Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksNothing here is ranked by paymentHelp & FAQAPI

Vendor news

Releases, funding, leadership changes and incidents across the vendors in this catalog — collected automatically from vendors' own public feeds.Where this comes fromEvery item links to the vendor's own published source: a GitHub release feed, a changelog, a status page, an SEC filing or a company blog. Nothing here is written or editorially reviewed by 0-Doubt, and nothing is a recommendation — it is machine-collected public record, labelled the same way as all other baseline content on the platform. Coverage is uneven by design: a vendor that publishes no public feed will not appear, and that absence is not a judgement about the vendor.

AllNew capability 352Release 343Incident 227Leadership 43Funding 30Announcement 10851AnnouncementsEverything the classifier could not read as a release, funding round, leadership change, incident or new capability lands in Announcement — in practice mostly vendor blog and marketing posts, and about nine in ten of everything collected. It is filterable here, but deliberately kept out of the default view rather than mixed in, so the feed you land on is not ninety percent marketing.
Clear

227 matching stories — incident — showing up to 3 per vendorPer-vendor capWhile browsing, no single vendor may fill more than three slots on any one page, so a vendor with a chatty release cadence cannot buy the page you are looking at. That means a page can render fewer stories than the count above. Searching a headline or naming a vendor turns the cap off, because then you have asked to see everything that matches.

Incident

CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen

CVE-2026-55634 und CVE-2026-55220 betreffen Pimcore. Fehlerbereinigungen sind für drei Versionsreihen verfügbar. The post CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen appeared first on LocateRisk.

LocateRisk·Vendor blog·Aug 28, 2026
Incident

CVE-2026-81934: Redis-Schwachstelle in der TLS-Datenverarbeitung

CVE-2026-81934 betrifft Redis-Instanzen mit TLS-Konfiguration. Bereinigte Releases stehen für mehrere Redis-Branches bereit. The post CVE-2026-81934: Redis-Schwachstelle in der TLS-Datenverarbeitung appeared first on LocateRisk.

LocateRisk·Vendor blog·Aug 27, 2026
Incident

PaperCut Software vulns: CVE-2026-81578, CVE-2026-82078

Certain versions of PaperCut NG and PaperCut MF are affected by two vulnerabilities. Here's how to find impacted assets with runZero.

runZero·Vendor blog·Aug 27, 2026
Incident

Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE

Critical Avada WordPress Flaw (CVE-2026-18431) Enables RCE A critical vulnerability chain tracked as CVE-2026-18431 affects the Avada WordPress theme and its required Fusion Builder plugin, now branded as Avada Builder .

SOCRadar Cyber Intelligence Inc.
← Newer
  1. 1
  2. 2
Older →
·
Vendor blog
·
Aug 27, 2026
Incident

Zimbra CVE-2026-73570 Exploited: Why Patching Isn't the Finish Line

CVE-2026-73570 is an unauthenticated Zimbra RCE under active exploitation and now on CISA's KEV list. Patching closes the door, but it doesn't tell you who already walked through it.

Vijilan·Vendor blog·Aug 26, 2026
Incident

CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads

A critical remote code execution vulnerability in Gitea has moved from disclosure to active exploitation less than a month after a patch became available. Tracked as CVE-2026-60004 and rated 9.8 on the CVSS scale, the flaw allows an attacker with ordinary repository write access to plant an executable Git hook and run arbitrary shell commands […] The post CVE-2026-60004: Critical Gitea RCE Exploited to Deploy Miner-Like Payloads appeared first on SOC Prime.

SOC Prime·Vendor blog·Aug 26, 2026
Incident

CVE-2026-64849: SSRF-Sicherheitslücke in MLflow wird aktiv ausgenutzt

CVE-2026-64849 (CVSS 9,3, EPSS ≥ 95. Perzentil) ist eine als kritisch eingestufte, nicht authentifizierte, serverseitige Request-Forgery-Schwachstelle (SSRF) [CWE-918] bei der MLflow-Webhook-Übermittlung. Die CVE betrifft alle Versionen vor 3.15.0. Die Hauptursache ist eine fehlerhafte Umleitungsverarbeitung und DNS-Rebinding. Die Schwachstelle wird durch Umgehung der Schutzmaßnahmen _validate_webhook_url in der Standardkonfiguration des MLflow-Tracking-Servers ausgenutzt. Die CISA hat CVE-2026-

Greenbone AG·Vendor blog·Aug 26, 2026
Incident

CVE-2026-55663: mediasoup SCTP state-cookie forgery

Fresh 25 August 2026 NVD publication for `CVE-2026-55663` shows the npm package `mediasoup` and Rust crate `mediasoup` trusted fixed SCTP State Cookie markers (`msworker`, `0xAD81`) instead of a secret-keyed MAC. On `PlainTransport` or `PipeTransport` with SCTP enabled, an on-path attacker could forge `COOKIE-ECHO`, establish an unauthorized association, and inject DataChannel messages as a trusted peer.

