Skip to main content

Cisco Unified Communications Manager SSRF to Root Privilege Escalation via WebDialer (CVE-2026-20230)

Scope: Cisco Unified CM and Unified CM SME (All Versions with WebDialer Enabled)

Oracle WebLogic Server Unauthenticated Data Access via T3/IIOP Added to CISA KEV (CVE-2024-21182)

Scope: Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0

Severity: Red

Google DoubleClick Abused as Redirector to Deliver DesckVB RAT via Malspam Campaign

Scope: Enterprise Email Users (Windows Endpoints)

Severity: Red

Marimo Python Notebook Pre-Authentication RCE Now Weaponized with LLM-Driven Post-Exploitation (CVE-2026-39987)

Scope: Marimo Python Notebook Versions 0.20.4 and Earlier

Severity: Red

PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation Added to CISA KEV (CVE-2026-0257)

Scope: Palo Alto Networks PAN-OS with GlobalProtect Portal or Gateway Configured

FBI Warning: Kali365 Phishing-as-a-Service Platform Bypasses MFA to Hijack Microsoft 365 Accounts

Scope: Microsoft 365 and Microsoft Entra ID (All Organizations)

Cybercriminals Targeting Formula 1 Fans with Fake Streaming Services, Counterfeit Merchandise, and Phishing Scams

Scope: Formula 1 Fans (Global)

Severity: Medium

Subscribe to Advisories