Skip to content
LEARN

Learning Resources

Expand your knowledge with our curated content.

Documents

Workshops, presentations, and demos.

No resources available yet.

Vulnerabilities (CVE)

Actively exploited or maximum-severity vulnerabilities.

Actively exploited

CVE-2026-48172

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

Added to KEV: 2026-05-26View details
Actively exploitedCVSS 9.8EPSS 0.17

CVE-2026-9082

drupal:drupal

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Added to KEV: 2026-05-22View details
Actively exploitedCVSS 6.7

CVE-2026-34926

trendmicro:apex_one

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affec…

Added to KEV: 2026-05-21View details
Actively exploitedCVSS 8.8EPSS 0.30

CVE-2025-34291

langflow:langflow

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-ori…

Added to KEV: 2026-05-21View details
Actively exploitedCVSS 4.0

CVE-2026-45498

microsoft:defender_antimalware_platform
WindowsCyberSecurityCloud

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

Analysis

Microsoft Defender is currently being targeted by active exploits in the wild that allow for a Denial of Service. While the severity score is moderate, its presence on the CISA KEV catalog makes it a priority for anyone managing Windows-based development environments or production servers.

Added to KEV: 2026-05-20View details
Actively exploitedCVSS 7.8

CVE-2026-41091

microsoft:malware_protection_engine
WindowsCyberSecurity

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

Analysis

Microsoft Defender contains a vulnerability in link resolution that allows a local user to elevate their privileges. While high severity, this is a standard local privilege escalation bug that is typically handled by automated OS updates and does not represent a systemic risk to developer infrastructure.

Added to KEV: 2026-05-20View details
HomeEventsBlogResources
Team