Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.
CTI status
As of:
Last pipeline run:
Full list, filterable by severity, tag and KEV status, sortable by relevance, EPSS, CVSS or date.
Source reliability
Information credibility
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.
CISA has added CVE-2025-25249 to the Known Exploited Vulnerabilities (KEV) catalog and prioritizes this security issue under BOD-26-04 guidance, setting a remediation deadline of 2026-09-12.
Two Windows EoP zero-days (ALPC, Update Stack) with active exploitation are addressed in Microsoft Patch Tuesday September 2026; CVSS 7.8 may understate operational risk for systems vulnerable to locally-exploitable privilege-escalation vectors.
Threat actors are deliberately targeting inadequately monitored perimeter edge devices to gain initial access via these vulnerabilities and deploy post-exploitation tools such as PivotC2.
Adobe releases a patch roundup report covering 170+ vulnerabilities without describing an active exploitation campaign or targeted attacks.
The alert provides no details on active exploitation, affected versions, or patch urgency , it is a generic patch announcement without context on threat activity or deployment timeline.
A CVSS-10.0 vulnerability in SAP Extended Passport Processing enables complete remote code execution without authentication and requires immediate patch implementation for all SAP instances.
An integer-overflow vulnerability in Adobe Photoshop's JPEG processing enables remote code execution upon user interaction and is listed in the CISA KEV catalogue.
Integer-overflow vulnerability in DCM file parsing enables remote code execution with user interaction, rated CVSS 7.8 critical severity.
RCE vulnerability in Adobe Photoshop during JPEG-LS image processing requires user interaction (visiting a malicious page or opening a malicious file).
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution upon user interaction with malicious PDF files or web pages.
Use of Adobe Acrobat Reader DC requires prompt patch prioritization, as RCE exploitability is present via file-opening vectors.
Adobe Acrobat Reader DC is vulnerable to Use-After-Free RCE in annotation processing; attack requires user interaction (file opening or web visit).
A use-after-free vulnerability in Adobe Acrobat Pro DC enables remote code execution via malicious files or web pages with CVSS 7.8, requiring user interaction.
Use-After-Free vulnerability in PDF annotation functionality enables remote code execution upon opening a malicious PDF or visiting a malicious website; CVSS 7.8 indicates high exploitability.
Use-After-Free vulnerability in annotation functionality enables remote code execution when visiting malicious pages or opening crafted files,relevant for organizations using Acrobat Pro DC in design and document workflows.
A use-after-free vulnerability enables remote code execution in Adobe Acrobat Reader DC with user interaction, presenting direct risk to organizations using this PDF reader.
Type confusion vulnerability in Adobe Acrobat Reader DC enables remote code execution through opening malicious PDFs or visiting prepared web pages.
Integer overflow vulnerability in Adobe Acrobat Pro DC's JPEG parser enables remote code execution when users open a malicious file or visit a malicious page.
An out-of-bounds write vulnerability in Adobe Acrobat Reader DC enables remote code execution upon user interaction with a high CVSS score of 7.8.
A Use-After-Free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction (visiting a malicious page or opening a malicious file).
No additional strategic information beyond patch announcement available; merely technical CVE classification without context of active exploits or campaigns.
Sensitive information hardcoded in source code allows unauthorized access to FortiMonitor instances; vague attack vector details suggest incomplete CVE documentation.
The vulnerability allows attackers to persistently manipulate network proxy settings via malicious add-ins and intercept authenticated Fusion user connections without user awareness.
An authorization flaw in Adobe Acrobat Reader enables privilege escalation without user interaction, significantly easing exploitation by locally present attackers.
Prototype pollution vulnerability in Adobe Acrobat Reader enables arbitrary file read via opened PDFs , requires user interaction but poses risk to PDF workflows.
The vulnerability enables arbitrary code execution through malicious PDF files but requires user interaction; there are no indicators of active exploitation in the wild.
The vulnerability requires user interaction via opening a malicious file; endpoint protection and file validation training are critical.
The vulnerability enables code execution in user context via malicious files, but requires active user interaction when opening the file.
A vulnerability in Adobe Illustrator enables arbitrary code execution through incorrect authorization controls, but requires user interaction to open a malicious file.
The CVE describes network-based remote code execution in a core Windows service; no evidence of active exploitation or public PoC has yet emerged.
CVE-2026-83998 is a network-exploitable remote code execution vulnerability in Remote Desktop Client that allows unauthenticated attackers to execute code , critical for RDP-based remote access infrastructure.
A heap overflow in Windows Imaging Component enables remote code execution over the network without authentication , this is a critical, immediately patchable risk for all Windows Server installations.
An authorization bypass in Entra ID allows authenticated attackers to escalate privileges across the network, critically compromising identity infrastructure.
Remote code execution over the network in a critical system component with high exploitation potential on Windows Server 2022/2019 infrastructure.
A heap-overflow vulnerability in Microsoft Word allows unauthenticated remote code execution over the network , affected organizations should check for available patches and increase monitoring of email-based attack vectors (Office attachments).
