top of page
ALL POSTS
CISA Adds Critical SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog Due to Active Exploitation
Key Findings CISA added CVE-2026-58644, a critical SharePoint Server remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog on July 16, 2026 The vulnerability was actively exploited in the wild before Microsoft released patches on July 14, 2026, making it a zero-day at the time of exploitation Federal Civilian Executive Branch agencies must remediate the flaw by July 19, 2026, under BOD 26-04 CISA also added two critical Fortinet FortiSandbox vuln
Jul 173 min read
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Bypass Flaw (CVE-2026-0257)
Key Findings CVE-2026-0257 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS affecting GlobalProtect portals and gateways Active exploitation confirmed by Rapid7 starting May 17, 2026, with two distinct attack waves originating from different hosting providers Vulnerability allows attackers to forge authentication cookies and bypass VPN access controls without credentials CISA added the flaw to its Known Exploited Vulnerabilities catalog in early June, re
Jun 153 min read
Marimo RCE Vulnerability CVE-2026-39987 Under Active Exploitation Since Disclosure
Key Findings Critical RCE vulnerability CVE-2026-39987 in Marimo (CVSS 9.3) exploited within 9 hours 41 minutes of disclosure Unauthenticated attackers can obtain full interactive shell access on exposed instances through /terminal/ws WebSocket endpoint Affects all Marimo versions up to 0.20.4; patched in version 0.23.0 Unknown threat actor built working exploit from advisory alone, with no public PoC available Attacker conducted credential theft operation and reconnaissance,
Apr 102 min read
bottom of page
