LIVE · cybersecurity feed
Latest
Archive
CVE Tracker
Report
Ransomware
Vulnerability
Breach
Malware
Nation-state
Phishing
Zero-day
AI
Cloud
Live wire
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
vendor
Wso2
7 CVEs published in the last four months. Exploited flaws first.
Critical
3
High
4
Medium
0
Exploited (KEV)
0
All recent CVEs
CVE
CVSS
Severity
Product
Summary
Published
CVE-2026-5430
10
critical
api control plane
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or su
30d ago
CVE-2026-1728
9.8
critical
api control plane
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-
30d ago
CVE-2025-15039
9.4
critical
api control plane
The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all r
30d ago
CVE-2026-4249
8.6
high
api control plane
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without suffi
61d ago
CVE-2025-10470
8.6
high
identity server
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting
117d ago
CVE-2026-2053
8.3
high
api manager
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validat
71d ago
CVE-2025-10908
7.3
high
identity server
Due to a lack of user account state validation during authentication, locked user accounts can be successfully aut
117d ago
Filter the full tracker by Wso2 →