Remote code execution vulnerability in Microsoft Office Publisher via unsafe deserialization enables arbitrary code execution over the network.
Network-exploitable heap overflow in Windows Codecs Library enables remote code execution without user interaction on standard Windows Server systems.
The out-of-bounds read in Remote Desktop Services allows an authorized attacker on the network to escalate privileges without additional exploits.
The vulnerability enables remote code execution over the network, which poses a critical attack vector for manufacturing environments where Office documents are frequently exploited as an initial entry point.
A use-after-free vulnerability in PowerPoint enables unauthenticated remote code execution over the network,critical for production environments with Office deployment.
A double-free vulnerability in Microsoft Word enables remote code execution over the network without user interaction; critical for organisations processing Word documents from external sources.
Remote Desktop Protocol is a direct attack vector for external attackers; network-based RCE without authentication acutely endangers critical infrastructure in production environments.
A heap-based buffer overflow vulnerability in Remote Desktop Client enables unauthenticated remote code execution over the network.
Network-exploitable RCE in Microsoft Word allows unauthenticated code execution; particularly critical in production environments where Office documents are frequently processed.
A use-after-free vulnerability in Outlook enables unauthorized remote code execution over the network without requiring user interaction.
It is unclear whether this alert describes active exploitation in the wild or merely a patch announcement without operational details on attack scenarios or affected sectors.
Vulnerability enables unauthenticated remote code execution on Windows Message Queuing instances over the network.
Authenticated remote code execution in Fortinet FortiSandbox via command injection allows attackers to compromise systems where the product is deployed.
The vulnerability enables unauthenticated access to AD accounts by exploiting RFC 4513-compliant LDAP implementations that accept anonymous binds.
A patch for CVE-2026-69414 (ShieldBreak) has not fully remediated the issue; the researcher demonstrated with ShieldCrash that the vulnerability can still be triggered under specific conditions and arbitrary files can be read with SYSTEM privileges.
Beyond the plain patch information, the alert provides no evidence of active exploitation; the flaw allows reading local files and is fixed in version 23.4.88.1429.
The vulnerability requires user interaction to upload a malicious driver and is not documented in active attack scenarios to date.
Denial-of-service vulnerability in Windows Key Distribution Center allows unauthorized attackers to disrupt Kerberos authentication in Active Directory environments.
The GRU actor Sandworm is chaining Cisco vulnerabilities to spread an upgraded Cyclops Blink variant and maintain persistent control over compromised network devices.
APT29 leverages generative AI systems to automate malware regeneration after detection, undermining static detection mechanisms, and compromises supply-chain infrastructure (hospitality vendors) for network manipulation.
Coordinated exploitation of a chain of zero-day vulnerabilities by Chinese espionage groups signals elevated threat to Western infrastructure and supply chains, with ongoing and expanding activity.
Multiple state-sponsored APT groups, including China-aligned APT31, are deploying a newly discovered exploit kit (BlueMoon) that chains multiple Windows and Chrome vulnerabilities to compromise targets in Western countries.
Low-severity vulnerability (CVSS 3.3) in Adobe Acrobat Reader DC with information disclosure potential through malicious PDF files, requires user interaction.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables information disclosure through malicious PDF or font files.
Russian state-linked actors are weaponizing commercial AI tools like Claude for targeted cyber-espionage against Western government and defense organizations, signaling strategic escalation of hybrid warfare with DACH implications.
Anthropic report demonstrates that AI tools enable smaller actors to conduct state-level hacking campaigns; documented cases include Russian-aligned espionage against 20+ organizations and Chinese exploit development, with relevance to European supply chains and critical infrastructure.
Russian-Ukrainian cyber operations escalate with sophisticated multi-payload delivery chains; security teams in DACH must prepare for similar techniques (WebDAV abuse, stealer distribution).
A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.
EU cybersecurity legislation establishes mandatory reporting obligations for actively exploited vulnerabilities within 24 hours effective immediately, signaling significant regulatory tightening for European organizations with comprehensive enforcement by December 2027.
The Rhysida attack on Berlin reveals systematic security gaps in the defensive architecture of critical German infrastructure that serves as a warning signal for other DACH organizations.
The alert provides only minimal information about the vulnerability itself (heap overflow in Windows Error Reporting) and contains no indication of active exploitation or specific attack campaigns.
The vulnerability requires already-authorized local access and is primarily a privilege-escalation risk within hypervisor-based infrastructures; no evidence of active exploitation in the wild.
The vulnerability enables information disclosure over the network through exploitation of uninitialized resources in Office; details on active exploitation or PoC availability are not documented.
Out-of-bounds read vulnerability in Microsoft Word enables information disclosure over the network; no further details on active exploitation or bypass available.
An out-of-bounds read in Microsoft Office enables unauthorized information disclosure over the network; availability via NVD indicates an already-documented vulnerability.
The vulnerability enables unauthorized access to memory contents via network vectors, presenting a data disclosure risk beyond typical Office exploits.
