
One Zero-Day, 40,000 Servers: The cPanel Mass-Compromise
A critical cPanel authentication bypass zero-day exploited for two months before disclosure compromised 40,000+ servers and targeted governments in Southeast

A critical cPanel authentication bypass zero-day exploited for two months before disclosure compromised 40,000+ servers and targeted governments in Southeast

A critical vulnerability in SGLang could allow remote code execution. Tracked as CVE-2026-5760, this flaw scores 9.8 on CVSS.

Three zero-day flaws in Microsoft Defender, dubbed BlueHammer, RedSun, and UnDefend, are being actively exploited to gain elevated system access.

Nginx servers vulnerable to attacks via a flaw (CVE-2026-33032) that allows authentication bypass.

Two severe security vulnerabilities identified in PHP’s Composer might allow arbitrary command execution.

Adobe releases emergency patches to fix a critical flaw in Acrobat Reader actively exploited in the wild, CVE-2026-34621.

A new Docker Engine vulnerability allows attackers to bypass authorization plug-ins due to an incomplete fix.

Fortinet issues emergency patches for a critical vulnerability (CVE-2026-35616) in FortiClient EMS, already exploited in the wild.

Critical Citrix vulnerability CVE-2026-3055 is targeted by attackers to steal data.

Two critical security vulnerabilities in n8n automation platform have been patched.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.