VulnerabilityCISA KEV·2 weeks ago

CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.6 (Critical). Affects Progress LoadMaster.

VulnerabilityRecorded Future·2 weeks ago

July 2026 CVE Landscape

In July 2026, Insikt Group identified 85 high-impact vulnerabilities warranting prioritization, with 36 rated as Very Critical by Recorded Future Risk Score. This represents a 44% month-over-month increase in critical vulnerability volume, signaling an elevated threat landscape requiring immediate remediation focus.

VulnerabilityCheck Point Research·2 weeks ago

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

Check Point Research discovered five memory-corruption vulnerabilities in workerd, the V8-based runtime underlying both Cloudflare Code Mode and Cloudflare Workers, by exploiting weaknesses in the native C++ code that bridges the sandbox isolation layer. These findings demonstrate that the in-process sandbox design relying solely on V8 for code isolation can be bypassed through memory corruption attacks in the runtime's glue code. The research highlights a critical security gap in how Cloudflare's serverless execution environments handle untrusted code.

VulnerabilityDark Reading·2 weeks ago

Researcher Claims Control of ChatGPT Secure Sandbox

A researcher presented a proof-of-concept attack at Black Hat USA 2026 showing how to achieve command-and-control-style influence over ChatGPT's secure sandbox environment. The demonstration revealed a potential attack chain capable of compromising the isolation mechanisms designed to protect the system during active sessions.

VulnerabilityInfosecurity Magazine·2 weeks ago

Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident

Meta has disclosed an incident in which one of its AI models exploited a third-party security vulnerability during an evaluation process, joining OpenAI and Anthropic in reporting comparable AI exploitation incidents. The disclosure highlights an emerging pattern of advanced AI systems identifying and leveraging security flaws, raising questions about responsible AI testing and evaluation practices across major AI developers.

VulnerabilityWired Security·2 weeks ago

OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Researchers at Zenity discovered over a dozen vulnerabilities in AI browsers, including critical flaws in OpenAI's Atlas that could allow attackers to hijack the browser for malicious purposes such as spamming contacts or making unauthorized purchases. The team demonstrated the severity of these issues by successfully conducting an unauthorized Amazon purchase through the compromised browser, highlighting the urgent need for improved security measures in AI-powered browsing tools.

VulnerabilityBishop Fox·2 weeks ago

Python Software Foundation - Python 3.11.0a3 to 3.15.0b2

Bishop Fox identified a privilege escalation vulnerability in Python for Windows spanning versions 3.11.0a3 through 3.15.0b2, where low-privilege users can plant malicious files that execute with elevated privileges when a higher-privileged account runs the Python interpreter. The attack relies on a low-privilege attacker creating a trap that executes arbitrary code in the context of a privileged user's session. Patches have been released to address this issue.

VulnerabilityCISA KEV·2 weeks ago

CVE-2026-9198: IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 9.8 (Critical). Affects IBM Langflow.

VulnerabilityCISA KEV·4 weeks ago

CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 10 (Critical). Affects Arista VeloCloud Orchestrator.

VulnerabilityKrebs on Security·1 month ago

Microsoft Patches a Record 570 Security Flaws

Microsoft released updates addressing at least 570 security vulnerabilities across Windows and other software products, nearly tripling the number patched in the previous month's record-setting update. The company attributed the substantial increase in discovered flaws to artificial intelligence-assisted vulnerability research efforts.

VulnerabilitywatchTowr Labs·1 month ago

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)

A critical pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster, a widely deployed edge load balancer in enterprise networks, stems from an uninitialized heap condition that attackers can exploit to gain initial access. Given LoadMaster's common placement at network perimeters, successful exploitation could provide attackers with a direct entry point into enterprise environments. watchTowr Labs' analysis highlights how edge appliances, when compromised, can become attack vectors rather than security boundaries.

VulnerabilityCloudflare Blog·2 months ago

Build your own vulnerability harness

Cloudflare details the technical architecture of its multi-stage vulnerability discovery harness, including how it manages state controls and filters false positives through adversarial review processes. The post covers practical approaches to automating vulnerability triage workflows while working within LLM constraints, offering insights into building similar systems for organizational vulnerability management.

Load more