Tag: cveoftheweek

Week 10 – A Bitter Cup of Java: CVSS 10 RCE in Cisco FMC

02 – 08 Mar 2026 Our CVE of the Week is about Cisco Secure Firewall Management Center (FMC) Software, which is an administrative nerve center for managing critical Cisco network security solutions. Critical vulnerability has been found with the CVSS score of 10 in CVE-2026-20131. 

Week 9 – Privilege Escalation Flaw in Windows Admin Center

23 Feb – 01 Mar 2026 In this week’s CVE of the Week, we’ll be looking at a high security flaw of improper authentication in Microsoft Windows Admin Center that allows an authorized attacker to elevate privileges over a network. Windows Admin Center is a 

Week 8 – From RecoverPoint to BreakPoint

16 – 22 Feb 2026 CVE-2026-22769 is a critical vulnerability affecting Dell’s RecoverPoint for Virtual Machines. RecoverPoint for Virtual Machines is a solution maintained by Dell to offer hypervisor-level backup and recovery for virtual machines and it is commonly used by enterprises. Exploiting this vulnerability 

Week 7 – Microsoft Patch Tuesday

9 – 15 Feb 2026 In this week’s CVE of the Week, we’ll be looking at one of the vulnerabilities updated during Microsoft’s February 2026 Patch Tuesday. CVE-2026-21510 is a protection mechanism failure that could allow an unauthorized attacker to bypass a security feature affecting 

Week 6 – When ++ Turns into a Minus

2 – 8 Feb 2026 Earlier this week, a security advisory reported a high-severity vulnerability in Notepad++, rated CVSS 7.7. But first of all, what is Notepad++? For those who may not be familiar with it, Notepad++ is a free, open-source text and source code 

Week 5 – Trusted by Default: Why Microsoft Office Remains a Prime Target

26 Jan – 1 Feb 2026 This week’s CVE of the Week highlights an actively exploited security feature bypass vulnerability in Microsoft Office. Microsoft Office is an office suite and a family of client software, server software, and services developed by Microsoft.It’s one of the 

Week 4 – Actively Exploited Zero-Day RCE Hits Cisco Unified CM and Webex Calling

12 – 18 Jan 2026 This week’s CVE of the Week is about the recent remote code execution vulnerability in Cisco’s Unified Communications (CM) products and Webex Calling Dedicated Instance, that has been actively exploited as a zero-day. This vulnerability is due to improper validation 

Week 3 – AI Agents Under Attack: High-Risk Vulnerability in ServiceNow

12 – 18 Jan 2026 Our CVE of the Week series continues with an AI Agent vulnerability that affected ServiceNow, one of the most popular cloud-based platforms for IT and business process automation. The CVE-2025-12420 vulnerability, assigned with a CVSS 4.0 score of 9.3, allows 

Week 2 – Wake up from this “Ni8mare”

5 – 11 Jan 2026 A new year, the same mission: raising awareness of critical vulnerabilities. Our CVE of the Week series continues in 2026 to help you stay ahead of emerging security risks. Let’s get started. Our first choice in 2026 is a vulnerability 

Week 51 – TOP10 CVE of the Week 2025

15 – 21 Dec 2025 As we reached the end of 2025 we have looked back to see the most impactful vulnerabilities of the year. Come and go through the TOP 10 CVEs of the year selected by our experts! A critical CVSS 9.1 flaw