Week 40 – Code injection: Sneaking in

28 Sept – 04 Oct 2026 A high-severity vulnerability in Microsoft SharePoint Server has recently drawn attention. CVE-2026-65660 is a CWE-94 code injection vulnerability that can allow an authenticated attacker to execute arbitrary code on an affected SharePoint Server. The vulnerability has a CVSS 3.1 …

Week 39 – Check Point Under Attack: Critical Zero-Day Exploited in the Wild

21 – 27 Sept 2026 What happens when the security infrastructure itself becomes the target? This week’s CVE of The Week covers CVE-2026-93616, a critical Check Point zero-day vulnerability with a CVSS score of 9.8 — exploited in targeted attacks before a patch was available. …

Week 38 – GitLab Under Attack: Critical Arbitrary File Read Vulnerability

14 – 20 Sept 2026 What if an unauthenticated user could read your sensitive data from the GitLab server? This week’s CVE of the Week highlights CVE-2026-85706 in GitLab – a critical CVSS 10.0 flaw that could allow unauthenticated attackers to read arbitrary files from …

Week 37 – SAP Attack: When the Buffer Says “No More”

07 – 12 Sept 2026 A critical CVSS 10.0 vulnerability puts thousands of Internet-facing SAP systems potentially at risk. Our latest CVE of the Week covers CVE-2026-44756, a buffer overflow vulnerability in the SAP Kernel that could enable remote attackers to execute code with administrative …

Week 36 – Critical Metabase SQL Injection Scores a Perfect 10

31 Aug – 06 Sept 2026 A critical CVSS 10.0 vulnerability puts the spotlight on one of the oldest tricks in the hacker’s toolbox: SQL injection. This week’s CVE of the Week, CVE-2026-72898, affects self-hosted Metabase Community and Enterprise/Pro deployments and can allow unauthenticated attackers …

Week 35 – CoSnitch: When Copilot Starts Snitching

24 – 30 Aug 2026 What if your AI assistant could be tricked into handing your data to an attacker? This week’s CVE of the Week looks at CVE-2026-24301 (CoSnitch), a CVSS 8.8 vulnerability in Microsoft Copilot combining automatic prompt execution, data exfiltration and persistent …

Week 34 – From Auto-Login to Full RCE: Inside the IBM Langflow CVE

17 – 23 Aug 2026 AI platforms are increasingly becoming attractive targets for attackers. CVE-2026-9198 affects IBM Langflow OSS and chains security flaws that can lead to unauthenticated Remote Code Execution (RCE). With public PoCs available and the vulnerability already exploited in the wild, affected …

Week 33 – TeamCity Under Construction: Critical RCE Flaw

10 – 16 Aug 2026 A critical unauthenticated remote code execution (RCE) vulnerability has been disclosed in JetBrains TeamCity On-Premises. Tracked as CVE-2026-63077 with a CVSS score of 9.8, the deserialization flaw could allow remote attackers to bypass authentication and execute arbitrary system commands on …

Week 32 – N-able N-central – Take Control Taken Over

03-09 Aug 2026 CVE-2026-18577 is a critical authentication bypass vulnerability affecting N-able N-central. Due to an incomplete patch, attackers can gain administrative access, abuse the built-in Take Control feature, and pivot to managed endpoints. Read White Hat IT Security’s analysis to understand the attack chain, …

Week 31 – CertiGhost: The Certificate That Shouldn’t Exist

27 July – 02 Aug 2026 This week’s CVE of the Week is CVE-2026-54121, also known as CertiGhost, a critical vulnerability affecting Microsoft Active Directory Certificate Services (AD CS). The flaw allows a low-privileged authenticated domain user to obtain a certificate for a Domain Controller, …