Corgea·Vendor blog·Aug 26, 2026
Incident

Patching mcp-remote Is the Easy Part: The Harder Lesson of CVE-2025-6514

The critical mcp-remote RCE (CVE-2025-6514, CVSS 9.6) exposes how AI clients over-trust MCP servers — see what identity-first Zero Trust reachability would have stopped. The post Patching mcp-remote Is the Easy Part: The Harder Lesson of CVE-2025-6514 appeared first on NetFoundry.

NetFoundry·Vendor blog·Aug 25, 2026
Incident

CVE-2026-65400: macOS Screen Sharing Authentication Bypass Under Active Exploitation

Resecurity·Vendor blog·Aug 25, 2026
Incident

Zimbra vulnerability CVE-2026-73570: find impacted assets

Zimbra discloses critical unauthenticated RCE flaw CVE-2026-73570 (CVSS 8.9). Learn how SMTP snmp_notify exploits occur and upgrade to 10.1.20 immediately.

runZero·Vendor blog·Aug 24, 2026
Incident

Red Hat Keycloak vulnerability CVE-2026-18963: find impacted assets

Red Hat disclosed a critical Keycloak vulnerability (CVE-2026-18963, CVSS 9.1) enabling full account takeover. Here's how to find impacted assets.

runZero·Vendor blog·Aug 24, 2026
Incident

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

Rapid7·Vendor blog·Aug 24, 2026
Incident

New View for Security Incident Investigations

See how the Huntress SOC runs security incident investigations from first signal to final resolution, including the ones closed as benign.

Huntress·Vendor blog·Aug 24, 2026
Incident

CVE-2026-19478: GitLab CE/EE: GraphQL-Sicherheitslücke ohne Authentifizierung wird aktiv ausgenutzt

GitLab hat Korrekturen für CVE-2026-19478 (CVSS 9,4, EPSS 0,7 % (51. Perzentil)), eine Code-Injection-Sicherheitslücke mit kritischem Schweregrad [CWE-94], veröffentlicht. Die Sicherheitslücke betrifft die GraphQL-Direktive in der GitLab Community Edition (CE) und der Enterprise Edition (EE). Laut GitLab kann die Schwachstelle unter bestimmten Bedingungen einem nicht authentifizierten Angreifer ermöglichen, öffentliche Projekte und Benutzerdaten aus der Ferne […]

Greenbone AG·Vendor blog·Aug 24, 2026
Incident

CVE-2026-19478: GitLab GraphQL Flaw Exploited

CVE-2026-19478: GitLab GraphQL Flaw Exploited GitLab has patched CVE-2026-19478 , a critical code injection vulnerability affecting self-managed Community Edition (CE) and Enterprise Edition (EE) instances. Under certain

SOCRadar Cyber Intelligence Inc.·Vendor blog·Aug 24, 2026
Incident

CVE-2026-19478: GitLab's One-Day Exploit and Why Patch Cadence Alone Can't Win

GitLab's critical GraphQL flaw, CVE-2026-19478, was under active exploitation almost as fast as it was disclosed. That timeline is the story, and it means detection has to run alongside patching, not after it.

Vijilan·Vendor blog·Aug 23, 2026
Incident

Emerging Threat: (CVE-2026-21580) Confluence Privilege Escalation via Unauthenticated Stored XSS

A stored cross-site scripting flaw in Atlassian Confluence Data Center and Server lets an unauthenticated attacker run script in a privileged user's browser and act on their behalf.

CyCognito·Vendor blog·Aug 23, 2026
Incident

CVE-2026-55040: SharePoint's JWT Bypass Is a Patch Problem That Patching Won't Solve

A JWT authentication bypass in on-prem SharePoint went from public PoC to active exploitation in hours. Patching closes the vulnerability, but it doesn't revoke a forged admin session or a stolen machine key already sitting in an attacker's hands.

