Install
Vulnerabilities & Patching
CVEs, exploits, SBOMs, and patch prioritization and virtual patching guides.
- 4 Tracked terms
- Last 30 days Feed window
What this topic collects on
An article joins this feed when it matches these terms. Each one is also a search of its own.
Related topics
Latest in Vulnerabilities & Patching
Solana Mobile Suspends Brevo Account Following Unauthorized Access
15+ hour, 37+ min ago (79+ words) Solana Mobile disclosed that a security incident occurred at third-party marketing email service provider Brevo, affecting some customer accounts, including Solana Mobile's own account. The team immediately suspended the account after discovering unauthorized access and is verifying the scope of…...
Solana Mobile Brevo Breach Exposes Users to Potential Phishing Threats
16+ hour, 38+ min ago (200+ words) Solana Mobile said attackers gained unauthorized access to its Brevo marketing account, potentially exposing customer information in a security incident at the email provider. The company disabled its Brevo account after discovering the breach and is working with the provider…...
Trezor, BitBox Warn of Phishing Emails After Email Provider Breach
2+ day, 17+ hour ago (965+ words) Hardware wallet makers Trezor and BitBox have warned users about a coordinated phishing campaign in which fraudulent security alerts were sent through legitimate looking email infrastructure. The campaign emerged on September 9, with attackers impersonating Trezor and BitBox and using claims…...
A Critical WHMCS RCE Just Got Patched. Did You Update?
3+ day, 20+ hour ago (642+ words) Lillian Castro, Senior Editor Lillian Castro brings more than 30 years of editing and journalism experience to our team. She has written and edited for major news organizations, including The Atlanta Journal-Constitution and the New York Times, and she previously served…...
Hundreds of old, vulnerable Exchange servers remain in Australia
5+ day, 3+ hour ago (370+ words) Unpatched and ancient Microsoft Exchange servers that are vulnerable to a critical authentication bypass vulnerability are rife on Australian and New Zealand networks, putting organisations' mailboxes in risk of full compromise. Worse, there is now working exploit code publicly available…...
Microsoft Exchange Exploit Requires No Password: 22,000 Servers Exposed, ESU Ends October
1+ week, 3+ day ago (565+ words) CVE-2026-62911 is classified as an authentication bypass by capture-replay (CWE-294) and carries a CVSS 3.1 score of 8.0 from Microsoft — confirmed in Microsoft's Security Update Guide — and 8.1 from the Zero Day Initiative. The flaw resides in Exchange's Mailbox Replication Proxy Service — the…...
Global sinkhole operation ends Sality botnet???s 23-year run
1+ week, 4+ day ago (463+ words) Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cut Sality’s…...
21,000 Exchange Servers Exposed to Public PoC Exploit After Pwn2Own $200K Chain Demo | Trust & Security | CryptoRank.io
1+ week, 4+ day ago (584+ words) 21,000 Exchange Servers Exposed to Public PoC Exploit After Pwn2Own $200K Chain Demo CryptoRank 21,000 Exchange Servers Exposed to Public PoC Exploit After Pwn2Own $200K Chain Demo CVE-2026-62911 is an Exchange authentication-bypass (CVSS 8.0/8.1) that enables NTLM relay to an HTTP.sys endpoint and a demonstrated three-bug…...
Nearly 22,000 Exchange Servers Are Still Vulnerable Despite Microsoft’s August Patch
1+ week, 4+ day ago (260+ words) Published on September 1, 2026 Nearly 22,000 Microsoft Exchange servers remain vulnerable to a high-severity authentication bypass flaw that could give attackers access to every user mailbox on affected systems. Shadowserver identified 21,899 vulnerable Exchange server IP addresses exposed to the internet. Around 6,200 are…...
21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation
1+ week, 4+ day ago (416+ words) According to daily internet-wide scans published by the Shadowserver Foundation, exactly 21,899 unique IP addresses were flagged as vulnerable as of August 31, 2026, underscoring how slowly organizations are responding to one of this year’s most consequential Patch Tuesday disclosures. CVE-2026-62911 is classified…...