SEKurity GmbH Logo
Home / Categories / CVE & Bug Bounty

CVE & Bug Bounty

Critical vulnerability discoveries, CVE research, and responsible disclosure reports

[21] entries #10 tags

[*] Accessing category: CVE & Bug Bounty
[+] Database query returned 21 results
root@sekurity:~/categories/cve-bug-bounty$ _

01
sekurity-team

InSEKurity of the Week (CW29/2026): SonicWall SMA 1000 Unauthenticated SSRF to Root RCE (CVE-2026-15409 & CVE-2026-15410)

A pair of zero-days in SonicWall's SMA 1000 remote-access appliance -- an unauthenticated CVSS 10.0 SSRF chained to a post-auth root code injection -- is being actively exploited to steal credentials, session databases, and MFA seeds.

02
sekurity-team

InSEKurity of the Week (CW28/2026): Linux KVM Guest-to-Host VM Escape -- Januscape (CVE-2026-53359)

A 16-year-old use-after-free in the Linux KVM shadow MMU lets a root user inside a guest VM escape to the host on both Intel and AMD x86 -- exploited as a zero-day in Google's kvmCTF

03
sekurity-team

InSEKurity of the Week (CW27/2026): Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659)

A deserialization flaw in Microsoft SharePoint Server lets an authenticated low-privilege user run code on the server -- now added to the CISA KEV catalog under confirmed active exploitation

04
sekurity-team

InSEKurity of the Week (CW26/2026): Fortinet FortiSandbox Unauthenticated OS Command Injection (CVE-2026-25089)

A critical OS command injection flaw in the FortiSandbox web GUI lets unauthenticated remote attackers run arbitrary system commands via crafted HTTP requests -- a foothold inside the very appliance built to detonate and analyze malware

05
sekurity-team

InSEKurity of the Week (CW25/2026): Splunk Enterprise Unauthenticated RCE via PostgreSQL Sidecar (CVE-2026-20253)

A missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar service lets unauthenticated attackers create and overwrite arbitrary files -- chained into remote code execution, actively exploited in the wild, and the first Splunk bug ever added to CISA KEV

06
sekurity-team

InSEKurity of the Week (CW24/2026): Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751)

A logic flaw in Check Point Security Gateway's deprecated IKEv1 VPN lets unauthenticated attackers establish a Remote Access VPN session without a valid password -- exploited as a zero-day by a Qilin ransomware affiliate and listed in CISA KEV

07
sekurity-team

InSEKurity of the Week (CW23/2026): Cisco Unified CM WebDialer Unauthenticated SSRF-to-Root (CVE-2026-20230)

Unauthenticated SSRF in the Cisco Unified Communications Manager WebDialer service lets remote attackers write files to the underlying OS and escalate to root -- public exploit code is already available

08
sekurity-team

InSEKurity of the Week (CW22/2026): Windows Netlogon Pre-Auth RCE on Domain Controllers (CVE-2026-41089)

Critical stack-based buffer overflow in Windows Netlogon lets unauthenticated attackers run SYSTEM code on any Windows domain controller over the network -- now under active exploitation

09
sekurity-team

InSEKurity of the Week (CW21/2026): Drupal Core Anonymous SQL Injection (CVE-2026-9082)

An unauthenticated SQL injection in Drupal core's PostgreSQL EntityQuery handler -- anonymous attackers turn JSON object keys and JSON:API filter parameters into raw SQL fragments. Drupal-rated 23/25 'Highly Critical', CISA KEV, 15,000+ exploit attempts in 48 hours

10
sekurity-team

InSEKurity of the Week (CW20/2026): NGINX Rift -- 18-Year-Old Rewrite Module Heap Overflow, Unauthenticated DoS & Potential RCE (CVE-2026-42945)

A size-mismatch bug in the NGINX rewrite module lets a remote, unauthenticated attacker overflow the heap with a single crafted HTTP request -- reliable worker crashes for everyone, potential RCE where ASLR is off. CVSS 4.0 9.2, public PoC, exploited in the wild since 2026-05-16, ~5.7M exposed servers

11
sekurity-team

InSEKurity of the Week (CW19/2026): Palo Alto PAN-OS User-ID Portal Unauthenticated Root RCE (CVE-2026-0300)

A buffer overflow in the PAN-OS User-ID Authentication Portal lets a remote, unauthenticated attacker pop a root shell on PA-Series and VM-Series firewalls -- CVSS 9.3, CISA KEV, actively exploited by a likely state-sponsored cluster (CL-STA-1132)

12
sekurity-team

InSEKurity of the Week (CW18/2026): Linux Kernel "Copy Fail" Privilege Escalation (CVE-2026-31431)

A nine-year-old logic bug in the Linux kernel's algif_aead crypto module lets any local user write 4 bytes into the page cache of any readable file -- root, container escape, no race condition, public PoC

13
sekurity-team

InSEKurity of the Week (CW17/2026): Windows TCP/IP IPv6 + IPsec RCE (CVE-2026-33827)

Critical pre-auth race condition in the Windows TCP/IP stack lets remote attackers run code over IPv6 against any IPsec-enabled host -- wormable, no credentials, no user interaction

14
sekurity-team

InSEKurity of the Week (CW16/2026): Windows IKE Extensions RCE (CVE-2026-33824)

Critical pre-auth double free in the Windows IKE Service Extensions (IKEEXT.dll) lets remote attackers reach SYSTEM over UDP/500 and UDP/4500 -- wormable, public PoC already online

15
sekurity-team

InSEKurity of the Week (CW15/2026): Cisco IMC Authentication Bypass (CVE-2026-20093)

Critical pre-authentication flaw in Cisco Integrated Management Controller lets remote attackers reset any admin password and seize full out-of-band control of UCS servers

16
sekurity-team

InSEKurity of the Week (CW14/2026): FortiClient EMS Unauthenticated Remote Code Execution (CVE-2026-35616)

Critical improper access control vulnerability in Fortinet FortiClient EMS actively exploited as zero-day - Unauthenticated API bypass leads to remote code execution

17
sekurity-team

InSEKurity of the Week (CW13/2026): Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-20129)

Critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager actively exploited - Unauthenticated access with netadmin privileges possible

18
sekurity-team

InSEKurity of the Week (CW07/2026): Windows Shell SmartScreen Bypass Zero-Day (CVE-2026-21510)

Critical zero-day vulnerability in Windows Shell allows attackers to bypass SmartScreen and Mark of the Web protections through a single malicious click

19
sekurity-team

InSEKurity of the Week (CW06/2026): OpenClaw AI Agent 1-Click RCE (CVE-2026-25253)

Critical vulnerability in OpenClaw AI Agent enables Remote Code Execution with just one click - Authentication token exfiltration through manipulated URLs

20
sekurity-team

InSEKurity of the Week (CW04/2026): Cisco Unified Communications Manager Zero-Day (CVE-2026-20045)

Critical zero-day vulnerability in Cisco Unified Communications Manager and Webex actively exploited - Root access via code injection possible

21
sekurity-team

InSEKurity of the Week (CW03/2026): Node.js node-tar Path Traversal (CVE-2026-23745)

Critical path traversal vulnerability in node-tar allows arbitrary file overwrite through manipulated hardlinks and symlinks in TAR archives

root@sekurity:~/categories/cve-bug-bounty$ echo "Query complete"
Query complete
root@sekurity:~/categories/cve-bug-bounty$ _