Vijilan·Vendor blog·Aug 22, 2026
Incident

CVE-2026-73570: Zimbra RCE Exploited

CVE-2026-73570: Zimbra RCE Exploited Zimbra Collaboration Suite (ZCS) faces an actively exploited command-injection vulnerability, identified as CVE-2026-73570 . This flaw affects the suite's SNMP notification processing

SOCRadar Cyber Intelligence Inc.·Vendor blog·Aug 21, 2026
Incident

No Crash Required: Verifying the Citrix NetScaler SAML Patch for CVE-2026-8452

CVE-2026-8452 lets an unauthenticated attacker corrupt memory in Citrix NetScaler's SAML parser with a single request, potentially leading to remote code execution. Bishop Fox breaks down the patch, how to safely verify it across a fleet, and what exploitation actually looks like in the logs.

Bishop Fox·Vendor blog·Aug 21, 2026
Incident

CVE-2026-19478 | GitLab CE/EE GraphQL Directive Code Injection Vulnerability

CVE-2026-19478 is a critical GitLab GraphQL code injection vulnerability that can allow unauthenticated attackers to modify or delete public projects and user data.

Horizon3.ai·Vendor blog·Aug 20, 2026
Incident

Detecting Langflow CVE-2026-33017 exploitation with Wazuh

Langflow is an open source, low-code platform for building and deploying AI-powered agents and workflows. These workflows, called flows, define how AI models, prompts, and other components interact to process a request. Organizations can publish flows as HTTP endpoints, allowing applications and users to interact with them remotely. Exposing these endpoints to the internet increases […] The post Detecting Langflow CVE-2026-33017 exploitation with Wazuh appeared first on Wazuh.

Wazuh·Vendor blog·Aug 20, 2026
Incident

CVE-2026-19490: Critical Citrix NetScaler Authentication Bypass Exposes Enterprise Gateways

Cloud Software Group has released security updates for a critical authentication bypass vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. Tracked as CVE-2026-19490 and rated 9.3 on the CVSS v4.0 scale, the flaw can allow an unauthenticated remote attacker to circumvent authentication controls on vulnerable systems configured as gateways or AAA virtual servers. The Critical […] The post CVE-2026-19490: Critical Citrix NetScaler Authentication Bypass Exposes Enterprise

SOC Prime·Vendor blog·Aug 20, 2026
Incident

Elementor Pro, rtMedia & Mailgun: mehrere kritische Sicherheitslücken (CVE-2026-32475, CVE-2026-66592, CVE-2026-78003)

CVE-2026-32475 (Elementor Pro ≤4.2.1), CVE-2026-66592 (rtMedia ≤4.7.11) und CVE-2026-78003 (Mailgun ≤2.2.0): PHP-Upload, SQL Injection und SSRF. Patches teils verfügbar. The post Elementor Pro, rtMedia & Mailgun: mehrere kritische Sicherheitslücken (CVE-2026-32475, CVE-2026-66592, CVE-2026-78003) appeared first on LocateRisk.

LocateRisk·Vendor blog·Aug 20, 2026
Incident

CVE-2026-8037 wird derzeit aktiv ausgenutzt! Authentifizierungsunabhängige RCE-Angriffe auf Kemp LoadMaster und ECS Connection Manager im Gange

CVE-2026-8037 (CVSS 9,8, EPSS >= 100. Perzentil) handelt es sich um eine kritische, nicht authentifizierte Sicherheitslücke, die die Ausführung von Remote-Code (RCE) ermöglicht, in Progress Kemp LoadMaster und Progress ECS Connection Manager. eSentire berichtete, dass die Ausnutzungsversuche am 29. Juni 2026 begannen und die Schwachstelle nun in die Liste der bekannten ausgenutzten Sicherheitslücken (KEV) der […]

Greenbone AG·Vendor blog·Aug 20, 2026
Incident

AI Security Incident Case: Encrypted Reasoning Blocks of Proprietary LLMs Can Be Stolen via Cross-Model Replay

Overview On August 10, 2026, MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and other institutions jointly published the paper Stealing Reasoning Traces from Proprietary LLM APIs. The research reveals a common architectural flaw in the reasoning model APIs of three major AI providers, Anthropic, OpenAI, and Google, which allows […] The post AI Security Incident Case: Encrypted Reasoning Blocks of Proprietary LLMs Can Be Stolen via Cross-Model

NSFOCUS·Vendor blog·Aug 20, 2026
Incident

CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perim

Rapid7·Vendor blog·Aug 19, 2026
Incident

CVE-2026-19478: Critical GitLab GraphQL Flaw Enables Unauthenticated Data Modification

GitLab has released an emergency security update addressing a critical vulnerability that can allow an unauthenticated remote attacker to modify or delete public projects and user data. Tracked as CVE-2026-19478, the flaw affects both GitLab Community Edition (CE) and Enterprise Edition (EE) and carries a CVSS score of 9.4. The vulnerability stems from a code […] The post CVE-2026-19478: Critical GitLab GraphQL Flaw Enables Unauthenticated Data Modification appeared first on SOC Prime.

