Vulnerability Trends — Top Exploited CVEs and Zero-Days | dbugs
#1 · PT-2025-48817 · Meta · React-Server-Dom-Turbopack
CVE-2025-55182
·
Published
2025-12-03
·
Updated
2026-08-27
10
Critical
Base
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The flaw is caused by the unsafe deserialization of payloads in the requireModule() function when processing the hasOwnProperty parameter during...Exploit
Fix
LPE
DoS
RCE
Deserialization of Untrusted Data
Related posts · 2478
2026-08-27 18:58:30
2026-08-25 17:59:12
2026-08-25 17:59:11
#2 · PT-2026-71124 · Jfrog · Artifactory
CVE-2026-66384
·
Published
2026-08-12
·
Updated
2026-08-29
5.3
Medium
Base
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Path traversal
Related posts · 14
2026-08-29 02:00:57
2026-08-28 15:00:27
2026-08-28 14:38:15
#3 · PT-2026-34274 · Linux · Linux Kernel
7.8
High
Base
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
algif aead cryptographic algorithm interface of the Linux kernel. The issue stems from an incorrect in-place operation during cryptographic processing where source and destination data mappings differ. A local attacker with low privileges can exploit this by splicing...Exploit
Fix
RCE
LPE
DoS
Use After Free
Related posts · 1144
2026-08-28 21:53:46
2026-08-26 23:57:43
2026-08-26 15:59:01
#4 · PT-2024-2752 · Palo Alto Networks · Pan-Os
10
Critical
Base
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploit
Fix
DoS
RCE
Command Injection
Related posts · 793
-
SentinelOne DFIR casework (66 CVEs, 12 months) and Tenable exposure telemetry (33 CVEs, thousands of customer environments) independently arrived at the same seven edge vendors: Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, and VMware. 100% convergence on edge infrastructure specifically. 93 CVE-actor attribution pairs span Chinese 🇨🇳, Russian 🇷🇺, North Korean 🇰🇵, Iranian 🇮🇷, and ransomware nexuses. Twelve CVEs have confirmed multi-nexus attribution, including CVE-2024-3400 (PAN-OS) exploited by both a China-nexus actor and INC Ransomware, and CVE-2024-24919 (Check Point) hit independently by PurpleHaze (China 🇨🇳) and Fox Kitten (Iran 🇮🇷).
-
F5 leads on breadth: 54% of monitored customer environments carry at least one actively exploited CVE. Citrix leads on persistence: 461-day median time to patch, 71% of affected environments still unpatched after a full year. High-priority CVEs take 146 days to remediate versus 122 days for all others, a statistically significant 24-day gap in the wrong direction.
-
In FortiGate intrusions, responders found rogue admin accounts, exported device configs containing LDAP bind credentials, and subsequent domain joins with no SPN.
2026-08-26 13:03:31
2026-06-15 16:42:52
2026-06-15 16:42:47
#5 · PT-2026-65725 · Gitea · Gitea
9.8
Critical
Base
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
services/repository/files/patch.go file. An attacker with write access to a repository can exploit the diffpatch API endpoint to install a malicious executable Git hook, allowing the execution of arbitrary shell commands with the privileges of the Gitea operating-system user. If o...Exploit
Fix
RCE
Code Injection
Related posts · 80
2026-08-29 12:35:08
-
McKesson confirms a breach after ShinyHunters claims a massive patient-data haul The U.S. drug distributor says attackers reached third-party apps and stole data. ShinyHunters says it used vishing against employees, then pulled about 1 TB from Snowflake — roughly 284 million patient-related records, not necessarily 284 million unique people. Names, SSNs, medical IDs and clinical details are allegedly in the mix.
-
PaperCut NG/MF: unauthenticated RCE in the wild, second emergency patch out Attackers are chaining two flaws (including CVE-2026-82078 and CVE-2026-81578) to change trusted config and run code with no login. The first hotfix was bypassed; PaperCut shipped a second emergency update with extra hardening. Print servers remain a favorite foothold into corporate networks.
-
CISA deadline day: Citrix NetScaler under active attack CVE-2026-8452 — a memory-overflow bug Citrix first framed as DoS — is being used for pre-auth code execution and webshells. Federal agencies were told to patch by today, August 29. Separately, Shadowserver still sees 8,300+ internet-facing Gitea boxes unpatched against the exploited RCE CVE-2026-60004.
2026-08-29 11:43:36
2026-08-29 07:01:10