Skip to main content

Microsoft SharePoint Complete Unauthenticated RCE Chain Now Fully Patched Across Two Patch Tuesdays (CVE-2026-55040 / CVE-2026-63520)

Scope: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and Share

Microsoft Officially Assigns CVE to ShieldBreak Zero-Day as Patch Development Confirmed (CVE-2026-69414)

Scope: Microsoft Defender for Windows (All Versions on Windows 10, Windows 11, Windows Ser

Forminator Forms WordPress Plugin Critical RCE Flaw Affects 600,000 Active Installations (CVE-2026-15748)

Scope: Forminator Forms WordPress Plugin (All Versions Prior to Patched Release)

Zoom Workplace for Windows Critical Authentication Flaw Enables Unauthenticated Account Takeover (CVE-2026-53412)

Scope: Zoom Workplace for Windows Prior to Version 7.0.0 and Zoom Workplace VDI Client for

GitLab CE and EE Emergency Out-of-Band Patch Addresses Critical Unauthenticated Data Deletion Flaw (CVE-2026-19478)

Scope: GitLab Community Edition and Enterprise Edition Self-Managed Installations Versions

Windows Server 2022 Reaches End of Mainstream Support in 60 Days — Begin Migration to Windows Server 2025 Now

Scope: Organizations Running Windows Server 2022 (On-Premises and Hosted Environments)

Apple macOS Screen Sharing Logic Flaw Actively Exploited to Deploy Monero Miner via Root Command Execution (CVE-2026-43760)

Scope: macOS Systems with Screen Sharing or Remote Management Enabled and VNC Password Aut

Subscribe to Advisories