CYBER Threat Intelligence Reports
LATEST CTIs
SonicWall SMA1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 Exploited for Unauthenticated RCE
SonicWall has disclosed two actively exploited zero-day vulnerabilities affecting its SMA1000 secure remote access appliances. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect the SMA1000…
Read more >

PaperCut CVE-2026-81578 and CVE-2026-82078 Exploited for Pre-Auth RCE
Threat actors are actively exploiting two vulnerabilities in PaperCut NG and PaperCut MF that can be chained to bypass authentication and achieve remote code execution…
Read more >

Next.js Critical Vulnerabilities Enable Unauthenticated RCE
Vercel has released security updates for two critical vulnerabilities in Next.js that could allow unauthenticated attackers to achieve remote code execution on vulnerable applications. The…
Read more >

Keycloak CVE-2026-18963 Enables Unauthenticated Account Takeover
A critical vulnerability in Keycloak could allow an unauthenticated remote attacker to take control of arbitrary user accounts through the platform's password recovery functionality. Tracked…
Read more >

Elementor Pro CVE-2026-32475 Enables Unauthenticated File Upload and RCE
A critical vulnerability in the widely deployed Elementor Pro plugin for WordPress can allow unauthenticated attackers to bypass file-type restrictions, upload executable PHP files to…
Read more >

Windows IKE CVE-2026-33824 Exploited for Pre-Auth Remote Code Execution
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE) is now being actively exploited. Tracked as CVE-2026-33824, the vulnerability is a…
Read more >

