Week 34 – From Auto-Login to Full RCE: Inside the IBM Langflow CVE

17 – 23 Aug 2026 AI platforms are increasingly becoming attractive targets for attackers. CVE-2026-9198 affects IBM Langflow OSS and chains security flaws that can lead to unauthenticated Remote Code Execution (RCE). With public PoCs available and the vulnerability already exploited in the wild, affected 

Week 33 – TeamCity Under Construction: Critical RCE Flaw

10 – 16 Aug 2026 A critical unauthenticated remote code execution (RCE) vulnerability has been disclosed in JetBrains TeamCity On-Premises. Tracked as CVE-2026-63077 with a CVSS score of 9.8, the deserialization flaw could allow remote attackers to bypass authentication and execute arbitrary system commands on 

Week 32 – N-able N-central – Take Control Taken Over

03-09 Aug 2026 CVE-2026-18577 is a critical authentication bypass vulnerability affecting N-able N-central. Due to an incomplete patch, attackers can gain administrative access, abuse the built-in Take Control feature, and pivot to managed endpoints. Read White Hat IT Security’s analysis to understand the attack chain, 

Week 31 – CertiGhost: The Certificate That Shouldn’t Exist

27 July – 02 Aug 2026 This week’s CVE of the Week is CVE-2026-54121, also known as CertiGhost, a critical vulnerability affecting Microsoft Active Directory Certificate Services (AD CS). The flaw allows a low-privileged authenticated domain user to obtain a certificate for a Domain Controller, 

Week 30 – A PDF Extension with a WhatsApp Obsession

20 -26 July 2026 In this week’s CVE of the Week, we’re examining a recently patched vulnerability chain in the Adobe Acrobat PDF Chrome extension, which is used by more than 314 million users worldwide. Tracked as CVE-2026-48294 (CVSS score: 8.2) and dubbed HermeticReader by 

Week 29 – Next Stop: SYSTEM

13 -19 July 2026 This week our CVE of the Week is CVE-2026-56164, a zero-day Elevation of Privilege vulnerability affecting Microsoft SharePoint Server that Microsoft confirmed is being actively exploited in the wild. SharePoint is a critical business platform used for document management, collaboration, and 

Week 28 – A perfect 10 in UniFi Connect

06 -12 July 2026 In this week’s CVE of the Week, we’re looking at CVE-2026-50746, a critical vulnerability affecting the Ubiquiti UniFi Connect Application, with a CVSS score of 10.0. The vulnerability is caused by Improper Access Control (CWE-284) and allows an attacker with network 

Week 27 – Impact Zone: RoguePlanet Crashes into Microsoft Defender

29 June – 05 July 2026 One of the most discussed security issues in weeks is CVE-2026-50656, also known as RoguePlanet, an Elevation of Privilege (EoP) vulnerability affecting the Microsoft Malware Protection Engine used by Microsoft Defender. It was eventually assigned a CVE ID, so 

Week 26 – Today’s offer: SSRF with root access

22 – 28 June 2026 In this week’s CVE of The Week, we’ll be looking at a newly exploited, high-severity server-side request forgery (SSRF) vulnerability, in Cisco Unified Communications Manager Server. Tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for 

Week 25 – Caught in the Web: ShinyHunters Spins a MeshCentral Trap for PeopleSoft

15 – 21 June 2026 Critical vulnerability has been found with the CVSS score of 9.8 in CVE-2026-35273. Our CVE of the Week is about PeopleSoft which is a comprehensive Enterprise Resource Planning (ERP) software suite owned by Oracle Corporation. PeopleSoft helps large organizations manage