SOC Prime·Vendor blog·Aug 19, 2026
Incident

Emerging Threat: (CVE-2026-60702) Oracle WebLogic Server Takeover via T3 and IIOP

A flaw in the core of Oracle WebLogic Server lets a low-privileged attacker with T3 or IIOP network access take over the server and reach adjacent systems.

CyCognito·Vendor blog·Aug 19, 2026
Incident

CVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why.

An unauthenticated attacker can crash any Cisco ASA or FTD with SSL VPN exposed; it’s been confirmed exploited in the wild, and Cisco hasn’t told us who or why. Attackers Can Force Your Firewall To Reboot If you run a Cisco Adaptive Security Appliance or a Firepower Threat Defense device with Remote Access SSL VPN […] The post CVE-2026-20349: Someone Is Crashing Cisco Firewalls. We Need to Talk About Why. appeared first on Eclypsium | Supply Chain Security for the Modern Enterp

Eclypsium·Vendor blog·Aug 19, 2026
Incident

CVE-2025-62593: Ray let Firefox and Safari drive dashboard job RCE

CISA's 17 August KEV addition for Ray is a browser-to-dashboard code-execution path in the PyPI package `ray`: versions before `2.52.0` trusted a `User-Agent` prefix check to spot browsers, but Firefox and Safari let `fetch()` override that header. With DNS rebinding, a malicious page could submit jobs to `/api/jobs` or `/api/job_agent/jobs/` on a developer's local or private-network Ray instance.

Corgea·Vendor blog·Aug 19, 2026
Incident

Emerging Threat: (CVE-2026-19478) GitLab Unauthenticated Project Deletion via GraphQL Directive

A code injection flaw in GitLab's GraphQL directive handling lets unauthenticated attackers modify or delete public projects and user data on self-managed instances.

CyCognito·Vendor blog·Aug 18, 2026
Incident

CVE-2026-63077 Puts Unauthenticated RCE on Every TeamCity On-Premises Server

A deserialization flaw in the agent polling protocol gives attackers TeamCity server privileges without credentials. JetBrains patched in 2025.11.7 and 2026.1.3 — CISA KEV and a 3-day federal deadline mean hunt now, not after the next release train.

isMalicious·Vendor blog·Aug 18, 2026
Incident

Ray CVE-2025-62593: Critical Browser-Driven RCE via DNS Rebinding

Resecurity·Vendor blog·Aug 18, 2026
Incident

Inside CVE-2026-59310: Root Cause Analysis of the VMware vCenter RCE Vulnerability

CVE-2026-59310 Root Cause Analysis A critical VMware vCenter vulnerability, CVE-2026-59310, was actively exploited in the wild within days of its disclosure. It’s giving attackers a permanent back door into sensitive, virtualized infrastructure. Some vulnerabilities never see the light of day in actual exploitation, but that is not the case here. As of August 14th 2026, about 361 systems have already been […] The post Inside CVE-2026-59310: Root Cause Analysis of the VMware vCenter R

Vali Cyber·Vendor blog·Aug 17, 2026
Incident

CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes

A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.

isMalicious·Vendor blog·Aug 17, 2026
Incident

INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)

INC affiliates are weaponizing an SSRF and a post-authentication code injection in SonicWall SMA 1000 to reach internal networks. Exploitation started weeks before the July 14 patch — here is how to hunt and triage.

isMalicious·Vendor blog·Aug 16, 2026
Incident

CVE-2026-73416 and CVE-2026-73627: JupyterLab extension-manager bypasses

Three August 2026 JupyterLab disclosures show the PyPI extension-management path could misapply administrator policy: blocklists compared non-canonical package names, `/lab/api/plugins` trusted incomplete lock enforcement, and a related `PyPIExtensionManager.install()` path skipped its own allowlist check because of a missing `await`.

Corgea·Vendor blog·Aug 16, 2026
Incident

CVE-2026-9082: Drupal Core SQL Injection Detection with Sn1per

CVE-2026-9082 is an actively exploited, unauthenticated SQL injection in Drupal core on PostgreSQL. Learn how to detect every affected host with Sn1per and Nuclei. The post CVE-2026-9082: Drupal Core SQL Injection Detection with Sn1per first appeared on Sn1perSecurity.

Sn1perSecurity LLC·Press release·Aug 15, 2026