No strategic insight beyond standard patch notification; the alert describes a single generic CVE without context to active attack scenarios or targeting.
An out-of-bounds read vulnerability in PowerPoint enables unauthorized disclosure of confidential information over the network, which is particularly critical for manufacturing-related technical documentation and design presentations.
CVE-2026-80084 enables unauthorized disclosure of sensitive information through an out-of-bounds read in Outlook and could expose business communications.
An out-of-bounds read vulnerability in Microsoft Office allows an attacker to disclose sensitive information over the network without authentication.
The vulnerability enables unauthorized access to sensitive information across the network via manipulated Word documents without requiring authentication.
The vulnerability enables unauthorized information disclosure over the network and could be leveraged for reconnaissance prior to targeted attacks.
A memory disclosure vulnerability in Microsoft Office enables remote information disclosure without authentication, which is particularly critical when office documents serve as attack vectors.
The vulnerability allows an attacker to remotely read sensitive information from Outlook memory without authentication, enabling information disclosure attacks.
An authentication vulnerability in Microsoft Authenticator enables local privilege escalation by unauthenticated attackers, increasing the risk of lateral movement on devices with Authenticator integration following compromise.
The report provides no information beyond the patch details about active exploitation or new attack vectors.
Russian state-sponsored hacker groups directly targeted AI vendor infrastructure and leveraged Claude to automate malware evasion techniques, signaling a new attack model against cloud service providers and their customers.
AI-driven automation lowers the entry barrier for resource-constrained attackers to achieve nation-state-equivalent capabilities in vulnerability discovery and malware development, fundamentally escalating threat posture across all sectors.
Multiple China-linked state-sponsored hacking groups actively exploiting the same Chrome zero-day suggests coordinated or centrally-directed cyber-espionage against Western infrastructure.
The report provides no information beyond the plain CVE description; there is no indication of active exploitation, a PoC, or threat actors.
A local privilege escalation in Windows Secure Kernel Mode allows authenticated attackers to elevate their privileges on affected systems.
The vulnerability requires local access by an authorized attacker, limiting the risk to insider threats and compromised workstations.
Pure vulnerability report with no indication of active exploitation, PoC, or attacker TTPs.
Beyond the pure patch information, the report provides no indications of active exploitation, threat actor groups, or affected victim sectors.
A local heap buffer overflow vulnerability in Adobe Acrobat Reader enables arbitrary code execution through opening a malicious PDF file without requiring additional system privileges.
The vulnerability requires user interaction (opening a malicious file), which elevates the risk from phishing and social-engineering attacks.
A Use-After-Free vulnerability in Adobe Acrobat Reader enables arbitrary code execution through opening a malicious file, posing a direct threat to production environments processing PDFs.
The vulnerability requires user interaction (opening a malicious PDF file) and could enable attackers to execute code with user privileges; relevance depends on actual exploitation in active attack campaigns.
This vulnerability enables remote code execution through opening manipulated PDF files,a common attack vector in manufacturing environments where technical documentation and CAD files are distributed as PDFs.
The vulnerability requires user interaction (opening a malicious file) and affects a widely deployed PDF application in production environments.
The NVD alert documents a Use-After-Free vulnerability in Acrobat Reader with RCE potential, but requires user interaction (opening a malicious file) and provides no indication of active exploitation or in-the-wild exploits.
The vulnerability requires user interaction through opening a malicious file and could be exploited in targeted phishing campaigns against manufacturing organizations.
The vulnerability requires user interaction (opening a malicious file) and could serve as an entry point for locally-triggered attacks in manufacturing environments that rely on PDF-based design or process documentation.
This vulnerability requires user interaction (opening a malicious file) and affects a widely deployed application in the manufacturing environment; targeted attacks via manipulated PDFs are a realistic scenario.
The vulnerability requires user interaction (opening a malicious file) and could result in complete system compromise upon successful exploitation if Acrobat Reader runs with elevated privileges.
The vulnerability requires user interaction (opening a malicious PDF), pointing to heightened phishing and social-engineering risk, especially in manufacturing environments with frequent document exchange.
The vulnerability requires user interaction (opening a malicious PDF), suggesting phishing or social-engineering scenarios.
The vulnerability requires user interaction to open a malicious file, which limits exploitability in a managed corporate environment but necessitates awareness training and strict document validation policies.
The vulnerability requires user interaction (opening a malicious file) and is therefore primarily mitigated by technical controls (file blocking, sandboxing) and security awareness, not patching alone.
The vulnerability requires user interaction (opening a malicious file), which increases risk in a manufacturing environment with document-intensive workflows involving technical drawings and PDFs.
The vulnerability requires user interaction to open a malicious PDF file and could be exploited for targeted spear-phishing campaigns against organizations using Acrobat Reader.
The vulnerability requires user interaction (opening a malicious file), which limits the risk in a production environment to phishing or social-engineering scenarios.
