being downplayed as low risk because it needs an existing account. On shared hosting, that’s exactly the wrong conclusion to draw.
vulnerability management
-
-
An unpatched Magento vulnerability is being exploited to backdoor stores with no login needed. Here’s how to check for compromise and cut your risk before a patch exists.
-
Citrix called CVE-2026-8452 a memory overflow. It turned out to be an unauthenticated root exploit, and that gap says something about how patch priority gets set.
-
A CVE identifies a vulnerability, nothing more. Here is why treating the number itself as a severity signal leads to the wrong patch order, and what should drive it instead.
-
CVE-2026-9586 shows how a mundane coding mistake in Sangoma’s Switchvox platform exposed thousands of businesses that never patch their phone systems.
-
A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.
-
Continuous threat exposure management (CTEM) is a genuinely useful framework buried under heavy marketing. Here’s what it actually requires, and where a dashboard alone falls short.
-
A practical walkthrough of external attack surface management: how discovery actually works, how it feeds into vulnerability scanning and penetration testing, and how to do it without enterprise tooling.
-
A PaperCut vulnerability chain let attackers bypass login and run code on print servers, and the vendor needed a second emergency patch after the first one was bypassed.
-
CVE-2026-21962 scores a perfect 10 on the CVSS scale and has been under active, automated attack since January. Here’s what it does and how to check if you’re exposed.