CISA Adds One Known Exploited Vulnerability to Catalog
This CVE is actively exploited and added to CISA's KEV catalog, requiring immediate patching of affected Linux systems.
Vergleich von 2. Mai 2026 mit dem Vortag 1. Mai 2026.
This CVE is actively exploited and added to CISA's KEV catalog, requiring immediate patching of affected Linux systems.
This alert describes a specific active exploit (CopyFail) with root access capabilities, not just a patch reminder, and highlights that many systems remain unpatched.
Public PoC and Metasploit module for a Linux kernel cryptographic API logic flaw enabling local privilege escalation on AMD64/AARCH64 systems.
The BRICKSTORM malware exploits vCenter SSO to establish persistence and evade detection, requiring MFA and real-time alerting on SSO account actions.
This vulnerability allows a non-privileged user to corrupt kernel memory via GPU system calls, which could be exploited in multi-tenant virtualization environments like VMware ESXi to break isolation.
This is a newly disclosed Linux kernel vulnerability with a TOCTOU race condition in the packet socket subsystem that could allow local privilege escalation.
This CVE describes a newly discovered vulnerability in the Linux kernel's SMB client that allows a malicious server to corrupt memory via a crafted DACL, going beyond a simple patch reminder by detailing the specific flaw in ACL validation.
An unauthenticated remote attacker can exhaust the max_connections pool by triggering memory allocation failures via crafted TCP connections, causing permanent denial of service until module reload.
This vulnerability describes a specific slab-out-of-bounds read in io_uring that can be triggered by passing large sqe->len values, potentially leading to memory corruption or information disclosure.
This is a newly disclosed use-after-free vulnerability in the Linux kernel's BPF sockmap subsystem that could allow local privilege escalation or denial of service.
This is a newly disclosed vulnerability with no active exploitation reported yet, but it poses a high risk of kernel panic for systems using AF_ALG crypto operations.
Keine Änderungen in dieser Kategorie.
Keine Änderungen in dieser Kategorie.
This is a new Linux kernel privilege escalation vulnerability (Copy Fail) that affects Ubuntu and Debian systems in the company's tech stack.
This critical authentication bypass vulnerability in ABB Edgenius Management Portal could allow an attacker on the network to execute arbitrary code, posing a significant risk to manufacturing operations.
Exploitation allows unauthenticated remote reboot and system configuration disclosure, posing operational risk to manufacturing environments.
This is a newly disclosed vulnerability with no active exploitation reported yet, but it affects a critical remote access component used by the company.
This is a newly disclosed vulnerability in Ivanti Secure Access client with no evidence of active exploitation yet, but it underscores the need for patching critical remote access infrastructure.
This is a newly disclosed vulnerability in Ivanti Secure Access client that could allow denial of service via a crafted server message, but no active exploitation or specific victim sectors are mentioned.
This is a patch notification with no evidence of active exploitation or specific campaign details.
This is a patch notification with no active attack campaign details or victim sector information.
This is a patch reminder for a local DoS vulnerability in Ivanti Secure Access Windows clients; no active exploitation or sector targeting is reported.