LIVE · cybersecurity feed
Live wire
vendor

Isc

4 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical0
High4
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-30397.5highbindBIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive me143d ago
CVE-2026-59467.5highbindMultiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet 143d ago
CVE-2026-59477.5highbindUndefined behavior may result due to a race condition leading to a use-after-free violation.143d ago
CVE-2026-35937.4highbindA use-after-free vulnerability exists within the DNS-over-HTTPS implementation.143d ago

Filter the full tracker by Isc →

Our coverage of Isc

breachcritical

Cisco Patches a Dozen Critical Vulnerabilities

Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…

vulnerabilitycritical

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…

security

Cisco quantum network controller lets apps order entanglement on demand

Cisco has unveiled a Quantum Network Controller, a research prototype designed to enable applications to request entanglement on demand from a quantum network, abstracting away the underlying hardware complexities. This controller manages the distribution of entanglement, a linked quantum state shared between distant points, which is a critical resource for quantum networks.

CVE-2026-102489high

Zammad Session Fixation Vulnerability Exploited Same Day as Disclosure

CVE-2026-102489, a session fixation vulnerability in Zammad GmbH Zammad, was exploited on the same day it was published. The vulnerability is now listed in multiple exploitation catalogues.

CVE-2017-20284high

Caucho Resin Path Traversal Flaw Exploited Same Day as Disclosure

CVE-2017-20284, a path traversal vulnerability in Caucho Technology's Resin, was reported as exploited on the same day it was published. VulnCheck lists it as exploited, but CISA and EUVD do not.

CVE-2026-102489critical

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure

The Dutch Institute for Vulnerability Disclosure (DIVD), a cybersecurity non-profit, recently disclosed that it was compromised in an attack that exploited two zero-day vulnerabilities in its Zammad helpdesk platform. The incident, detected on September 24, involved the use of what DIVD describes as an "agentic AI" to execute the attack.

CVE-2023-54403high

Yonyou U8 CRM Path Traversal Flaw Exploited Same Day as Disclosure

CVE-2023-54403, a path traversal vulnerability in Yonyou U8 CRM, was reported as exploited on the same day its CVE record was published. The flaw has no patch window.

CVE-2026-104286high

Fortinet FortiMail Path Traversal Flaw Exploited Same Day as Disclosure

A path traversal vulnerability in Fortinet FortiMail was exploited on the same day it was disclosed, leaving no patch window for affected organizations.

breach

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws…

CVE-2026-86950high

Apple Products Vulnerability Exploited Same Day as Disclosure

A critical out-of-bounds write vulnerability in multiple Apple products was exploited on the same day it was disclosed. Both US and EU government catalogues now list it as actively exploited.

vulnerability

Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

Google's Threat Intelligence Group (GTIG) has reported a significant surge in vulnerability disclosures, with monthly totals more than doubling from January to August of this year. The number of disclosures climbed from 5,045 in January to over 10,000 in both July and August, peaking at 10,740 last month. This increase is attributed by GTIG researchers to the growing influence of artificial…

CVE-2026-76461high

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Cisco has confirmed that attackers are actively exploiting a zero-day SQL injection vulnerability, tracked as CVE-2026-76461, in its Secure Email Gateway appliances. The company's Product Security Incident Response Team became aware of the exploitation in September 2025 and has since provided indicators of compromise for organizations to check for potential breaches.