The vulnerability requires user interaction (opening a malicious file) and is likely introduced into creative workflows via manipulated project files or malicious PDF/EPS files.
The vulnerability requires user interaction (opening a malicious file) and affects local code execution within the current user's context.
The vulnerability requires user interaction (opening a malicious file) and could be exploited via spear-phishing or supply-chain attacks targeting design workflows in manufacturing environments.
The vulnerability requires user interaction (opening a malicious file) and thus presents a targeted attack vector potential against engineers or designers in manufacturing companies.
The vulnerability enables attackers to execute arbitrary code by tricking users into opening a malicious file, requiring only user interaction with a crafted document.
An integer overflow vulnerability in Adobe Photoshop Desktop enables arbitrary code execution if a user opens a malicious file , relevant for organizations with designers and CAD specialists.
An out-of-bounds write vulnerability in Adobe Photoshop enables code execution but requires the user to open a malicious file; no active exploitation reports are documented.
The vulnerability requires local authentication and affects the Graphics Component in Windows systems, posing a risk to workstations and servers running graphical applications.
Without information on active exploitation or PoC availability, it cannot be determined whether this vulnerability is already being leveraged in attack scenarios or represents only routine patch guidance.
Local privilege escalation requires pre-authenticated access; risk concentrates on scenarios with privileged insider threats or compromised user sessions on Windows Server systems.
NVD reports a local privilege escalation flaw in a Windows system service; without proof-of-concept or active exploitation, this is currently a patch-management matter for existing systems.
Although the vulnerability requires local authentication, it provides an authorized attacker with a direct path to system privilege escalation on Windows Servers.
This vulnerability requires local access and authentication, making it primarily relevant as a risk for insider threats and post-compromise scenarios.
Local privilege escalation on Windows Servers by authenticated attackers with file system access presents a risk for insider threat scenarios and lateral movement.
A local privilege escalation in the Windows Kernel allows authorized attackers to elevate to SYSTEM-level rights, indicating either compromised internal accounts or physical access scenarios.
Local privilege escalation in Windows VBS Enclaves allows authorized attackers to gain elevated access to sensitive hypervisor functions.
The vulnerability enables local code execution through a heap-based buffer overflow in Excel, but requires either local access or social engineering to open a malicious file.
Locally exploitable heap overflow in Excel enables code execution in the context of the logged-in user; critical for manufacturing environments that use Excel for calculations and CAD integration.
Out-of-bounds read in Excel enables local code execution through specially crafted files; relevant for manufacturing enterprises using Excel-based processes (design, planning, data processing).
Out-of-bounds read vulnerability in Excel enables local code execution via malicious spreadsheets; risk when opening untrusted files.
Locally exploitable stack buffer overflow in Excel poses risk to systems with direct file access , relevant threat for manufacturing environments with CAD/design workflows.
A heap-based buffer overflow with local code-execution capability represents a classic high-risk profile for desktop-based attacks; the CVE indicates current exploitability, and exploit availability and escalation paths should be monitored.
Integer overflow vulnerability in Excel enables local code execution through file opening; relevant attack vectors in manufacturing environments with file shares or email attachments.
Heap-based buffer overflow in Microsoft Excel enables local code execution via manipulated documents; risk amplified by automatic file processing and document exchange workflows.
The vulnerability enables local code execution through malicious Excel files and poses a risk if employees open untrusted documents.
Heap-based buffer overflow in Microsoft Excel enables local code execution through manipulated file handling, relevant for environments with automated Excel processes and integrated workflows.
The vulnerability enables local code execution via a malicious Excel file and could be leveraged as a vector for malware distribution or privilege escalation in manufacturing-oriented environments.
Stack-based buffer overflow in Excel enables local code execution; no indication of active exploitation or ransomware campaigns, but relevant for manufacturing operations using Excel for documentation and automated process integration.
A local stack-based buffer overflow in Microsoft Excel enables unauthorized attackers to execute code on affected systems without additional authentication.
A locally exploitable heap overflow in Excel enables unauthorized code execution and could be leveraged by attackers via weaponized files in phishing or supply-chain scenarios.
The vulnerability enables local code execution through the Windows Codecs Library and could be exploited by locally authenticated attackers or for privilege escalation after initial compromise.
Privilege escalation via local buffer overflow in Windows Work Folders affects systems in production environments with active sync service.
Chrome 153.0.8010.36/.37 patches one actively exploited medium-severity vulnerability and five critical flaws, including four in WebGL, enabling remote code execution.
The ShieldCrash exploit enables privilege escalation to System privileges on Windows systems with September 2026 patches and has publicly available PoC code.
The critical vulnerabilities allow unauthenticated attackers to bypass authentication using forged JWTs and proxy user browser traffic if users visit malicious websites,a direct risk to privileged access management.
Both zero-days are local privilege-escalation vulnerabilities that can escalate existing low-privilege code execution to SYSTEM rights , typically relevant as a second stage in exploit chains or post-compromise scenarios.
