Skip to main content
WordPress Core Path Traversal Flaw Moves From Patch to Active Payload Delivery Within Hours (CVE-2026-87902)

Scope: WordPress Core, All Versions Prior to 7.1.2 (Fix Backported to 4.7.37)

WordPress Core Unauthenticated Path Traversal Affects Every Version Since 2016, Can Enable Code Execution (CVE-2026-87902)

Scope: WordPress Core, All Versions 4.7.0 Through 7.1.1

F5 BIG-IP APM Unauthenticated Remote Code Execution Actively Exploited on OAuth-Configured Systems (CVE-2026-94127)

Scope: F5 BIG-IP Access Policy Manager, Virtual Servers Configured with Both an APM Access

Arista VeloCloud Orchestrator Maximum Severity Flaw Exploited With No Available Workaround (CVE-2026-93952)

Scope: Arista VeloCloud Orchestrator (VCO) On-Prem Deployments

Linux Kernel Actively Exploited Vulnerabilities Remain Unpatched Past Federal Deadline (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964)

Scope: Linux Kernel (All Distributions Running Affected Kernel Versions, Including Servers

FomoPeek Trojanized iOS App Hides Kernel Exploit to Steal Cryptocurrency Wallet Data

Scope: iOS Devices with FomoPeek or Similarly Sideloaded Cryptocurrency Applications Insta

Subscribe to Advisories