// VULNERABILITIES

// ВРАЗЛИВОСТІ

8 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited

Google disclosed CVE-2026-21385, a high-severity buffer over-read vulnerability (CVSS 7.8) in a Qualcomm Android graphics component that has been actively exploited in the wild. The vulnerability involves memory corruption from unvalidated user-supplied data without proper buffer space checks.

New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel

A patched Chrome vulnerability (CVE-2026-0628) allowed malicious extensions to escalate privileges and access local files through insufficient policy enforcement in the WebView tag. Google patched the flaw in January 2026, with a CVSS score of 8.8 indicating high severity.

900 Sangoma FreePBX Instances Infected With Web Shells

A real security incident involving 900 Sangoma FreePBX instances that were infected with web shells. The attacks exploited a post-authentication command injection vulnerability in the endpoint manager's interface, affecting multiple actual targets.

Juniper Networks PTX Routers Affected by Critical Vulnerability

Juniper Networks released an out-of-band security update for Junos OS Evolved to patch CVE-2026-21902, a critical remote code execution vulnerability affecting PTX routers. This is a vulnerability disclosure with a specific CVE identifier and affected product line.

Trend Micro warns of critical Apex One code execution flaws

Trend Micro disclosed two critical remote code execution vulnerabilities in its Apex One product that have been patched. This represents an actual vulnerability disclosure (CVE) affecting a real security product with specific impact potential.

SolarWinds Patches Four Critical Serv-U Vulnerabilities

SolarWinds released patches for four critical vulnerabilities in their Serv-U product that could be exploited for remote code execution. This is a legitimate vulnerability disclosure involving specific CVEs/security defects in a widely-used file transfer software.

Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia

Peter Williams, an ex-US Defense Contractor executive, was sentenced to 87 months in prison for selling cyber exploits to a Russian broker. This represents an actual security incident involving the unauthorized transfer of exploits to a foreign adversary.

CISA: Recently patched RoundCube flaws now exploited in attacks

CISA has identified two Roundcube Webmail vulnerabilities that are being actively exploited in real attacks against organizations. U.S. federal agencies have been mandated to patch these vulnerabilities within three weeks, indicating confirmed active exploitation in the wild.