Two of the 974 CVEs are already being actively exploited and have highest priority, while the remaining 114 critical vulnerabilities are distributed through bundled update packages per product.
A zero-day in Microsoft Defender enables local privilege escalation to SYSTEM rights and represents a serious threat to organizations relying on Defender as a protection layer.
This is a patch roundup aggregating 974 independent CVEs without describing a specific active attack campaign; however, the two actively exploited zero-days require immediate patching to limit exposure.
The security updates address two actively exploited zero-days plus 20 potentially wormable vulnerabilities, requiring prioritization in patch deployment.
The vulnerability enables local code execution via memory management flaw in Excel; attackers can execute arbitrary code through manipulated files (e.g. in supply-chain scenarios via email or shared drives).
A double-free vulnerability in Microsoft Excel allows unauthenticated local code execution; in a manufacturing environment with heavy reliance on Excel for ERP and CAD data processing, this poses significant risk.
The vulnerability requires high privileges and user interaction for successful exploitation, which limits the practical attack risk in controlled corporate environments.
Use-after-free vulnerability in Windows Kernel enables local privilege escalation by authorized attackers; the alert is based solely on NVD patch data with no indication of active exploitation or targeted campaigns.
This is a pure patch notification with no new insights into active attacks or exploitation in the wild.
The vulnerability requires local authenticated access and is therefore primarily relevant for post-compromise scenarios where an attacker already has access to a system and seeks to escalate privileges.
The alert confirms a heap overflow vulnerability in Excel with local execution capability, but provides no evidence of active exploitation or APT campaigns in production environments.
BlueMoon kit actively exploits previously unpatched zero-days in Windows and Chrome, requiring immediate defensive readiness.
Critical authentication bypass vulnerability (CVSS 10.0) is actively exploited by ransomware operators (UAT-11988) who gain initial access via static credentials and abuse legitimate tooling for reconnaissance and lateral movement.
An authorization vulnerability in Adobe Acrobat Reader allows attackers to bypass security features and gain unauthorized write access when a user opens a malicious file.
Auth0 AD/LDAP Connector versions up to 6.5.0 expose Active Directory service account credentials in plaintext locally without authentication, enabling lateral movement from compromised local user accounts.
The vulnerability enables arbitrary code execution outside the sandbox by an adjacent attacker using crafted network traffic , a significant risk for Chrome-based systems.
A sandbox bypass in Chrome WebGL enables attackers to execute code outside the browser sandbox, increasing the risk of full system compromise via crafted web pages.
The vulnerability enables arbitrary code execution outside the browser sandbox via a crafted HTML page, suggesting potential active exploitation.
A code-execution vulnerability in 7-Zip can be exploited by remote unauthenticated attackers and requires immediate patching.
BSI warning regarding critical remote code execution vulnerability in FortiOS with immediate implications for the company's perimeter security.
BSI alert on critical SAP vulnerabilities across multiple products; specific CVE numbers and affected versions are required for prioritized patch planning.
The BSI warning indicates multiple critical vulnerabilities in the Azure/Entra identity platform affecting authentication, authorization, and code execution,a core infrastructure for Microsoft 365 environments.
Adobe Commerce vulnerability is already under active exploitation; Experience Manager contributes significantly to patch burden with 107 vulnerabilities patched.
The vulnerability requires user interaction (opening a malicious file) and targets memory disclosure rather than direct code execution.
The vulnerability requires user interaction (opening a malicious file) and affects a widely deployed product used in document management.
The vulnerability requires user interaction through opening a malicious file and could lead to disclosure of sensitive memory contents, posing an information disclosure risk in typical office environments.
The vulnerability enables disclosure of sensitive memory contents by opening a malicious PDF file, which is relevant for targeted attacks against production environments with critical CAD data or business documents.
The vulnerability requires user interaction and primarily affects confidentiality through memory disclosure rather than system integrity or availability.
The vulnerability requires user interaction (opening a malicious file) and leads to memory disclosure rather than direct code execution , risk is mitigated by basic phishing awareness and regular patching.
The vulnerability requires user interaction (opening a malicious file) and results in memory disclosure rather than code execution; risk is moderate in environments with endpoint protection.
The vulnerability requires user interaction (opening a malicious file) and leads to memory disclosure rather than direct code execution; risk depends on file controls and user awareness.
None; this is a pure patch notification without active campaign or novel technical findings.
The vulnerability requires local access and enables only information disclosure, not remote code execution or system compromise; relevance is limited to scenarios where local system access is already compromised.
Local buffer over-read vulnerability in Word can lead to disclosure of confidential documents, particularly concerning in development and engineering environments with sensitive design files.
A local buffer over-read vulnerability in Microsoft Word enables memory disclosure; its relevance depends on whether active exploitation in-the-wild is documented or whether this is a patch advisory only.
This is a standard Excel security update with no evidence of active exploitation or coordinated campaign; the assessment is based on NVD metadata without additional investigative substance.
The vulnerability enables local information disclosure through type confusion in Excel and requires user interaction; no remote code execution, but relevant risk for data theft when processing trusted files.
