LIVE · cybersecurity feed
Live wire
vendor

Quest

15 CVEs published in the last four months and 11 stories. Exploited flaws first.

Critical3
High12
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2021-320869.8criticalkace systems management applianceAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.40d ago
CVE-2021-320849.8criticalkace systems management applianceAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.40d ago
CVE-2021-320889.8criticalkace systems management applianceAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.40d ago
CVE-2026-97818.8highnetvault backupQuest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-97828.8highnetvault backupQuest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-97838.8highnetvault backupQuest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-97848.8highnetvault backupQuest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-75698.8highnetvault backupQuest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability.73d ago
CVE-2026-97868.8highnetvault backupQuest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-97878.8highnetvault backupQuest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability.73d ago
CVE-2021-320858.8highkace systems management applianceAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.40d ago
CVE-2021-320878.8highkace systems management applianceAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.40d ago
CVE-2026-97858.8highnetvault backupQuest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-75708.8highnetvault backupQuest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability.73d ago
CVE-2026-97808.8highnetvault backupQuest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability.73d ago

Filter the full tracker by Quest

Our coverage of Quest

patch

The Collective Cyber Defense letter wrote your next vendor questionnaire

More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work. The post The Collective Cyber Defense letter wrote your next vendor questionnaire appeared first on CyberScoop.

security

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems

breach

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group ShinyHunters posted screenshots on its leak site, claiming a bigger win. The incident was preceded by an unusual exchange on X several days earlier. Last we

phishing

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.

breach

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

breachcritical

Frequently asked questions about the active threat to Siemens S7 Series PLCs

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future

vulnerability

GPT-5.6-Cyber refuses security researchers’ requests far less often

GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity professionals. “The GPT‑5.6‑Cyber model is trained to improve performance on certain cybersecurity workflows i

ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

scams

Congress Questions Executive Branch, Allies on Anti-Scam Coordination

US Senators questioned Trump administration officials regarding the coordination between federal agencies and international allies in combating scams. Lawmakers raised concerns about the lack of a central authority overseeing the numerous federal agencies involved and whether current efforts are sufficient to address transnational scam operations. Discussions also touched upon the potential need for a multinational coordination mechanism similar to those used for drug trafficking.

ai

Humans in the loop miss a third of dangerous AI coding agent requests

You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?

openssl

OpenSSL Flaw Allows Denial-of-Service via Small TLS Requests

A denial-of-service vulnerability in OpenSSL, dubbed HollowByte, can be triggered by sending an 11-byte TLS request. This request causes unpatched servers, particularly those using glibc, to allocate up to 131 KB of memory that remains unavailable until the server process is restarted. The fix was released in June without specific disclosure.