
Cisco Unified CM SSRF Flaw CVE-2026-20230 Under Active Exploit
CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM’s WebDialer, is under active exploitation after a PoC dropped June

CVE-2026-20230, a CVSS 8.6 SSRF flaw in Cisco Unified CM’s WebDialer, is under active exploitation after a PoC dropped June

CVE-2026-20971 is a CVSS 7.8 use-after-free in Samsung KNOX’s PROCA and FIVE subsystems, affecting Galaxy S9 through S25 across Android

Four critical Dify vulnerabilities named DifyTap allow cross-tenant access to private AI chats, uploaded files, and internal APIs. Patched in

JFrog disclosed CVE-2026-8461, a critical heap overflow in FFmpeg’s video decoder enabling remote code execution when processing malicious video files.

CISA added CVE-2026-48907 to its KEV catalog as automated exploit campaigns target the unauthenticated file upload flaw in the Joomla

Unit 42 found CVE-2026-2473 in the Vertex AI SDK lets attackers execute code in a victim’s GCP tenant by squatting

Defused confirmed active exploitation of CVE-2026-39813 and CVE-2026-39808 in FortiSandbox, chained with CVE-2026-25089 to deliver unauthenticated root code execution across

Cisco released patches for CVE-2026-20262, an unauthenticated server-side request forgery flaw in SD-WAN Manager now actively exploited, as CISA issued

CISA added LiteSpeed cPanel CVE-2026-54420 to its KEV catalog with a 48-hour deadline as exploitation of the unauthenticated REST API

A three-CVE attack chain disclosed by Obsidian Security in LiteLLM AI Gateway lets low-privilege users escalate to root and steal
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.