Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Required action: Apply mitigations in accordance with vendor instructions, ensuring…
Cyber Signal
Urgent advisories, exploited vulnerabilities and incidents. Current Signal data is server-rendered for readers and search engines, with source attribution and update timestamps.
Cyber Signal
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security…
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk…
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates…
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. Required action: Apply mitigations in accordance…
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to…
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted…
What this Signal is seeing now
CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Required action: Apply mitigations in accordance with vendor instructions, ensuring…
CISA Known Exploited Vulnerabilities Catalog · 18 hours agoCVE-2026-63077 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security…
CISA Known Exploited Vulnerabilities Catalog · 3 days agoCVE-2026-18556 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk…
CISA Known Exploited Vulnerabilities Catalog · 4 days agoCVE-2026-34486 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…
CISA Known Exploited Vulnerabilities Catalog · 4 days agoHow to read this Signal
Signal surfaces source-attributed information and ranks current items using freshness, severity, observed movement and source confidence where those measurements are available. A high ranking identifies attention or consequence; it does not convert an allegation into a fact or a market price into a guaranteed forecast.
Current feed: CISA. Last successful snapshot: August 7, 2026 5:26 pm.
Subscribe to this Signal RSS →