LIVE · cybersecurity feed
Latest
Archive
CVE Tracker
Report
Ransomware
Vulnerability
Breach
Malware
Nation-state
Phishing
Zero-day
AI
Cloud
Live wire
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
vendor
Lmsys
12 CVEs published in the last four months. Exploited flaws first.
Critical
9
High
3
Medium
0
Exploited (KEV)
0
All recent CVEs
CVE
CVSS
Severity
Product
Summary
Published
CVE-2026-15976
9.8
critical
sglang
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifica
37d ago
CVE-2026-3059
9.8
critical
sglang
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker
177d ago
CVE-2026-3060
9.8
critical
sglang
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the d
177d ago
CVE-2026-7301
9.8
critical
sglang
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink tha
110d ago
CVE-2026-15969
9.8
critical
sglang
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete
37d ago
CVE-2026-15971
9.8
critical
sglang
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape
37d ago
CVE-2026-7304
9.8
critical
sglang
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-cust
110d ago
CVE-2026-7302
9.1
critical
sglang
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an
110d ago
CVE-2026-14890
9.1
critical
sglang
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface
51d ago
CVE-2026-3989
7.8
high
sglang
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization.
177d ago
CVE-2026-15977
7.5
high
sglang
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SS
37d ago
CVE-2026-15978
7.5
high
sglang
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose t
37d ago
Filter the full tracker by Lmsys →