Out-of-bounds read vulnerability in Excel enables local disclosure of sensitive data through improper memory handling; attack vector typically requires malicious files or manipulated content.
A local buffer over-read vulnerability in Excel enables information disclosure through a local threat actor; the vulnerability requires local execution privileges and is addressed in Microsoft security updates.
The vulnerability enables local information disclosure through improper memory access in Excel and requires local system access.
A local information disclosure in Excel allows unauthorized access to sensitive system data without network access; relevant for environments with shared workstations or user privilege escalation.
This vulnerability requires local access and enables only information disclosure without remote execution; priority is lower than critical RCE flaws, but should be considered in access controls for Excel usage.
The vulnerability allows local disclosure of memory contents through crafted Excel files, which could lead to data extraction when processing design or business-critical spreadsheets.
The vulnerability enables local information disclosure through uninitialized resource manipulation in Excel, but requires local access and is not remotely exploitable.
Out-of-bounds read in Excel enables local disclosure of sensitive information; relevant for organizations using Excel in design (CAD/PDM), financial accounting, or ERP environments.
The vulnerability enables local exposure of system information without authentication, but affects only local attackers and thus represents an escalation vector following prior compromise.
Critical vulnerability in PAN-OS XML processing enables unauthenticated access to management and dataplane interfaces, with root-level code execution on PA-Series; Panorama affected.
BSI warning on multiple critical GNU libc vulnerabilities without specific CVE disclosure suggests coordinated release or ongoing patch cycle , urgency depends on patch status.
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.
Beyond the plain patch information, the report adds no new insight: there is no indication of active exploitation, nor any details on TTPs or affected sectors.
The report shows that even phishing-resistant passkeys can be bypassed through social engineering and abused email delivery infrastructure to take over Microsoft cloud accounts.
The vulnerability enables authentication bypass in PLC systems through incorrect implementation of authentication algorithms, which is particularly critical for legacy or lower application levels.
The BSI advisory describes multiple vulnerabilities in GNU libc without specific CVE numbers, which may indicate coordinated disclosure or an incompletely documented vulnerability series.
The Bluemoon exploit kit is actively used by Chinese hackers against Windows users and poses an immediate threat to manufacturing environments.
Heise reports on SAP patch day with multiple critical vulnerabilities but does not name active attacks or exploit code; typical patch reminder reporting without evidence of wild exploitation.
The BSI warns of multiple vulnerabilities in Adobe Acrobat/Reader enabling a broad range of attack scenarios, though specific CVE numbers or version details are not provided in this alert.
BSI warning regarding multiple Chrome vulnerabilities without specific CVE identification or patch-status details; typically an aggregated update advisory.
A Russian threat actor group is using AI-generated exploits to automate and scale attacks against hundreds of PaperCut instances worldwide, combined with active post-exploitation for remote code execution and credential harvesting.
Attackers use voice phishing on personal devices to gain Microsoft 365 access and then abuse the Graph API for large-scale data exfiltration, threatening conventional BYOD policies.
Threat actors are leveraging AI-powered techniques to craft highly convincing spoofed emails impersonating internal executives, enabling large-scale campaigns distributing over one million fraudulent messages.
Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.
The BSI advisory covers multiple OpenSSH vulnerabilities without specifying CVE numbers or affected versions; precise identification of affected versions and exploitability status is required.
BSI advisory on systemd vulnerabilities without specification of individual CVE IDs; patch status and active exploitation remain unclear.
Two critical vulnerabilities in Check Point firewalls enable unauthenticated remote code execution through faulty VPN certificate handling, indicating systemic risks in TLS/PKI validation in enterprise security appliances.
BSI warns of multiple vulnerabilities in FortiSandbox enabling remote code execution or information disclosure; specific CVE IDs and affected versions are detailed in the BSI advisory.
The article is a patch announcement for multiple independent ICS vendors without description of an active attack scenario or targeted campaign.
BSI warning on multiple unnamed vulnerabilities in FortiOS/FortiProxy with DoS and information disclosure potential , specific CVE numbers and CVSS scores are missing, making patch prioritization difficult.
An authenticated remote vulnerability in FortiManager enables the bypass of security controls, endangering the central management layer of Fortinet infrastructures.
BSI warning on multiple vulnerabilities in Adobe Acrobat and Reader without specific CVE identifiers; patch status and availability must be obtained from the vendor.
BSI warning regarding multiple Microsoft Office vulnerabilities with potential for privilege escalation and code execution; specific CVE details and patch status require consultation of the full BSI advisory.
The malware uses in-memory injection to evade disk-based scanning , an indicator of targeted attacks against organisations with security monitoring.
BSI warns of multiple local Intel processor vulnerabilities enabling privilege escalation and data compromise , affects server and endpoint infrastructure running Intel CPUs.
BSI warning on multiple OpenSSL vulnerabilities with broad impact on encryption, authentication, and availability , requires verification of deployed OpenSSL versions in the infrastructure.
