
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS

CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS

CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging

CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.

Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and

CISA added exploited Progress Kemp LoadMaster command injection CVE-2026-8037 to its KEV catalog after 792 in-the-wild exploitation attempts were documented.

Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the

Researcher Malcolm Stagg’s NatJack technique hijacks TCP sessions and spoofs DNS through NAT table manipulation, affecting Windows Hyper-V and Linux

Novee Security found flaws in Claude Code and Google Gemini CLI that let an attacker-controlled GitHub issue reach CI workflow

PortSwigger’s AI-assisted HTTP Terminator found roughly 30,000 HTTP desync vectors and a live Apache Traffic Server zero-day affecting roughly 700

CISA added JetBrains TeamCity CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, citing unauthenticated remote code execution in the wild.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.