BSI warns of multiple vulnerabilities in Chrome and Edge enabling active exploitation via malicious websites,standard browser protection for employees required.
Unauthenticated attackers can disclose sensitive information via OAuth Device Code Grant flows in Entra ID; threat to identity security and access control.
Sandbox-escape capability enables code execution outside Chrome sandbox; standard CVE advisory with no indication of active exploitation.
An out-of-bounds read vulnerability in Chrome's WebGL engine enables an attacker to bypass the sandbox and execute arbitrary code outside the sandbox context,a critical risk for endpoints running Chrome.
The vulnerability requires an already-compromised renderer process and could bypass the Chrome sandbox , a two-stage attack on Windows systems.
The vulnerability enables sandbox escape via crafted HTML pages, allowing attackers to gain system access with Chrome process privileges , beyond typical browser exploits.
A sandbox-escape vulnerability enables code execution outside the Chrome sandbox, but requires prior renderer process compromise and social engineering.
This is a standard security patch notification with no evidence of active exploitation or specific campaigns; the vulnerability requires renderer compromise as a prerequisite.
The vulnerability enables sandbox escape via XML type confusion, potentially allowing code execution with elevated privileges upon successful exploitation.
This is a sandbox-escape vulnerability in the ANGLE rendering engine that allows attackers to execute code outside Chrome's sandbox, thereby breaking the browser's process isolation.
The vulnerability requires prior compromise of the renderer process, elevating risk through multi-stage exploits in real-world attack scenarios.
A sandbox-escape vulnerability in Chrome extensions enables remote code execution with elevated privileges beyond normal capability, significantly increasing infection risk from malicious web content.
Active exploitation in the wild or campaign context is not described in the alert; this is a standard vulnerability announcement without additional strategic context.
The vulnerability allows an attacker with renderer process access to execute code outside the Chrome sandbox , a sandbox escape that could lead to arbitrary system-level code execution if successfully exploited.
An out-of-bounds read vulnerability in the ANGLE graphics engine enables memory access outside the browser sandbox and could expose memory contents; the vulnerability is rated High severity and requires timely update to Chrome 153.0.8010.36 or later.
A use-after-free vulnerability in the V8 JavaScript engine enables attackers to achieve remote code execution within the Chrome sandbox via crafted HTML pages.
A double-free vulnerability in Chromium's PDF engine enables remote code execution within the browser sandbox via crafted PDF files,a direct attack vector exploitable through social engineering.
The vulnerability allows an attacker with control over the renderer process to execute code outside Chrome's sandbox, bypassing browser-based exploit mitigations.
The vulnerability allows attackers with network access to bypass Chrome's sandbox and execute arbitrary code on affected systems , a significant risk for all browser users.
A type confusion bug in the V8 engine enables memory reading within the Chrome sandbox without full sandbox escape; this represents an active attack vector against browser users.
A vulnerability in Chrome's LocalNetworkAccess mechanism allows an attacker with renderer process access to bypass system resource access restrictions via a crafted HTML page.
The vulnerability enables sandbox escape via incorrect filesystem reference resolution and requires active social engineering; however, there is no evidence of active exploitation in the wild.
The vulnerability enables sandbox escape and potentially system access on endpoints running Chrome , relevant for phishing campaigns using crafted HTML pages.
This vulnerability requires a prior successful renderer process compromise as a prerequisite and is thus more of a follow-up step in a multi-stage attack than a direct initial compromise vector.
Use-after-free in V8 enables sandbox bypass with arbitrary code execution,not merely local privilege escalation, but complete browser compromise through remote attack via crafted HTML.
The vulnerability allows local attackers with existing access to the Windows system to execute arbitrary code outside the browser sandbox through an improper search path in the CredentialProvider component.
Type confusion in Chrome's Rust implementation enables sandbox escape and remote code execution through crafted HTML pages.
The vulnerability allows an attacker with access to the renderer process to execute code outside the sandbox , a classic sandbox escape that compromises Chrome's security architecture.
The vulnerability enables sandbox escape and local code execution without remote access; a local attacker (e.g. via compromised software or physical access) can thereby control the system outside the Chrome sandbox.
The vulnerability enables sandbox escape, potentially granting attackers access to the underlying operating system rather than being confined to isolated browser processes.
A security vulnerability in Chrome's WebUI allows an attacker who has already compromised the renderer process to bypass the sandbox and execute arbitrary code , but this requires a previously compromised renderer as a prerequisite.
A sandbox-escape vulnerability in Chromium ANGLE allows attackers to execute arbitrary code outside the browser sandbox, posing critical risk to end users.
The vulnerability allows an attacker who has already compromised the renderer process to bypass the same-origin policy and breach web security boundaries.
A sandbox bypass in Chrome DevTools enables arbitrary code execution via crafted HTML pages without user interaction.
The vulnerability allows an attacker with control over the renderer process to execute code outside the Chrome sandbox, enabling full system compromise.
The vulnerability requires renderer process compromise combined with social engineering, which significantly limits practical exploitation in enterprise environments, but enables full code execution outside the browser sandbox if successfully exploited.
The vulnerability enables sandbox escape and arbitrary code execution via a crafted HTML page, but requires active user interaction and is not documented as actively exploited.
Use-after-free vulnerability in Chrome's platform code enables remote code execution within the sandbox; patching to version 153.0.8010.36 or later is required.
A use-after-free vulnerability in the Aura component allows a remote attacker to execute code outside the browser sandbox, bypassing Chrome's isolation mechanisms.
The vulnerability enables code execution within Chrome's sandbox via crafted HTML content , the risk lies in browser-based attack vectors requiring only visit to a malicious webpage, with sandbox mitigation as the primary containment layer.
Attackers abuse legitimate Google services as intermediary redirects to bypass email security gateways and phishing filters, reducing detection signals for poorly configured security solutions.
Bundling several already-patched zero-days into a circulating exploit kit lets even less skilled espionage-motivated actors exploit them, making the window between patch availability and patch deployment the decisive risk factor.
Attackers exploit passkey-themed phishing lures to trick users into revealing Microsoft 365 authentication credentials,a tactic that exploits modern security expectations.
Microsoft September 2026 patches cause Remote Desktop Services outages , a critical remote access component requiring immediate compatibility assessment.
Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.
A disgruntled security researcher is actively publishing exploitable zero-day exploits against Windows Defender as patch bypasses, regularly circumventing the protective effect of security updates.
CVE-2026-87491 is actively being exploited in the wild and presents an immediate threat requiring urgent patching.
An actively exploited V8 flaw enables code execution within Chrome's sandbox, which could facilitate escalation to system level.
Google has documented multiple Chrome zero-days in active attacks, including iterator invalidation in CSSFontFeatureValuesMap and out-of-bounds write in Skia , indicating targeted browser-based attack campaigns against unidentified threat actors.
The report does not provide specific CVE IDs or attack details, so the actual exposure and urgency remain unclear.
The vulnerability in Paessler PRTG allows information disclosure, which can compromise the confidentiality of monitoring data.
The report describes a novel attack technique (Benchmaxxing) that goes beyond pure patch information and provides new TTPs for defense.
The report contains no insights beyond patch information, as it is a pure NVD entry with no indication of active exploitation.
The report contains no information beyond the patch details regarding active exploitation, attackers, or affected sectors.
The vulnerability is a local out-of-bounds write in the AppArmor parser that can be triggered via /proc/self/attr/apparmor/current, but requires loaded AppArmor profiles and has not been actively exploited so far.
Pure patch information with no indication of active exploitation or strategic relevance.
There is no evidence of active exploitation, threat actors, or strategic implications; the report describes only a single kernel vulnerability with an available patch.
The advisory summarises multiple Linux kernel vulnerabilities without providing specific CVEs or evidence of active exploitation.
The article is a generalized warning report lacking specific CVE numbers, active campaign names, or technical details on exploit methods; the website primarily loads cookie consent dialogs rather than substantive content.
BSI advisory on local kernel DoS vulnerabilities without specific CVE numbers or PoC status , requires verification of affected kernel versions.
A vulnerability in the renderer process allows an attacker with a compromised renderer to access cross-origin data via crafted HTML; however, prior renderer compromise is a prerequisite.
The vulnerability allows a remote attacker to potentially exfiltrate sensitive information via crafted network traffic, going beyond typical input validation issues.
The vulnerability allows attackers to bypass the Same-Origin Policy via crafted HTML pages and gain access to privileged pages, posing a significant risk to enterprise users.
A Low-Severity vulnerability in Chrome that requires prior renderer-process compromise and can only be exploited via crafted network traffic , a routine browser security update with no strategic implication.
This is a standard patch announcement with no indication of active exploitation or campaign context; the notice repeats NVD information without additional security insights.
An authorization bypass vulnerability in Chrome allows attackers to circumvent system access restrictions via crafted HTML pages, posing a risk to employees with privileged access.
The vulnerability requires active social-engineering manipulation via a crafted HTML page and is rated Low-Severity; operational priority is low, but regular Chrome updates should be enforced.
The vulnerability requires active social engineering manipulation via a crafted HTML page and affects only users who click on malicious links, therefore posing low risk for well-trained users.
The vulnerability requires already-compromised renderer processes and is exploited via crafted PDF files, suggesting targeted attacks following initial compromise.
The vulnerability enables arbitrary code execution within the Chrome sandbox via crafted HTML pages, but currently shows no documented active exploitation.
An information leak vulnerability in Chrome allows remote attackers to obtain sensitive data via crafted HTML pages , relevant for organizations using Chrome without additional browser isolation or content-security policies.
The vulnerability enables CSRF attacks against web applications if users interact with manipulated HTML via the browser; primarily affects cloud-based services deployed in the organization.
An authorization flaw in Chrome allows attackers to extract sensitive information via crafted HTML pages, with no active exploitation in the wild currently reported.